Support

Admin Tools

#26932 Site has been Hacked

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Wednesday, 22 February 2017 17:17 CST

[email protected]
 I have a joomla site that is getting hacked. We continualy find files that are being uploaded to the site and whenever we try to access the admintools we get cannot access this website. Some of the files that I'm finding uploaded are

libraries/legacy/form/javascript57.php
/libraries/f0f/database/query/element.php
/libraries/f0f/encrypt/cache.php
/images/sampledata/fruitshop/title.php

By reinstalling Admintools and akeebabackup fixes the issue until it gets hacked again. We are going to be redoing the site from scratch to fix the hacking. We do not know what has been compromised at this point. I am creating this ticket to help better understand what is going on and why the admintools gets broken. Possible hack to admintools or some other component that effects admintools and akeebabackup.

Any insight would be greatly appreciated.

Thanks

Jimmy Lee

dlb
Jimmy,

There are several possibilities here. It is possible that the hackers have put a back door in your site that allows them to compromise it even after you have cleaned it up. It is possible that the server is not secure enough and you can be hacked from a "neighboring" site. It is possible that you have a vulnerable extension on the site.

We have some thoughts on unhacking your site here: https://www.akeebabackup.com/documentation/walkthroughs/unhacking-your-site.html. There are also services that will scan and unhack your site like myjooomla.com. If you are planning on redoing the site, that might be the easiest course of action, just delete everything and start from a bare drive. But you need to start bare, change all the passwords, etc.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

[email protected]
Thanks for the info...

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!