Questions?

Monday - Friday
9AM to 5PM Eastern (GMT-5)

Latest Blogs

Testimonials

Randy Taylor“Jacob is a team player and continues to be an excellent resource for me to innovate the best avenues and ideas in supporting and continued maintenance of our various technical application needs.  I highly recommend Jacob to anyone seeking a creative, high level internet applications professional.”
Randy Taylor
Dot2Dot Retail Group

Henry A. BromelkampJacob did a great job on the technical side of migrating our web site to a new version of software and adding some functionality. He was a great help!
Henry A. Bromelkamp
President at Bromelkamp Company LLC

39 more testimonials more testimonials on LinkedIn

Who's Checking Us?

We have 1 guest online

FreshBooks

We are now IDL Web Inc.

We've expanded our team and rebranded our company.

Our goal is still the same, to provide outstanding customer service.

Continue to IDL Web Inc - Expert Joomla & WordPress Developers

Joomla Blog

Subscribe to feed Viewing entries tagged hack

Joomla 1.5/2.5 - Buy Generic Viagra Fix

Posted by Jacob Hodara
Jacob Hodara
User is currently offline
on Monday, 03 March 2014
in Security 0 Comments

A new variation of the Viagra hack has emerged.

It has affected both Joomla 1.5 and Joomla 2.5

The cause may not be a result core Joomla 2.5 (1.5 no longer supported as of Fall 2012)

Hack Description

The hack creates hidden URL on your site, example: www.yourdomain.com/buy-generic-viagra

Removal of Hack

Edit .htaccess, locate and remove these lines:

RewriteRule image.php - [L]
RewriteCond %{REQUEST_METHOD} (GET|POST)
RewriteCond %{SERVER_PORT} 80
RewriteCond %{REQUEST_URI} !(login|auth|register|secure|admin|image.|config.|include) [NC]
RewriteCond %{HTTP:servers} !(true)
RewriteCond %{REQUEST_URI} (corestemsw|ialis|iagra|cachecontrl) [NC]
RewriteRule ^.*$ /templates/system/images/image.php [L,NC]

Also remove the file: /templates/system/images/image.php

Removal URL from Google

Your URL will still be index by Google. Use Google Webmaster Tools and submit a request to remove the mentioned URL.

Your next action:

Upgrade to latest Joomla 2.5/3.x immediately. As well as upgrading all 3rd party components, unpublishing any unused components.

Hire an affordable Joomla expert

For your free, no obligation estimate please contact us today.

Hits: 18488
0 votes

Joomla 1.5.x Viagra Hack Information and Fix

Posted by Jacob Hodara
Jacob Hodara
User is currently offline
on Tuesday, 27 March 2012
in Security 4 Comments

In the past week alone we've had two clients reach us about their site being hacked.

The hack injected numerous "Buy Viagra" links into their websites right below the tag. The hack only displays for User Agent Googlebot, that means if you are using Fiirefox or Internet Explorer you will not see these links when viewing the source code, only Chrome.

Upon further investigation, comparing site and original Joomla 1.5.x source code we've located the file to be located in:

Tags: hack, joomla, security
Hits: 28365
0 votes