By Chantal Schlatter on Tuesday, 09 June 2015
Posted in Technical Issues
Likes 0
Views 759
Votes 0
Hi,

one of my site uses easyblog. It runs with joomla 2.5xx and I didn't want to upgrade it because I use it only until August 2015. But the site is beeing hacked, although I have OSE security suite installed. I get the IP Adresses of the hackers and put them on htaccess.txt but there come attacks with new IP adresses. They create themselfes super users and post blog entries.
Is this because the site is running with joomla 2.5? Is there anything I can do reagarding easy blog to protect me from that? I tried to install the latest easy blog version but it failed.

Thank you,

Chantal
Hello Chantal,

Perhaps if you can provide us with your Joomla backend and FTP access we could figure out what causing the site to be vulnerable to attack. Please advise.
·
Tuesday, 09 June 2015 10:49
·
0 Likes
·
0 Votes
·
0 Comments
·
Of course, thank you.
See below.
But I deleted all wrong posts and users. But I am sure it wont take long until they start again.
·
Tuesday, 09 June 2015 11:06
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Chantal,

I've checked your user level settings for "Registered" user group and it seems like the user group has the "Super User" permission checked as you can see from my screenshot here, http://screen.stackideas.com/2015-06-09_1847.png . Hence they will be able to access your administrator area while having super user privilege. I've removed super user privilege for the registered user group and it should be working fine now.

I also have disabled "publish entry" from the easyblog ACL settings for registered user group so that they won't be able to publish the new blog post without your permission. You can always change it back the setting from backend > easyblog > ACL > registered > publish entry, http://screen.stackideas.com/2015-06-09_1852.png .

Hope these help.
·
Tuesday, 09 June 2015 18:52
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Ezrul,

Thank you so very much!

Have a good day (or night?) :-)

Chantal
·
Wednesday, 10 June 2015 05:11
·
0 Likes
·
0 Votes
·
0 Comments
·
I'd also check in with your host. While hardening security on this side is a must, most hosts can and will help. I know my host, HostGator wants to know about hacks and vulnerabilities.
·
Wednesday, 10 June 2015 09:14
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi David,

you are certainly right. I'll do that.

Chantal
·
Wednesday, 10 June 2015 09:19
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Chantal.

You're welcome. Have a nice day
·
Wednesday, 10 June 2015 11:52
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post