Login|Contact Us
Question and Answer

Programming

Ask a Programming Question, Get an Answer ASAP!

  • Ask A Question
  • Browse Answers
  • Meet The Experts
  • How JustAnswer Works

Hi, I have a site created in Joomla 1.5, my site has been

 
Arty's Avatar
  • Answered by:Arty
  • Computer Software Engineer
  • Positive Feedback: 99.2 %
  • Accepted Answers: 353
Verified Expert
in Programming

Recent Feedback

Positive
Excellent work as always.
Positive
Provided a well-written thorough response that helped me easily understand.
Positive
Quick response. Was very patient with me and explained what I was doing wrong.
Positive
Great work!
Positive
Hey thanks a lot it compiles and runs well.
Positive
Quick and accurate :)
Positive
Awesome!!
Positive
Very quick and professional. Great service!
Positive
a very intelligent man
Positive
Good job

Customer Question

Hi,

I have a site created in Joomla 1.5, my site has been hacked, I would like the site to be restored as was before and the Joomla updated to the latest. I can't log in from the front-end, but have all relevant passwords for ftp and cpanel. Can anyone help with this? If the cost is more please let me know.

site is: www.axioshealth.com


Cheers Peter

 

Optional Information:
Programming Language: joomla

Already Tried:
nothing tried so far

Submitted: 988 days and 4 hours ago.
Category: Programming
Value: AU$90
Status: CLOSED

Accepted Answer

Picture
Expert:  Arty replied 988 days and 4 hours ago.

Chat Conversation Started

Arty :

Hi. You can reset your admin password XX cpanel (in phpmyadmin) by direct update of joomla MySQL table.

Arty :

Do you have phpmyadmin access?

Customer :

yes I have all the passwords for this

Arty :

wait a little, I should start my Joomla site and generate password XXX you

Arty :

you may open Joomla table

Customer :

ok

Arty :

go to jos_users

Arty :

locate 'admin', I'll tell you what to update a bit later

Customer :

sorry Arty, but not sure what I really need to do

Arty :

login to cpanel

Arty :

depending on cpanel config there may be many icons

Customer :

yes Im cpanel now

Arty :

but MySQL admin is pretty standard

Arty :

go there

Customer :

ok

Arty :

are you there?

Arty :

there is a

Customer :

yes im at jos_users

Arty :

you can browse

Arty :

then find admin

Customer :

I have located username admin

Arty :

wait a little, I'm generating password

Customer :

Arty would it be quicker If i give you login details? if this is safe of course

Arty :

not safer

Arty :

this board is open

Customer :

ok

Customer :

maybe if i send you an email with login info it will be quicker for you

Customer :

are you here

Arty :

and we are not allowed to contact directly, sorry. Almost ready

Arty :

that's not difficult, wait a bit

Arty :

I'm back

Arty :

is it working?

Customer :

ok Arty

Customer :

I will try now

Arty :

you may get 'Invalid token', just refresh page then

Arty :

I just tested in my test lab

Arty :

that worked

Customer :

ok

Arty :

how many non-standard Joomla extensions are you using there?

Customer :

i min Arty

Arty :

if it was not password XXXXX force guess, there might be PHP security bug exploit

Customer :

where is sql query tab

Customer :

Im in jos_users

Arty :

ok

Arty :

I'll make a screenshot

Arty :

do you see menu items like 'Browse' 'Structure' 'SQL'?

Arty :

at the top

Arty :

you need SQL

Customer :

I have done this I'm logging in now

Customer :

I get incorrect username password

Arty :

let me try

Customer :

ok

Arty :

it seems I should fix it manually

Arty :

you can put some file to your site

Arty :

with login details

Arty :

then remove it

Arty :

after I get it

Customer :

what do you want me to do, sorry I don't understand

Arty :

so it will not be visible here

Arty :

create a text file

Customer :

yes ok

Arty :

with ftp and cpanel login details

Customer :

with what information

Arty :

then upload it

Customer :

ok where do I put the text file

Arty :

then tell me what is a filename on your site

Customer :

ok got it

Arty :

then you will remove it

Customer :

ok I will give you all information 1 minute so I can fix texst file

Arty :

how did you restore backup and from what source?

Arty :

how old is the backup

Arty :

I wonder why the site keeps saying hacked after restored...

Arty :

I'll also perform security audit and check how it has happend

Customer :

the back up is new, someone else created the site

Customer :

ok

Customer :

where do i upload the file Arty?

Arty :

to your site, anywere where it is accessible from web

Arty :

hmm

Arty :

did you get my response, it seems I have 2 chat windows open

Arty :

you should put it somewhere to your site by FTP

Customer :

yes i got it

Customer :

ok

Arty :

ok, sorry then

Arty :

> I would like the site to be restored as was before and the Joomla updated to the latest

Arty :

do you remember when you did the update?

