Wp-content In Joomla 4 - Question | JoomShaper

Wp-content In Joomla 4

S

Schwyzer

Helix Framework 10 months ago

Hi, I have e big problem......in different customer-Joomla4-orders, there is suddenly a wp-content-order in Joomla 4....that meens, this Joomlas will be hacked.

My Hostar meens, it could be beauce of the Helix-Plugin, which I use for all my customers...I use Helix Ultimate and SP Page Builder......even all Joomlas are updated ....a few days later this ordner wp-content will be again in the Joomla....

Does anybody have this same problem?

Hope, you can help me..

Kind regards, Maggie

0
20 Answers
S
Schwyzer
Accepted Answer
10 months ago #119077

so, you mean my code in the htaccess will fix my problem... or do i have to write another code.. thanks for your help.

0
Pavel
Pavel
Accepted Answer
10 months ago #118944

Hi.

Where exactly in the code does this appear? I don't think this is a hack. Hacking does not look like that. There is no sense in this. Most likely, they simply copied the content from the WP website and did not clean its code before inserting to Joomla editor. Especially it happens if the content was copied from the WP page made through Elementor

0
S
Schwyzer
Accepted Answer
10 months ago #118947

Hi Pavel

WP-Content appears as a ordner in Joomla.....and I never used Worpress.....all those Joomla I migrated from Joomla 3 to 4....and I don't know Elementor .....hmm....it happens also in a new Joomla4 installation...a few days later.....and I use always helix ultimate...the newest version...

It is strange to have this problem in different websites. Even I delete this ordner.....a few days later it happens again....changed the password...it doesn't help....

0
Pavel
Pavel
Accepted Answer
10 months ago #118949

appears as a ordner in Joomla.....

I don't understand this your description. A correctly asked question is 50% of success to obtain the correct answer.

and I never used Worpress

I'm not saying that you are using WP. I say that you could copy content from another site that uses WP and add by this action the garbage code to the Joomla editor

0
S
Schwyzer
Accepted Answer
10 months ago #118952

in the joomla administration there is an ordner called wp-content ... i will send you a picture as soon as i have this problem again

0
S
Schwyzer
Accepted Answer
10 months ago #118953

its a folder in joomla.. sorry for my english

0
Pavel
Pavel
Accepted Answer
10 months ago #118954

A little clearer. In this case, this requires an investigation that is not possible to conduct within the framework of the forum. And I do not think that this is somehow connected with Helix. If this is a hack, then hacking goes from the side of the server, not the site.

0
S
Schwyzer
Accepted Answer
10 months ago #118956

hmm... they told me its not a server problem...

so i need to ssk in a joomla forum

0
M
Marco
Accepted Answer
10 months ago #118968

this is a hack something similar happen to me a year ago..

0
S
Schwyzer
Accepted Answer
10 months ago #118998

how did you fix it?

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 10 months ago #119003

Hi there,

I appreciate you reaching out. I sincerely apologize for this oversight. I have checked files and folders. But, there is no code of WordPress related.

-Thanks

0
S
Schwyzer
Accepted Answer
10 months ago #119030

yes, i fixed it yesterday.., but i am afraid it happens again in a few day, like before

0
S
Schwyzer
Accepted Answer
10 months ago #119046

I found something in Joomla-Forum....they told me to add this code to the .htaccess-datei:

<Files wp-login.php> Order Deny,Allow Deny from all </Files>

I will see, if this helps....

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 10 months ago #119051

Maggie, If I may....

Spam/hackers bots scan random websites and they make php requests, they do not check what CMS is .. just do they job. It's like a thief who walks around and grabs handles.

On my Joomla firewall logs I had a lot of WP request even 2-3 years ago.

Nothing to worry by now, you have to just lock them via htaccess rules and lock IP one by one.

p.s.

If you are using WordPress CMS somewhere there are methods to hide login URL etc..

0
TF
Thomas Fischer
Accepted Answer
10 months ago #119202

<German Text at the bottom>

If these folders always re-appear, you might have a more serious problem. As i don't have details about your server it is hard to say, where the problem exactly lies, but it could be that the Administrator account is compromised, that has access to all the client sites.

