Bloody Hackers and Joomla 3 - Forum | JoomShaper
Staff replied Helix Framework

Bloody Hackers and Joomla 3

Asked by PhoenixGB 3 months ago Last activity 3 months ago

HI

Have an old client using Joomla! 3.10.10 - got the custom script hack, removed it, done all updates BUT the Helix Ultimate System and Helix Ajax are both 2015 v3.0.2

Can i just upload the new versions cos theres no way ot update them from updates?

Don't want to have to keep going back and fixing it cos of these dickheads

5 replies

Rashida Rahman Staff

Hi,

We sincerely apologize for the inconvenience.

Are you talking about Helix3 or Helix Ultimate, please? It seems helix3 though!

However, please follow the steps below to resolve the issue for Helix3:

  1. Go to Site Template Styles → Your Template → Template Options → Custom Code → Custom JavaScript.
  2. Check for any suspicious or unknown JavaScript code and remove it. This should remove the injected message if it was added through the template's Custom JavaScript field.
  3. After that, please update both the System - Helix3 Framework plugin and the Helix3 - Ajax plugin to the latest version (v3.1.2).

If you do not see an update notification in your Joomla dashboard, you can download the latest Helix3 package from the following page and install it via Extensions → Install:

https://www.joomshaper.com/joomla-templates/helix3

Best regards,

PhoenixGB Asked this

Rashida I already said i have removed the script, its the helix updates and its an old Joomla 3 site using Travelia v2 from 2017 !!

PhoenixGB Asked this

Thank you Rashida

Rashida Rahman Staff

You are always welcone:)

PhoenixGB Asked this

Cheers Pascal, at the moment it's liking playing Whack A Mole on all my sites, some clients just wont pay for updates and expect everything to be fixed FOC, give them the analogy of servicing ur car, u might get away with it for a few years but when it does break it costs way more - still dont wanna pay. I need a job like sweeping parks and roads aaaarrrgh!

Pascal - HTProtect.org

I developed HTProtect (free extension) for exactly this purpose.

It already protects against all of these vulnerabilities, including Helix Ultimate, and receives protection and security updates automatically via a live feed. That means you don't have to keep the extension itself up to date to receive new protection rules, although it also includes a built-in self-update mechanism.

Just added: https://htprotect.org/en/helix-ultimate

PhoenixGB Asked this

That looks great Pascal, what Joomla versions will it run on, i have clients from 3 to 6 (and that's their mental ages in some cases lol)

Pascal - HTProtect.org

Supports Joomla 2.5 through 6.x and PHP 5.6 through 8.5 (PHP 7.4+ recommended).

Automatic extension updates are available on Joomla 5.4+, as they rely on the Task Scheduler.

Joomla 3 is still fully covered by the Mini-WAF protection rules and security notifications - only automatic extension updates are unavailable due to the missing Task Scheduler.

Paul Frankowski Senior Staff
3 months ago · edited

Using Joomla 2.5 in 2026. It's madness! No excuses.

PhoenixGB Asked this

We ALL know that but some clients think a website is a website is a website and isn't something that needs maintenance. I always try to get them to take a support contract and even compare it to servicing a car, u can get away for years and then whe nit does break it costs a fortune.

Log in to reply.