I need help fixing a vunrability within my clients website

Status
Not open for further replies.

1337WuLF

Senior Member
Joined
Jan 3, 2011
Messages
1,028
Reaction score
436
One of my clients websites has a vulnerability within it which allows spammers to upload an SMTP mail send script which is sending out thousands of spam emails a day. I've tracked down where the files are that are sending the spam, however I'm not sure how the hackers are getting in.

Anyone able to help? The website is running Joomla.
 
I had the same issue on WP, good thing my hosting provider managed to figure it out.
 
Maybe this will help.

Thanks, although I can't make heads or tails of that :P

send me a pm or add me on skype, able to help you out on this one!

Added you on Skype :)

I had the same issue on WP, good thing my hosting provider managed to figure it out.

My hosting company has been somewhat helpful, although they refuse to fix the actual vulnerability :(

There are many ways to get in. The Wordpress plugin / slider Revslider is one and it is well spread

Otherwise, nulled themes / nulled plugins are also a highway for these kind of backdoors. As you mentionned, it isn't necessary the spammy file which is the source of the issue.

You can take a look at the link below only if you are using Wordpress : http://www.host-stage.net/client-ar...w-to-secure-your-wordpress-based-website.html or even here : http://codex.wordpress.org/Hardening_WordPress

My site is running Joomla.
 
May I ask which is your hosting provider?

www.vpsblocks.com.au - They've been somewhat helpful with the problem, but certainly didn't aid me in solving it completely.



I found this website: http://myjoomla.com/ - From there I was able to run an audit which was quite helpful, although that didn't fix my problem either. I decided to just contact them and Phil fixed it up and removed the vulnerability within about 6 hours of placing the ticket with them. Pretty impressive.
 
Status
Not open for further replies.
This thread has been auto closed due to the forum's thread age policy. Read more.
Back
Top