Joomla site hacked?

If you have any 'mechanical' forum or Joomla! sites related issues/suggestions, please contact the Sites & Infrastructure Workgroup here.

Moderators: brad, Tonie

Forum rules
Forum Rules
READ ME <-- please read before posting, this means YOU.
Locked
ben-work
Joomla! Apprentice
Joomla! Apprentice
Posts: 17
Joined: Mon Jan 09, 2006 10:48 pm

Joomla site hacked?

Post by ben-work » Thu Mar 06, 2008 2:55 am

I came here earlier and saw IFRAME links in the title and menu items, I assume the site was hacked. Just curious - if it's known how it happened, was this a new vulnerability? Or was the site not running the latest version..

EDIT: I should point out I mean the main website not this forum.

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Joomla site hacked?

Post by brad » Thu Mar 06, 2008 9:15 am

Nothing related to Joomla.. rather a 3rd party component... should be ok now though.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

User avatar
PhilD
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Sat Oct 21, 2006 10:20 pm
Location: Wisconsin USA
Contact:

Re: Joomla site hacked?

Post by PhilD » Thu Mar 06, 2008 4:39 pm

Hey Brad,

I know you don't want to bash others hard work, but in the interest of others who may be using the same 3rd party component, could you maybe mention what the component is instead of just saying it was a 3rd party component. I'm sure the component developer wouldn't mind mention if the problem is legit and they are working on a fix. This may help someone else who is using the same component and may be unaware of a compromise in the component. Then again, if people won't read, they won't know anyway until it's to late.
Phil

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Joomla site hacked?

Post by brad » Thu Mar 06, 2008 7:42 pm

It was the custom install/integration of the WP blogs.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

User avatar
ilox
Joomla! Apprentice
Joomla! Apprentice
Posts: 20
Joined: Thu Aug 25, 2005 3:29 pm
Location: Adelaide, South Australia
Contact:

Re: Joomla site hacked?

Post by ilox » Fri Mar 07, 2008 1:07 pm

So Brad, it wasn't anything to do with this message presently appearing above this page, and any other Forum page?

Code: Select all

[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3366: Undefined index: 13.5
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3391: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2914)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3393: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2914)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3394: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2914)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3395: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2914)
Just wondering?

FYI: viewing with Firefox 2.0.0.11 through Xandos Linux on an ASUS EEE PC.
Cheers,  Ian
"So long, and thanks for all the fish" - The Dolphins - http://www.jengajam.com/r/dolphins
The Hitch Hikers Guide To The Galaxy by Douglas Adams - "Don't forget your towel"

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Joomla site hacked?

Post by brad » Fri Mar 07, 2008 7:59 pm

Nothing to do with that at all.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

User avatar
mihu
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Mon Mar 20, 2006 8:17 am

Re: Joomla site hacked?

Post by mihu » Sun Mar 09, 2008 6:23 am

Is that why my favorite "Official working group blogs" gone?
:-[
bento2go.com - We DO NOT sell bento !!

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Joomla site hacked?

Post by brad » Sun Mar 09, 2008 7:07 am

mihu wrote:Is that why my favorite "Official working group blogs" gone?
:-[
A brief holiday?
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

JasynL1977
Joomla! Fledgling
Joomla! Fledgling
Posts: 4
Joined: Thu Sep 06, 2007 5:14 pm

Re: Joomla site hacked?

Post by JasynL1977 » Mon Mar 10, 2008 6:10 pm

Is the Joomla site down or hacked?

I cannot perform a search, preview the demo, access the latest Joomla 1.5 stable download, or access the extensions page.

Is there something going on over there? It seems the Joomla team is strangely silent on these issues; it actually surprises me. You would think that a web site going down like this, especially one that generates a ton of traffic, would not go unnoticed.

Jason

User avatar
mihu
Joomla! Apprentice
Joomla! Apprentice
Posts: 11
Joined: Mon Mar 20, 2006 8:17 am

Re: Joomla site hacked?

Post by mihu » Mon Mar 10, 2008 6:37 pm

I think it's down. I will try to get someone on it. :pop
Thanks for report.
bento2go.com - We DO NOT sell bento !!

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Joomla site hacked?

Post by brad » Mon Mar 10, 2008 7:09 pm

JasynL1977 wrote:Is the Joomla site down or hacked?

I cannot perform a search, preview the demo, access the latest Joomla 1.5 stable download, or access the extensions page.

Is there something going on over there? It seems the Joomla team is strangely silent on these issues; it actually surprises me. You would think that a web site going down like this, especially one that generates a ton of traffic, would not go unnoticed.

Jason
Perhaps if you posted a new thread on the issue rather than assuming our site is hacked you'd receive a better response. FYI Apache was down and needed to be restarted on one of our 5 servers. Only the Extensions site and the doc.joomla.org site were affected though.

As for us being strangely silent on 'these' issues... I really have no idea what you are hinting at..
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!


Locked