Sites compromised by mod_araticlhess - Joomla! Forum - community, help and support


hi all

i'm having major problem joomla sites getting compromised nasty little script called wso. installs /modules/mod_araticlhess/mod_araticlhess.php , mod_araticlhess.xml

all server permissions on file system fine. also, joomla version doesn't seem affect this; i've had 1.5.22/28 , 2.5.18 installations compromised. no users created , module not appear on site (although expected)

the uploaded script nasty , allows lot of control on server. seems scan known os/apache exploits. in addition has bruteforce capabilities , can access online rainbow tables break mysql , other services

if point me in right direction how stop extremely grateful

has seen or heard of this? i've done googling appear new script

if no 1 else can , can manage figure out post solution here in case else gets hit

if more detail needed please let me know

thanks in advance

dan

please run , post fpa.
do following familiar mod_administrator, mod_msn, , mod_araticlhess
all fake modules inserted hacker





Comments

Popular posts from this blog

Joomla 3.3 Installation Error message - Joomla! Forum - community, help and support

Multilanguage infinite redirect loop error. - Joomla! Forum - community, help and support

Thread: Wine can't find the cd