Update on the hacked Joomla! website

In a previous post we looked at a business website which had been hacked. Before making the post we had contacted the site owner and advised them that their site had been compromised. The response we received was:

We know about it, it is due to old version of Joomla it is not our component problem, we plane to set up latest Joomla CMS, ok, we have fixed this problem, what you think about our component?

So what would you think about using a component from a business which knows its website has been hacked, fails to respond quickly to the hack, and then assumes that simply installing the latest version of Joomla! is the answer to the problem? Compare the above response to the thorough investigation documented here by another business site. The impressive and professional response by the second company comprised:

Example of Step-by-Step Actions to Clean up a Hacked Joomla! Website

  1. How I noticed something was wrong
  2. What is Microsoft ‘Remote Data Services Data Control’?
  3. HTTP Debugging with Fiddler
  4. ‘Yourgoogleanalytics’ and ‘Statscounter’??
  5. Checking the Javascript files
  6. Preventing further infection
  7. Telling the Web Hosting Provider
  8. Checking my Desktop PC
  9. Securing the Web Hosting Account
  10. Tracking Down Hacking Attempts
  11. Online Tests for Malware in a Website
  12. Removing Google’s ‘This site may harm your computer’ Warning

The security of our customers websites matters to us. Had the hacked site responded in a similar way to the professional response described above, we might have continued to evaluate their component. Instead their code remains untested, the downloaded zip file has been deleted from our system and we are evaluating alternative solutions to the customer’s requirements.

About these ads
This entry was posted in Joomla! website security and tagged , , , . Bookmark the permalink.