Hi,
Our all websites were virused throught sp page builder. we clean all of them, removed lines from htaccess, removed from cron and more.... 24h it was ok, no it's happen again, and we have the latest version.
And ideea? help?
Hi,
Our all websites were virused throught sp page builder. we clean all of them, removed lines from htaccess, removed from cron and more.... 24h it was ok, no it's happen again, and we have the latest version.
And ideea? help?
Hi,
Follow (many tips, suggestions, codes, tools) >> https://www.joomshaper.com/forum/question/45152
If you updated everything, you need:
Thaks, i did all.... now it's again ....
Hi,
Thanks for contcating us. You can also check this
https://github.com/zkrana/joomla-security-scanner
-Regards.
If you would have good firewall component hacker couldn't upload any malware file. It means that:
Thank you,
Can be also in databse?
because from what i see:
Yes. Two users mentioned about that possibility in topic that I shared.
Maybe recover whole website from backup: 5 or 10 days old before The D-Day.
If you made any big content changes in last 72h, you can keep only SPPB table from it, and whole rest should be taken from "the past".
This is screenshot from firewall (today) they are still trying but their IP is locked each time. And since 15 June, no infections anymore.

my settings

It's enought to have this in htaccess?
##
# Emergency block - SP Page Builder uploadCustomIcon exploit
# Blochează requesturile către:
# index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
##
RewriteCond %{QUERY_STRING} (^|&)option=com_sppagebuilder(&|$) [NC]
RewriteCond %{QUERY_STRING} (^|&)task=(asset\.uploadCustomIcon|asset%2euploadCustomIcon)(&|$) [NC]
RewriteRule ^ - [F,L]
In databases what i find is new users created, so is creating new users and from here will create new rules...
That's not quite enough; it's definitely worth adding additional rules in .htaccess to the /images, /media, and /file folders as well—as we mentioned in the thread mentioned earlier — to protect them from unauthorized .php files.