Support

Admin Tools

#10149 Site crashing

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by user13238 on Tuesday, 13 December 2011 15:06 CST

user13238
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? No
Have I searched the forum before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: (1.5.25)
PHP version: (5.2.6)
MySQL version: (5.0.51b)
Host: (self hosting Windows IIs 6.0 server)
Admin Tools version: (2.1.14)

Description of my issue:
Nick, thank you for providing your outstanding AdminTools and Akeeba Backup extensions to the Joomla community. Both have been a major life & time saver for many of us.

I manage a private school's website (Joomla 1.5.25) that resides on their Windows IIs server. With the assistance of AdminTools, I have blocked just about every country outside of North America due to some really harsh activity coming mostly from China and the Russian Federation IPs. The problem we are having is the site is crashing at least once a week due to 'eval(base64_decode' scripts being added to all index.php files within the Joomla installation. I have a copy of one of the index.php files as well as the last admintools_breaches.log file before taking the site down and re-installing from a recent backup. I'm not 100% sure what direction to take in preventing this from happening in the future thus I am turning to you for assistance.

If this matter would best be handled via a support ticket subscription, please let me know and I'll make the necessary purchase. If you wish to receive the infected index.php file to review along with the admintools_breaches.log file, let me know how to best get these files to you.

Finally, since I have GEOblocking active and if you wish to view the Joomla site in question (both public/admin), I'll need your IP address so I can add it to the white list. I understand that this may be outside the scope of AdminTools but wanted to seek your expert advise and assistance on prevention measures moving forward.

In regards,
Ed

brianteeman
You have locked the door after the horse has bolted. Your site obviously has had a hackers backdoor script installed on it. All you are doing is removing the symptoms not solving the problem - that's why it keeps happening.

user13238
Brian,

Thanks for your reply, what processes/steps would you suggest I undertake in correcting this issue?

In regards,
Ed

brianteeman
^This is as good a place as any
http://docs.joomla.org/Security_and_Performance_FAQs#Help.21_My_site.27s_been_compromised._Now_what.3F

nicholas
Akeeba Staff
Manager
I agree with Brian. You're hacked. I've written an unhacking guide myself https://www.akeebabackup.com/documentation/walkthroughs/unhacking-your-site.html

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user13238
Nick & Brian,

Thank you both for your prompt replies and detailed links. I'll go through both and follow their recommendations. It seems like I have a days worth of work ahead of me but... it will be time well spent if it corrects the situation. Thanks again and Happy Holidays!

In regards,
Ed

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!