Arty :

and from which version to which

Customer :

yes, it was last week

Customer :

I also have a back-up on my computer

Arty :

there are complex Joomla steppings procedures to update

Arty :

sometimes

Arty :

so you cant update from 1.5.14 to 1.5.20

Arty :

but you should follow intermediate updates...

Customer :

what to make it more secure

Arty :

sure it should be updated, but more secure is not to be used at all..

Customer :

http://www.eg-design.net/2010/08/04/cpanel-details/

Customer :

above is where the word file is

Customer :

I will delete once you get it

Arty :

got it

Customer :

ok

Customer :

Arty if it costs more to update etc. let me know

Arty :

I can't negotiate price here, so I'd agreed on initial amount, but you may always add bonus after the job is done :-)

Arty :

it seems your admin backend is not standard

Customer :

I guess not, I didn't create the site someone else has, I just got passed the site from someone to update the look, but since transferring host I have this problem

Arty :

I'm started, that may take a while. I'll let you know.

Customer :

ok Ill check back later

Arty :

I should also know cpanel URL

Arty :

it's safe to post it here

Customer :

www.axioshealth.com/cpanel

Arty :

one more question

Arty :

did you update it from 1.0 to 1.5?

Customer :

no I didn't update when I received the job it was already in 1.5

Arty :

can't login to cpanel

Arty :

could you check that login/pass is OK

Arty :

but connected to FTP

Arty :

are they really the same

Customer :

ok

Customer :

yes should be the same Ill check

Arty :

got it

Arty :

it has different URL

Customer :

ok good man

Customer :

very confusing

Arty :

I see there are no backups there

Arty :

in cpanel

Arty :

where did you get your files from?

Customer :

I uploaded from my computer

Customer :

to ftp

Arty :

I'm creating full backup now, before any changes has made

Customer :

thanks Arty

Customer :

Ill check back later

Arty :

I've fixed admin login

Arty :

password XXX to 'password', login is 'admin'

Arty :

try it

Arty :

you should reset it asap

Customer :

HI Arty,

Customer :

I have check the site, problems I have noticed is the Join us doesn't work and also parable says you have to be logged in to view

Customer :

sorry about the wrong information on Joomla version, will you be able to update to more secure version?

Arty :

I didn't know how this worked before

Arty :

so parable should be visible for all?

Arty :

that's all can be done through Joomla admin page

Customer :

yes that is correct, if you view it logged in you will see how it looks

Customer :

I have noticed when you click on join us button the page is not visible you get an error

Arty :

parable is now published

Customer :

ok we are getting there

Arty :

when did you add 'join us'?

Arty :

and who has add it

Arty :

that's incorrect URL used

Customer :

it was added last week

Customer :

I had this problem when I moved the site but someone on here fixed the problem

Customer :

but the url should be axioshealth.com/join_us

Arty :

there is nothing there

Arty :

probably there should be another URL

Arty :

or link to existing article

Arty :

currently it is defined as an 'URL' menu item, not as an article link

Arty :

should it point to 'Join The Global Strategy'?

Customer :

it was there before but not sure what the url was

Customer :

it just had a login for email and name

Arty :

I see this item was in process of editing

Arty :

it is 'checked out' by Anne

Arty :

at the moment of the backup

Arty :

when you did it

Customer :

I think this was the link URL /option,com_letterman/task,subscribe/Itemid,1/

Arty :

so, it might look like now, not fully edited

Customer :

i had this problem when I transfered the site, but someone on here fixed for me

Customer :

I think the link is the one above

Customer :

Also the home page is wrong, if you go to the bottom of the page and click welcome, this is how the page should appear, not the stuff above it.

Arty :

ok, I'll try to fix it

Customer :

thanks Arty

Arty :

that's fixable

Arty :

are you logged in?

Arty :

I should unpublish unneseccary items

Arty :

but I see them locked

Customer :

ill check for you

Customer :

Im out now

Arty :

just ubpublished them

Arty :

should 'prephecy' be visible for registred only?

Arty :

prophecy I mean

Customer :

no

Customer :

If you click on top navigation there should be a page for each

Customer :

this only happened since the hack

Arty :

video should be also open?

Arty :

I've fixed menu up to the 'video'

Customer :

yes

Customer :

ever since the hack everything got messed up

Arty :

still not sure what to do with Join us

Customer :

it should be on the ftp

Customer :

did you look at the old link i gave you

Customer :

URL /option,com_letterman/task,subscribe/Itemid,1/

Arty :

still fixing

Arty :

didn't work with com_letterman befor

Arty :

and your URL is not clickable

Arty :

got it, fixing :-)

Customer :

gee don't know what to say

Customer :

cool

Arty :

done

Arty :

I'm logging out

Arty :

you should change admin password

Customer :

Ok I will

Customer :

will you be able to update to a more secure version of Joomla?

