× Joomla Facebook Connect support forum

Topic-icon mod_jfbcfan hacked

Active Subscriptions:

None
15 years 2 weeks ago #10422 by iveth
mod_jfbcfan hacked was created by iveth
Hi
My mod_jfbcfan was hacked, here is what I got:

It has come to our attention that you are hosting a fraudulent "phish"
website that is attempting to steal account information from customers of
M&T Bank. The URL of the fraudulent site is as follows:

www.domain.org/modules/mod_jfbcfan/mandt/index.html

I really like jfbc connect so can these issues be fixed, thanks let me know, I will disable until further notice
The topic has been locked.
Support Specialist
15 years 2 weeks ago #10430 by alzander
Replied by alzander on topic mod_jfbcfan hacked
Iveth,
We do security checks on every release of JFBConnect and follow all Joomla best-security practices. I truly don't believe that, if you were hacked, it was through the JFBCFan module. In over 2 years, we've never had a report of a severe security vulnerability which would let an intruder modify the local database or file-system, and we've never been listed on Joomla's Vulnerable Extension List (VEL).

The JFBCFan module itself doesn't write to your database and doesn't take any user-inputs at all (by using the query string or other). Both of these are common ways that can be used to hack a site if the extension is not coded properly.

Also, when any extension does have a vulnerability, it usually opens up your whole site for malicious activity. So, if extension "a" is vulnerable, it's very easily possible for a bad person to put a file in any directory on your site, including one that's part of JFBConnect. That doesn't necessarily mean that the location of the unwanted files is the source of the entry point.

With that said, some obvious things to check are:
* Do you have any extensions which are listed on the VEL? Please note that extensions are removed from the VEL about 6 months after any hole has been patched, so it's also best to visit any extension vendor's page that you're using to make sure that you're up to date. If not, check their changelog for security fixes between the release you have, and the most recent version:
docs.joomla.org/Vulnerable_Extensions_List

* Are any of your directories set to the permissions of 777? Definitely look at the /modules/mod_jfbcfan directory, but you should look at every directory on your site. If any directory has open permissions, then a bad script can be uploaded there. Once there, it can be executed and do anything, including copying files to other directories.

* Look through you filesystem for other unknown/unwanted files. They may be similar to the files in the mandt directory you mention above, but may not be. If you find any, you really should re-do your whole site. There's a lot of great instructions on how to do this (don't just restore an old backup), and the most recent and thoroguh post I've seen is:
forum.joomla.org/viewtopic.php?p=2508716#p2508716'

Finally, where did you get that message? Was that an email? I found Mandt Bank's webpage, but am curious if they provide any information about what they detected or what the know.
Also, I'm assuming there were files in that directory that you mentioned. Do you know anything about those files, and have you deleted them yet?

Hope this helps you get started, and if you have any indications, other than the directory, that the Fan module was involved in the intrusion, we'll be happy to help further.
The topic has been locked.
Active Subscriptions:

None
15 years 2 weeks ago #10433 by iveth
Replied by iveth on topic mod_jfbcfan hacked
Alazander

Thanks for all you information, I have scanned the whole site and it seems to be ok now, using oseanti virus, must admit it could have been a chmod issue, I do have some file from the server that I have zipped if you would like to look at it, please send me an email for sending it to..
The topic has been locked.
Support Specialist
15 years 2 weeks ago #10436 by alzander
Replied by alzander on topic mod_jfbcfan hacked
Sure, we'll gladly take a look, but likely they won't be anything that will pinpoint the cause.. just the effects. Send them (zipped) to This email address is being protected from spambots. You need JavaScript enabled to view it..

Thanks,
Alex
The topic has been locked.