Shaper_Doctor Corrupted, Sending Spam Mails - Question | JoomShaper
Black Friday sale is live with flat 50% OFF. Sale ends soon! Grab your deal now!

Shaper_Doctor Corrupted, Sending Spam Mails

FE

Feyzi Erdar

Template 3 years ago

Hi Joomshaper team,

we created 2 Websites with the Shaper_doctor Template for customers. In both cases, the web provider sent an abuse eMail that the index.php would send spam messages. The providers located the index.php as the source an locked the sites.

After I have deactivates eMail sending in the control panel and the forms unter "contacts", the provider unlocked the contents on both sites.

Could you please check the files if there are any vulnerabilities inside?

Pre-thanks

Feyzi Erdar Microsoft Certified Systems Engineer CEO

ERDAR Consulting - IT Center Biedenkopf GmbH Marktplatz 20 · 35216 Biedenkopf T 06461 75875-0 · F 75875-299 www.it-center.biz

0
7 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 years ago #62814

Hi Feyzi,

but "index.php" from what folder? More details please. Becuase index.php from root template folder do not have sending script unless somebody (Russian Hacker?) added it.


I also use this same template for one site, of course with RSfirewall (and .ru locked), and so far, no problems.

-1
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 years ago #62815

BTW

Those "Sent Spam Mails" were in what language, what domains mails? I ask out of curiosity.

-1
FE
Feyzi Erdar
Accepted Answer
3 years ago #62954

Hi Paul,

thx for your replies. Indeed, it´s the index.php in the root directory of joomla. But this file doesn´t contain any code that can cause spam mails - even the required '/includes/defines.php' and '/includes/framework.php' do not contain any code like that.

The provider just sent us the information, that the index.php would cause spam mails - without any further information:

Von: [email protected] Datum: 21. März 2022 um 09:50:17 MEZ An: [email protected] Betreff: Ihr STRATO Paket wurde gesperrt (Auftrag: xxxxxx) Kundennummer: xxxxxxx Auftragsnummer: xxxxx

Hallo Dr. xxxxxxxxxx,

wir haben folgende Funktion/en Ihres STRATO Paketes (xxxxx) vorübergehend gesperrt: Versand von E-Mails durch Skripte in Ihrem Webspace (bspw. Kontaktformular) Zugriff auf Ihre Website

Über Ihr Paket wurden unerwünschte Massen-E-Mails (Spam) versandt. Wir gehen davon aus, dass unbekannte Dritte schadhafte Dateien in Ihren Webspace eingeschleust haben. Die Sperrung erfolgte, um weiteren Missbrauch und Schaden von Ihnen und anderen abzuwenden. Hierzu sind wir im Rahmen der Mitstörerhaftung verpflichtet.

Der Versand erfolgte über folgende schadhafte Datei: ./index.php

Wir konnten diese Datei eindeutig identifizieren. In vielen Fällen werden jedoch weitere Dateien eingeschleust, um die Bereinigung zu erschweren.

Bitte folgen Sie der Anleitung in unserem FAQ-Artikel, um Ihr STRATO Paket wieder uneingeschränkt nutzen zu können: https://www.strato.de/faq/vertrag/anleitung-zur-entsperrung-ihres-paketes

Mit freundlichen Grüßen

STRATO AG | Abuse

E-Mail: [email protected] Website: https://www.strato.de

STRATO AG Otto-Ostrowski-Straße 7 10249 Berlin

Die gesetzlichen Pflichtangaben gemäß § 80 AktG finden Sie unter https://www.strato.de/impressum/

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 years ago #62970

If somehow it was Joomla core index.php (what I doubt) - I don't see our fault. I think they should have more detailed info. I've gotten more info when one of managed sites goes crazy with spam.


Anyway, I recommend start using Firewall component and htaccess security rules.

Security audit is beyond Joomshaper support.

-1
‏‏‎ ‎J‏‏‎‎e‏‎‏‏‎‎n‏‏‎‎s W.‏‏‎
‏‏‎ ‎J‏‏‎‎e‏‎‏‏‎‎n‏‏‎‎s W.‏‏‎
Accepted Answer
3 years ago #62984

0
‏‏‎ ‎J‏‏‎‎e‏‎‏‏‎‎n‏‏‎‎s W.‏‏‎
‏‏‎ ‎J‏‏‎‎e‏‎‏‏‎‎n‏‏‎‎s W.‏‏‎
Accepted Answer
3 years ago #63207

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 years ago #63216

Yes, CMS upgrade may help. But security layers are needed, especially now when we all in EU notice RU attacks 24/7.

0