Arty :

the last released Joomla 1.0 is 1.0.15

Arty :

you are on 1.0.13

Arty :

but 1.0.15 still not secure

Customer :

ok, is there anything you can do to make more secure?

Arty :

the problem is not in Joomla itself, but in components, probably you have been hacked through one of them

Arty :

that reqiures more investigation

Arty :

I can update to 1.0.15 for now

Customer :

should I change all passwords including cpanel and ftp?

Arty :

because major updates from 1.0 to 1.5 are non-predictable

Arty :

yes, that's preferrably to change everything

Customer :

ok then, can you update to 1.0.15?

Arty :

ok, I will

Arty :

that may require day or do to perform 1.0 -> 1.5 migration with all bug fixing ..

Customer :

Arty, the only thing I noticed is that the urls are very long and messy is this an easy fix, if not don't worry about it

Arty :

I mean migration bugs

Arty :

yes, that's intentionally

Arty :

that's are native Joomla URLS

Arty :

some links were broken because on SEF URLS

Customer :

ok

Arty :

so I turned it of

Customer :

ok I understand

Customer :

are you finished then arty?

Arty :

after updating to 1.0.15 - yes

Arty :

I'll create a working backup now

Arty :

then update

Arty :

that will be full backup, easily restorable

Arty :

with MySQL data

Customer :

ok, should I change my passwords once you have finished?

Arty :

so even in case of hack, that's easy to rollback

Arty :

yes

Arty :

I guess that will take 20 minutes

Arty :

may be less

Customer :

OK, once you have finished let me know so I can accept answer

Customer :

and change passwords

Customer :

I will be on and off this afternoon

Customer :

so don't worry I will pay you

Arty :

I will also head out soon, but you can write here, I'll see emails

Arty :

after I finish and close this chat

Customer :

OK thanks for your help Arty, I will be back later

Customer :

let me know when I can change passwords

Arty :

all done

Arty :

now you are on Joomla! 1.0.15 Stable [ Daytime ] 22 February 2008 23:00 UTC

Arty :

it is much more secure, there was a major security bug in 1.0.13 that allowed to get access to content of any file on your web

Arty :

you can change passwords

Customer :

thank you for your help, I looked on my cpanel and my disk space is almost all used up, can I delete any files to make more space?

Arty :

I can delete backup

Arty :

or it

Arty :

is better if you download it

Arty :

then delete

Customer :

ok I will do thank you for your help

Customer :

where is the back up stored?

Expert TypeComputer Software Engineer
Category: Programming
Pos. Feedback: 99.2 %
Accepts: 353
Answered: 8/4/2010

Experience: 15+ years of programming, C, C++, Java, PHP, awk, ruby, shell, ASM, Forth, Raptor, M.A.R.I.E, Excel

Ask this Expert a Question >
 
Tweet

2 Programmers are Online Right Now

Ask Your Question Now
Programming Questions Date Submitted
C ProgrammingDecode LabYour assignment is to write a C 4/9/2013
Reference the following instructions to assist you when completing 4/8/2013
First you will present the pseudo code with all the modules 4/8/2013
NA-112 4/8/2013
The first programming project involves completing a program 4/8/2013
RA-201 4/7/2013
This is my final exam for my c programming class. It is due 4/7/2013
Program Description Your program will display (see the sample 4/6/2013
RA-211 4/3/2013
ra-614 4/2/2013
RSS
Next 10 >
Ask A Programmer
Type Your Programming Question Here...
characters left:

Top Programming Experts

See More Programmers

In The News

Nbc
Washington Post
New York Times
Cnn
Learn More

How It Works

  • Ask an Expert
  • Get a Professional Answer
  • Ask Followup Questions
  • 100% Satisfaction Guarantee
Learn More
close
Find Expert answers related to your question.
Sign up using email
We will never post anything without your permission.
Already have an account? Sign in

Ask a Programmer

Get a Professional Answer. 100% Satisfaction Guaranteed.
123 Programmers are Online Now
Type Your Programming Question Here...
characters left:
Disclaimer: Information in questions, answers, and other posts on this site ("Posts") comes from individual users, not JustAnswer; JustAnswer is not responsible for Posts. Posts are for general information, are not intended to substitute for informed professional advice (medical, legal, veterinary, financial, etc.), or to establish a professional-client relationship. The site and services are provided "as is" with no warranty or representations by JustAnswer regarding the qualifications of Experts. To see what credentials have been verified by a third-party service, please click on the "Verified" symbol in some Experts' profiles. JustAnswer is not intended or designed for EMERGENCY questions which should be directed immediately by telephone or in-person to qualified professionals.
Truste
Contact Us | Terms of Service | Privacy & Security | About Us
© 2003-2013 JustAnswer LLC