I just noticed that at the bottom of my home page someone has added some random spam code. Ive looked but can't find what file they added, and im not sure of they are doing something worse than just the nasty code.
Can someone have a look and give me a few tips (or links to posts) that will help me remove this code what thay did?
Thanks people!
URL:
www.australianmma.com.au
Joomla 1.5.26 stable
PHP: 5.2.17
Rockettheme: Zephyr
Note: Scroll to botom of homepage to see code.
I am patched and look ok here. Will be mirating to J2.5 once this is resolved.
[ ] Scan all machines with FTP, Joomla super admin, and Joomla admin access for malware, virus, trojans, spyware, etc -
Is there a remote tool to use for this as I dont host my own website?
[ ] Change all passwords and if possible user names for the website host control panel and your Joomla site -
Done
[ ] Use proper permissions on files and directories. They should never be 777, but ideal is 644 and 755
I did (i think!)
[ ] Check your htaccess for for any odd code (i.e. code which is not in the standard htaccess supplied as part of the Joomla installation).
.htaccess is empty
[ ] Check the crontab or Task Scheduler for unexpected jobs/tasks.
Where is this located?
[ ] Ensure you do not have anonymous ftp enabled
IT is disabled, but I had my credentials in the FTP Layer (I removed this), also I saw an FTP User called "username_logs" in my CP, is this a legitimate user?