Welcome, Guest

Turkish Hackers how to resore site
(1 viewing) (1) Guest
  • Page:
  • 1


Posting guidelines
To help us help you faster please ensure that you include the following details in your forum post:
- A link to your site (you can create a support ticket if you need to provide us with confidential information.
- Please ensure that css and javascript compression is disabled in your template settings.
- Please ensure that you have checked the change log and your template and extension are up to date.
- Please search the forum to see if your answer has already been asked before.
- Please ensure that you only post your request in either the forum or ticket system but not both.
- Please only post in an existing thread if your issue is exactly the same as the one being discussed in the thread.

TOPIC: Turkish Hackers how to resore site

Turkish Hackers how to resore site 2 years, 4 months ago #40214

Yesterday afternoon my entire hosting account with HostGator was hacked, new index.html and index.php files with the Turkish flag and music playing were placed into over 20 websites. It was a big shock. I was able to restore everything quickly by simply replacing the index.php with the original Joomla index.php.

HostGator claims they broke in through the admin in an older install of wordpress I have and then obtained access to my entire hosting account, I am going to be moving that wordpress site into its own little account somewhere because I cannot upgrade the install without breaking the whole site with the shopping cart plugin (this was before I found joomla!), and this kind of vulnerability is not fun!

A question: can hackers get into my whole hosting account through Joomla too? I have taken the small steps of changing the default admin login, database prefix, SEF url, and akeeba backups stored on my hard drive and on dvd but this could turn into a nightmare if it gets repeated on a heavier scale. Any thoughts? Thanks, Carin
  • handsun
  • OFFLINE
  • 3 Month Basic
  • Posts: 365
  • Karma: 1

Re: Turkish Hackers how to resore site 2 years, 4 months ago #40228

Ouch, sorry to hear that Carin.

I would caution though that any changes may be very hard to detect, and you should not assume that Joomla is not still compromised. You can't ever really trust a known hacked site again. Any half-competent hacker will also have backdoored your sites.

To answer your question; if it is not properly secured, yes. This is why it is essential to keep everything up to date.

I think you should consider restoring all your sites to known good, pre-hack versions from backup. You can use the Akeeba sitediff tool to compare hacked/good versions to be sure: www.akeebabackup.com/software/akeeba-sitediff.html
  • Seth
  • OFFLINE
  • Moderator
  • Posts: 8401
  • Karma: 200
Internet Inspired! - Creative Websites (and freelance websmithing!)

Re: Turkish Hackers how to resore site 2 years, 4 months ago #40254

Yep I would second that.

Often hackers place root kits that enable access tot he site in oddly named files - Slightly misspelt or files that are discreetly hidden in a sub sub folder. If you download the backups and do a scan for the text "base64" you will get some false positives - some J files use that - but it may reveal the files in question. Although it can be hard to locate some as they are expertly hidden.

If you need pro help Id recommend Brian Teeman - brian.teeman.net or Phil taylor www.phil-taylor.com/ - they have help me in the past.

Best of luck.

Anthony
Creative Unique Minimal Joomla Templates

Re: Turkish Hackers how to resore site 2 years, 4 months ago #40267

Thanks you guys, I guess "resore site" is an apt typo, ouch is right. I will be using the Akeeba tool right away, and thanks Anthony for the referrals, take care, Carin
  • handsun
  • OFFLINE
  • 3 Month Basic
  • Posts: 365
  • Karma: 1

Re: Turkish Hackers how to resore site 2 years, 4 months ago #40284

Great recommendations from Anthony.

One other thing, you might want to look a another host once you sites are cleaned. Seems like HG are trying to put all the blame on you, when in fact they are also responsible for the security of a shared server. For all you know, someone elses account was compromised and that is how they got access to yours.

Good luck Carin, let us know how you get on.
  • Seth
  • OFFLINE
  • Moderator
  • Posts: 8401
  • Karma: 200
Internet Inspired! - Creative Websites (and freelance websmithing!)
  • Page:
  • 1
Time to create page: 0.37 seconds