Announcement

Collapse
No announcement yet.

Website Deleted automatically

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Website Deleted automatically

    Hi ,

    We do have our website devloped in joomla , mysql and we do have hosting with the shared server.

    Now our website content automatically deleted randomly , if i change our ftp password from outside it stops but if i am changing even ftp password from my local LAN website is got deleted.

    Now we are having some vulnerablity in our network or on our shared hosting , that we want to identify.

    We have already done this steps
    1. Installed Licensed Antivirus update it and scan full pc
    2. Install Sonicwall firewall .
    3. Install Antispyware and Anti-malware program
    4. Remove iframe scripts from joomla coding.
    5. implement mod_security in joomla cpanel.

    Now how to catch this vulnerability which capture my ftp user id/password and send's it to outside network intruders so how to capture this ..

    I am really stuck ...please help...

    Kathy

  • #2
    Re: Website Deleted automatically

    I'd look at doing somethng like going to my firewall, blocking all outgoing traffic.
    I'd then specifically allow my mailserver to communicate to outbound port 25, and install a Web proxy that would be allowed to communicate out via port 80 and 443. A corresponding rule would ensure that only this proxy server can communicate on port 80 and 443. Appropriat security on this proxy will ensure that authentication is required.. and you can then log everything as well.

    By this method, you're ensuring that traffic is not passing through your firewall without you knowing about it. That should then help you track down where it is.

    Of course, you should _definitely_ speak to your hosting provide, explain the situation to them, and ask them to review logs - they may be able to say there was a login using appropriate credentials and where it came from, or that there w asn't, in which case there are more problems..
    Please do show your appreciation to those who assist you by leaving Rep Point https://www.petri.com/forums/core/im.../icon_beer.gif

    Comment


    • #3
      Re: Website Deleted automatically

      Hi ,

      I am now preety much confirm that there might be some network threat in my network which capture the user id / pwd while i open my cpanel and delete my website from cpanel .

      As when i am not opening my connection to cpanel inside from my network my website is not getting delete , i mean if i am uploading my changes from my home network the website will stay for longer times ...

      so now i am sure there is some vulnerability in my network , now how can i capture it that particularly from which pc this is happening ...

      Can anyone suggest me any solution to capture this vulnerability.

      Please help,

      Thanks,

      Comment


      • #4
        Re: Website Deleted automatically

        Hi Kathy,

        We are joomla website development company based in India. Since last 1 week we are facing severe problem of joomla website automactically getting deleted. If we open the cpanel or ftp or ninja explorer from our network, the credential somehow gets out and then the websites starts getting deleted. It also seems that process deleting joomla website is joomla aware, because it sometime removes just content, or tables or just selected plugin and sometimes complete website. We also have drupal, wordpress and other development going on,, but those team have faced no problem. This is joomla specific attack. Please do share if you somehow manage to resolve problem. Currenlty we have 2 network security teams working on this issue.

        Comment


        • #5
          Re: Website Deleted automatically

          Which versions of Joomla are you guys currently using?
          Marcel
          Technical Consultant
          Netherlands
          http://www.phetios.com
          http://blog.nessus.nl

          MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
          "No matter how secure, there is always the human factor."

          "Enjoy life today, tomorrow may never come."
          "If you're going through hell, keep going. ~Winston Churchill"

          Comment


          • #6
            Re: Website Deleted automatically

            Hi ,

            I am start using https since 2 days , yet not any single website is got deleted ...hope for the best...

            Thanks ...

            Comment


            • #7
              Re: Website Deleted automatically

              Thanks Kathy,

              WE will try using https connection. Although please do report if incidence still continues. It looks like joomla based websites are being targeted all our place. There are two other companies around us who reported the similar issues. Network security guyz here are reported concerted attack by china based ip addresses on joomla websites.

              Comment


              • #8
                Re: Website Deleted automatically

                Hi ,

                Are you having a shared hosting or a dedicated hosting ...If shared hosting SSH must be required ...you can even ask joomla devloper to make it or purchase from some reputed one...

                Comment


                • #9
                  Re: Website Deleted automatically

                  Again which versions are you using? If you are using older versions, please upgrade due to the many security issues Joomla has.
                  Marcel
                  Technical Consultant
                  Netherlands
                  http://www.phetios.com
                  http://blog.nessus.nl

                  MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
                  "No matter how secure, there is always the human factor."

                  "Enjoy life today, tomorrow may never come."
                  "If you're going through hell, keep going. ~Winston Churchill"

                  Comment


                  • #10
                    Re: Website Deleted automatically

                    Hi ,

                    We are using joomla 1.5.17 , and after taking dedicated server hosting from 1n1 server hosting provider still a week passed away but no internal/external hacker has been removed my site...

                    Thanks SSL

                    Pniraj007.... what about you ...have you purchased ssl at least and made your website fully secure .....

                    kathy

                    Comment

                    Working...
                    X