Support

Akeeba Backup for Joomla!

#11780 Understanding Logs - is this a remote backup?

Posted in ‘Akeeba Backup for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Akeeba Backup version
n/a

Latest post by nicholas on Sunday, 01 April 2012 10:38 CDT

vthomas
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Looked at the Troubleshooter
Have I searched the tickets before posting? yes, for remote backup
Have I read the documentation before posting (which pages?)? troubleshooting
Joomla! version: 1.5.26 (upgraded from 1.5.25 after hack)
PHP version: 5.3.10
MySQL version: Server version: 5.1.56
Host: rochen shared server acct
Akeeba Backup version: WAS Akeeba Backup core 3.3.11, now 3.4.3

EXTREMELY IMPORTANT: Please attach a ZIP file containing your Akeeba Backup log file in order for us to help you with any backup or restoration issue. If the file is over 2Mb, please upload it on your server and post a link to it.

Description of my issue:

For certain this site was hacked (scary pic and music on home page) and site owner called and asked me to fix it. Then, I was looking at backend and noticed some odd behaviour, and also the database seemed to revert to any earlier version (I know, because user details I had changed reverted to earlier settings). I changed their passwords, upgraded from j1.5.25 --> 26, updated software, including akeeba. Then, noticed (see attached) log in server tmp folder that appears to show a remote backup (I did not do this! nor did they!) and remote attempts too in the akeeba joomla log. I've attached both files. My question is - does it look to you like this is a remote backup? If so, it is a hacker. Or, am I misunderstanding the log. Since it is in the akeeba log, are they using akeeba backup core for this - I don't think it has this feature? Thanks for your feedback, I just want to understand the log and stop ability to remote backup. I did uninstall lazy scheduling plugin, which was deactivated already. Thank you in advance.
 Vicky Thomas

nicholas
Akeeba Staff
Manager
First problem I notice:
INFO |120331 12:52:39|Akeeba Backup ATP/FAM (2011-12-12)

"ATP/FAM" is NOT a version I have ever published. All of my versions are numeric. I have no idea who installed this or which version it really is.

Now, the original log file was evidently called akeeba.backend.log. If it's called akeeba.backend.log, it's taken from the backend. In order to take a backup from the backend, you need to log into the backend. You can't take a remote backup from the backend, so it's not a remote backup. If someone takes a remote backup, the log file is called "akeeba.json.log" as the backup is done through the JSON API.

If someone takes a front-end backup (e.g. using webcron.org or altbackup.php) the log file is called akeeba.frontend.log. Likewise, if you use the backup.php CRON script it's akeeba.cli.log. Therefore, the name of the backup tells you its origin, which is the same origin recorded in the database and shown in the Administer Backup Files page.

Based on your description, it looks like someone has access to the backend, restores an earlier version of the site and then takes a backup of the site.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

vthomas
Thank you, Nicholas. Very helpful.
Also, does the term "Kettenrad" ever show up in 'real' akeeba backup log files?
 Vicky Thomas

vthomas
I found this in a simple web search. Look at the source! Found "ATP/FM" as the 'version" ...
http://subversion.assembla.com/svn/jadmintools/trunk/component/backend/akeeba/platform/jfscan/platform.php
 Vicky Thomas

nicholas
Akeeba Staff
Manager
I was under the impression you were looking in Akeeba Backup's output directory, not your site's tmp directory. Yes, Admin Tools' File Change Scanner does have ATP/FM as its version, but it should generate the log file in the site's tmp directory, not Akeeba Backup's output directory. If the log file is misplaced, that's a bug.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!