Support

Akeeba Backup for Joomla!

#20315 3.1.1. backup?

Posted in ‘Akeeba Backup for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Akeeba Backup version
n/a

Latest post by nicholas on Thursday, 19 June 2014 10:54 CDT

user6466
i see that the downloads say you are not supporting 3.0 or 3.1
I am using 3.1.1 which akeeba backups pro or free can I use?

nicholas
Akeeba Staff
Manager
We have not tested our latest versions with Joomla! 3.1. You should be able to use Akeeba Backup 3.8.2 on that site.

HOWEVER! Joomla! 3.1 is way too old, obsolete and contains vulnerabilities (security issues) which are already known and widely publicised. Under no circumstances should you be using Joomla! 3.1 on a live site. It's like having a death wish and, oh believe me, hackers will be most willing to fulfil it. Please upgrade to Joomla! 3.3 a.s.a.p. (after taking a backup, of course – I assume that's why you asked me).

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user6466
Yes I understand completely and was lazy because I found your compatibility chart and lo and behold there was Akeeba Backup 3.8.2, my apology.

I adopted this site and of course [i] am aware however the client is unaware as are most Joomla site owners of those vulnerabilities (security issues). There needs to be a better or more sever warning system.

I noted you stated you should never download Akeeba backup file from the browser , I was using fireftp and filezilla. However fireftp no longer works in Firefox and filezilla was hacked and became vulnerable.

Are there any preferably Joomla component FTP or Firefox FTP that are functional they do binary as you stated and are secure.

Thank you!


user6466
The restore to my server as a Dev site failed or more accurately wont load in the browser after clicking go to sites frontend form akeeba. i assume this is because the ssl certificate is only approved for the live sites URL? How do I remove it for this site or how do I fix this ?

Secure Connection Failed
An error occurred during a connection to mysite.com. Peer's Certificate has been revoked. (Error code: sec_error_revoked_certificate) The page you are trying to view cannot be shown because the authenticity of the received data could not be verified. Please contact the website owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.





user6466
I turned force SSl off by changing the setting in the config file from 2 to 0.
This allowed me to view and get into the admin.

However the site looks different from the live site the header is not there and the top module is not present.

dlb
You can find post restore troubleshooting tips here: https://www.akeebabackup.com/documentation/troubleshooter/prbasicts.html.

From your description, the problem is most likely an .htaccess Maker issue or a $live_site issue.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

user6466
Could you address this question from above for me please

"I noted you stated you should never download Akeeba backup file from the browser , I was using fireftp and filezilla. However fireftp no longer works in Firefox and filezilla was hacked and became vulnerable.

Are there any preferably Joomla component FTP or Firefox FTP that are functional they do binary as you stated and are secure.

Thank you!"

dlb
You should recheck your sources on the problem with FileZila. From the FileZilla website:
2014-01-28 - Advisory: Malware downloads on third-party websites

As recently published on the avast! blog, modified versions of FileZilla tainted with malware are being distributed on some third-party websites.

This is by no means a new threat. While this instance is one of the largest to date, there have been many cases of modified versions spreading malware hosted on third-party websites for over a decade. We do not condone these actions and are taking measures to get the known offenders removed. Note that we cannot in general prevent tainted versions on third-party websites or prove their authenticity, especially since the FileZilla Project promotes beneficial redistribution and modifications of FileZilla in the spirit of free open source software and the GNU General Public License.

To avoid any risk when downloading FileZilla, we recommend that you only download FileZilla from the official FileZilla website or from SourceForge, the official download partner of FileZilla and many other open source projects.

To check the authenticity of your version of FileZilla, the SHA-512 hash of the unmodified FileZilla_3.7.3_win32-setup.exe is f56716044dcf1239d09343d11422b26230fb14419a4e85b702a03080550bc9e69e1c7ec22312874701de54c1ed4085e0f468d93d4993b36eabd704406b3567ff

In case you no longer have the installer, the SHA-512 hash of the installed filezilla.exe in version 3.7.3 is d6d68f564295a878ba6cdf1d79cc90b4cff4fb98177bf5aac0eb22ad3757f8997e2de718e290eb97520892d04a8d2388bb2bcb71b785d05c2b59b037abf6d28f

Note that the SHA numbers in this message are for the 3.7.3 version, not the current 3.8.1 version. It really doesn't matter what FTP client you use, it has been so long since I used anything but FileZila I just don't have anything else to recommend.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

nicholas
Akeeba Staff
Manager
On Mac OS X I am using Transmit and Cyberduck. The latter is also available on Windows. On Linux I am using Filezilla.

Moreover please note that Filezilla has not been hacked. On top of what Dale told you, there's another misconception: using Filezilla will report your connection information to hackers. That's a big load of BS.

Filezilla, like most FTP/SFTP software on Windows, has to store the connection information (hostname, username, password) somewhere. By default this is an unencrypted INI file in your user account. The alternative is in your registry. In both cases IF YOUR PC IS ALREADY COMPROMISED and infected by malware, the malware installed on your PC can find this file and send it to its masters.

This is not a vulnerability in Filezilla itself. If your computer is compromised and infested with malware Filezilla's predictable unencrypted storage is the least of your concerns. Malware also features keyloggers and automatic screenshots whenever you are typing into a password field. No matter what software you use, if you run an FTP connection from a compromised computer your chances of nothing bad happening are akin to jumping off a plane without a parachute.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user6466
I wish the explanation I found when I first was notified about the filezilla vulnerabiity had been as clear as you were Nicholas. Would have saved me a huge amount of time and effort.
They being filezilla never stated what you did .

I downloaded the latest filezilla from sourceforgeand reinstalled it. It seemed to remeber my prevvious site settings so doobviously I had not completely removed it in my las t attempt.

Just as a side note I moved to quickly in my download from sourceforge and did not notice it was also going to include the speeddial download. For future reference anyone doing this should be aware of the results of doing that by reading the info on this link to remove it.

http://www.pcrisk.com/removal-guides/7876-speedial-com-redirect

Once again thank you for your accuracy and clarification on the filezilla issue Nicholas.

nicholas
Akeeba Staff
Manager
You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!