Hi, I have several sites hacked by this f#@$er dr timor..I am at a loss as to how he hacked me and how to fix this..i believe the hack is only affecting the index.php and any help would be very appreciated. my server guys are very annoyed with me but i have no permissions set to 777 and have captchas on all contact forms.. .... please help if you can.
Cheers
NB
Usually these hackers target old versions of Joomla or unsecure extensions. First rule is to stay up to date. Second rule have a good back up regime. :cheesy:
I have used the extensions from OSE and they have worked well. You can find out more here -
OSE Joomla anti-hacker
.
I use their security suite and this will also scan your site files for usual viruses and clean files. Great value for money and their support is good too.
Hope this helps
Please search forums before posting. Please make sure your post includes the version of the CMS you are using and a link to the problem. Annotations on screenshots can also be helpful to explain problems/goals. Please use the "secure" tab for confidential information
I Googled the phrase 'Hacked by Dr. Timor', and this guy has been BUSY. There are a lot of sites that have been hacked, and they are still up and running. The owners don't seem to know that they have been hacked.
Thanks for the replies guys..... I cleaned the sites of his index.php file (its about 5.3kb instead of the usual 2kb) and replace it with fresh index.php strengthen up all the sites admin login names and passwords... also made sure all forms have a captcha attached and am installing OSE on your good advise. Thanks again, it gave me some grief and worry and a lot of work but I guess the hacker guy is just mad at the world.. but it taught me a good lesson. Secure your sites and make backups.
Cheers
NB