The "Hacks" usually consist of an uploaded PHP File, that then downloads an actual payload. The payload has no easy readable code inside, either base64-encoded or a mixture of hex and dezimal values. For WP it would be for example the ini.php. Mostly these exploits are used to control the server and/or to send a ton of spam over it. Check the mail queue of the server in question. If you get a ton of bounces and potentially a mail queue with thousands of mails in it, the server is definitely compromised. In that case each site needs to be checked. There are also many other logfiles available, that can help to identify the problem. This is a very good example, why virtual servers should be running in a jail, so if one gets compromised, the others are safe unless they can be as easily compromised.

Hi, wenn die Ordner immer wieder auftauchen, könntest du ein etwas größeres Problem haben. Da ich aber keine Details über den Server habe, ist es schwer hier etwas genaueres zu sagen. Der Account des Admins könnte kompromitiert sein, der auch Zugriff auf alle Client Home Ordner hat.

Die "Hacks" arbeiten in der Regel so, dass eine Datei auf den Server geladen werden kann, die dann wiederrum einen File Drop runterladen und ihn im System verankern. Das kann auch so gemacht werden, dass man auf der eigentlichen Seite nichts sieht. Schau dir mal die E-Mail Queue der Kunden an. Wenn du tausende Mails in der Queue hast, ist das schonmal ein sicheres Zeichen, dass der Server zum Spammen genutzt wird. Auf dem Server gibt es auch jede Menge Log-Dateien, die weitere Infos beinhalten können. Das ist ein Paradebeispiel, warum man Kundenseiten immer in einer Jail laufen lassen sollte. Somit können andere Seiten nicht "befallen" werden, wenn eine Seite kompromitiert wird. Das Bereinigen eines Servers kann eine recht aufwendige Sache sein, die auch einiges an Zeit in Anspruch nimmt. Der Server muss im Grunde genommen eine recht lange Zeit überwacht werden und evtl. bestimmte Netze blockiert werden. Persönlich filter ich Netzverkehr von bestimmten Ländern raus. Niemand aus China hat zum Beispiel etwas auf meinem Server zu suchen. Und falls es doch mal jemand geben sollte, dann hat er halt Pech gehabt. 99,99999999% vom Traffic sind aber halt nur Angriffe und da habe ich keinen Bock drauf, also werden alle APNIC Netze blockiert.

Wenn du Hilfe benötigst, finden wir sicherlich eine Lösung in Kontakt zu geraten.

Tom

0
S
Schwyzer
Accepted Answer
10 months ago #119205

Hallo Thomas

Vielen Dank für Deine ausführliche Information. Ich werde Deinen Beschrieb meinem Provider zustellen und hoffe, mit ihm dieses Problem stoppen zu können.

Vielen lieben Dank.

Gruss Maggie

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 10 months ago #119232

The problem of website security is a very complex one, and it's getting more challenging every year. Sometimes the problem is a poorly secured server, sometimes the website CMS or installed extensions .... there are many windows through which a potential GOOD hacker can get in.

0
S
Schwyzer
Accepted Answer
10 months ago #119236

Yes Paul, as Thomas wrote, its very complex... I have to be careful not to lose the fun with it....

Now I hope with this order in the htaccess-datei:

<Files wp-login.php> Order Deny,Allow Deny from all </Files>

it will be fixed....I will see.....

0
TF
Thomas Fischer
Accepted Answer
10 months ago #119556

Maggie,

you still need to identify where this is coming from. Of course mitigation is also important, but the root cause needs to be fixed as well.

As Paul said correctly, IT-Security is an extremely complex area of IT in general. Especially if you work with something like Joomla and also rely on 3rd party extensions. Each piece of software you install increases the risk and you never know how serious a developer of an extension takes security and updates. Out of 30 years experience in IT i have 20 years in IT-Security and even I say, i only have a little bit of knowledge in this area.

So good luck with the server. And if the Hoster is not playing ball, there are many more out there ;).

Tom

0
S
Schwyzer
Accepted Answer
10 months ago #119579

Hi Tom Yes, I will try it with my hoster.....it won't be easy....

It makes no fun again.......

Have a good day. Maggie

0