Support

Admin Tools

#41507 Image file replaced by hacker without any sign of intrustion

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
5.2.2
PHP version
8.2
Admin Tools version
7.6.2 (Pro)

Latest post by on Monday, 20 January 2025 13:43 CST

davidascher

Some hacker managed to replace an image file on the site with an "inappropriate" image file. I don't see any evidence of any other files getting overwritten and I don't see any evidence of the original file being accessed in any of the log files I have examined. I don't see any evidence that anybody used the credentials of any of the few users that the site has. 

I have Admin Tools configured to either prevent or report any activity that might be suspicious or harmful and I don't see any report of any of that.

Do you have any ideas about how I might further investigate how this hack was accomplished? Until I find out how it was done and plug that hole, the site is vulnerable to further serious attacks.

I can provide you with credentials to allow you to access the site as a Super User if you would prefer to investigate yourself. Thanks.

System Task
system
The ticket information has been edited by david ascher (davidascher).

System Task
system
The ticket information has been edited by david ascher (davidascher).

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!