We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Urgent help with website security after hacking

_Andy_
Posts: 11,150 Forumite
in Techie Stuff
Hi, hoping there might be a security guru here who could help.
If someone here is able to help, I can't offer to pay as such but would happily make a donation to your favourite charity..
I have several Joomla (v1.5.23) sites hosted on the same hosting package. Today they got hacked/had front pages defaced. I have restored the previous versions which is fine.
Obviously what I want to do now is prevent further attacks.
I've changed all the Joomla admin passwords (and also my Gmail and PayPal ones to be sure).
My host (Vidahost) haven't been especially helpful in terms of how to secure things from here.
I've seen some suggestions about .htaccess but any of them Ive tried just lead to 403 errors across all sites.
I have got rid of an old install of Wordpress in case.
Basically, help! Can anyone assist with securing this to prevent a further attack?
Thanks in advance
ETA: doesn't appear to be something like a password stolen off the pc by a trojan etc, have done a couple of scans and although of course I can't rule that out it doesn't seem to be the case (plus my email and various accounts etc haven't been touched)
If someone here is able to help, I can't offer to pay as such but would happily make a donation to your favourite charity..
I have several Joomla (v1.5.23) sites hosted on the same hosting package. Today they got hacked/had front pages defaced. I have restored the previous versions which is fine.
Obviously what I want to do now is prevent further attacks.
I've changed all the Joomla admin passwords (and also my Gmail and PayPal ones to be sure).
My host (Vidahost) haven't been especially helpful in terms of how to secure things from here.
I've seen some suggestions about .htaccess but any of them Ive tried just lead to 403 errors across all sites.
I have got rid of an old install of Wordpress in case.
Basically, help! Can anyone assist with securing this to prevent a further attack?
Thanks in advance

ETA: doesn't appear to be something like a password stolen off the pc by a trojan etc, have done a couple of scans and although of course I can't rule that out it doesn't seem to be the case (plus my email and various accounts etc haven't been touched)
0
Comments
-
Are you hosting all the sites on your own server? Has YOUR PC been infected?Estate Agent, Web Designer & All Round Geek!0
-
Are you hosting all the sites on your own server? Has YOUR PC been infected?
hi Steve
Have done some scans and from what I can see the PC isn't infected. The hacker in question has 'done' a couple of other sites today also using Joomla and various ones before according to zone-h.org
I believe I've now undone all the damage (thankfully they hadn't deleted anything) but I just feel a bit lost now as to how to prevent it again.
Ps it's not my own server its shared hosting on Vidahost
Thanks0 -
I'd be contacting your host if your pc is not infected with a keylogger.
Otherwise, change host.Estate Agent, Web Designer & All Round Geek!0 -
If possible UPGRADE Joomla to the latest version 1.7.0 or 1.6.6 ASAP!!!
If you can't, then make arrangements to move to a host that will let you use the latest version! as you're more than likely to be attacked again with probably worse results!
The main reason they were ably to deface the sites was probably a flaw in the older version.Laters
Sol
"Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"0 -
If possible UPGRADE Joomla to the latest version 1.7.0 or 1.6.6 ASAP!!!
If you can't, then make arrangements to move to a host that will let you use the latest version! as you're more than likely to be attacked again with probably worse results!
The main reason they were ably to deface the sites was probably a flaw in the older version.
A friend of mine uses Joomla and he hasn't been hacked so upgrading to 1.7 is not going to make any difference.
Ny money is still on your host being infected rather than you.Estate Agent, Web Designer & All Round Geek!0 -
If possible UPGRADE Joomla to the latest version 1.7.0 or 1.6.6 ASAP!!!
If you can't, then make arrangements to move to a host that will let you use the latest version! as you're more than likely to be attacked again with probably worse results!
The main reason they were ably to deface the sites was probably a flaw in the older version.
Hi Sol
Will upgrading to 1.6/7 affect currently installed modules/plugins though?
Thanks0 -
Hi Sol
Will upgrading to 1.6/7 affect currently installed modules/plugins though?
Thanks
There is a possibility if they have not been tested with 1.7.
Before upgrading anything (bearing in mind 1.7 has only just come out) speak to your host and make sure that they have plugged the leak in their security system.Estate Agent, Web Designer & All Round Geek!0 -
Thanks Steve
Vidahost don't seem to think it's a problem with them as such.
I have removed a J! component (CK forms) which apparently isn't secure although that wasn't on the main site. Also have uninstalled the old Wordpress and deleted the old folders etc.
Have tried various things with htaccess but all results in errors when visiting the site.
Looking like I will purchase a Joomla firewall/security component but not ideal.0 -
-
Could it not be something specific to my Joomla though? Looking at the other sites hacked on same day it's not like he/she has done a whole load.
Have read about SQL injection attacks and changing table prefixes from jos_ but again it's all a bit of a minefield to me and not something I want to touch without help0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 352.1K Banking & Borrowing
- 253.6K Reduce Debt & Boost Income
- 454.2K Spending & Discounts
- 245.1K Work, Benefits & Business
- 600.7K Mortgages, Homes & Bills
- 177.5K Life & Family
- 258.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards