?
avatar FRECHINFOWEB
FRECHINFOWEB
21 Apr 2017

Bonjour,

Ce que j'ai fait
Installation de la dernière version de Joomla avec le thème VARSITA.

Ce qui s'est passé
Envoi de 127727 e-mails de spam par le composant "com_tags"

Ce qui aurait dû se passer
Aucun envoi.

Autres informations
Nous proposons des hébergements optimisé et un client qui a installé un Joomla sur son espace web s'est retrouvé avec un problème. Nous nous sommes vite aperçu grâce au SPF, DKIM et DMARC installé sur le serveur que le site Joomla ou plutôt le composant « com_tags » à une faille et a été utilisé comme serveur d’e-mail pour envoyer du spam aux gens...

Voir la suite ici : https://www.facebook.com/frechinfoweb/posts/1197945480327986

Cordialement,
L'équipe FréchInfoWeb

avatar FRECHINFOWEB FRECHINFOWEB - open - 21 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - labeled - 21 Apr 2017
avatar FRECHINFOWEB FRECHINFOWEB - change - 21 Apr 2017
The description was changed
avatar FRECHINFOWEB FRECHINFOWEB - change - 21 Apr 2017
The description was changed
avatar FRECHINFOWEB FRECHINFOWEB - edited - 21 Apr 2017
avatar franz-wohlkoenig
franz-wohlkoenig - comment - 21 Apr 2017

@FRECHINFOWEB can you please write in English?

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

Translation with google:

Hello,

What I have done
Installation of the latest version of Joomla with the VARSITA theme.

What happened
Sending of 127727 spam emails by component "com_tags"

What should have happened
No shipment.

Other information
We offer optimized accommodation and a client who has installed a Joomla on his webspace and ended up with a problem. We quickly found through the SPF, DKIM and DMARC installed on the server that the site Joomla or rather the component "com_tags" to a flaw and was used as an e-mail server to send spam to people ...

See more here: https://www.facebook.com/frechinfoweb/posts/1197945480327986

Regards,
The FréchInfoWeb team


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

avatar zero-24
zero-24 - comment - 21 Apr 2017

@FRECHINFOWEB it would be great if you could share any details you have with us.

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

Translation with google:

Other information
We offer optimized hosting and a client who has installed a Joomla on his webspace and ended up with a problem. We quickly found through the SPF, DKIM and DMARC installed on the server that the site Joomla or rather the component "com_tags" to a flaw and was used as an e-mail server to send spam to people ...

See more here: https://www.facebook.com/frechinfoweb/posts/1197945480327986

Regards,
The FréchInfoWeb team


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

avatar zero-24
zero-24 - comment - 21 Apr 2017

it would be great if you could offer details about the problem. And not repeat what you have posted above ?

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

Vous voulez quoi comme information ?

Cordialement,
L'équipe FréchInfoWeb

Translation with google:

Want what as information?

Regards,
The FréchInfoWeb team


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

Je n'ai que ça comme information :

J'ai parcouru les journaux de messagerie et j'ai constaté que le répertoire "public_html/administrator/components/com_tags/helpers" a envoyé 127727 messages depuis le début du journal.

Translation :

I scanned the mail logs and found that the public_html/administrator/components/com_tags/helpers directory has sent 127727 messages since the log started.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

avatar joomla-cms-bot joomla-cms-bot - change - 21 Apr 2017
Title
Spam emails by "com_tags"
Une faille sur la dernière version de Joomla a été trouvé grâce à la configuration de nos serveurs.
avatar joomla-cms-bot joomla-cms-bot - edited - 21 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 21 Apr 2017
Title
Une faille sur la dernière version de Joomla a été trouvé grâce à la configuration de nos serveurs.
Spam emails by "com_tags"
Priority Critical Medium
Status New Discussion
avatar joomla-cms-bot joomla-cms-bot - change - 21 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 21 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 21 Apr 2017
The description was changed
avatar joomla-cms-bot joomla-cms-bot - edited - 21 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 21 Apr 2017
Title
Une faille sur la dernière version de Joomla a été trouvé grâce à la configuration de nos serveurs.
Spam emails by "com_tags"
avatar zero-24 zero-24 - change - 21 Apr 2017
The description was changed
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2017-04-21 16:46:12
Closed_By zero-24
avatar zero-24 zero-24 - close - 21 Apr 2017
avatar zero-24
zero-24 - comment - 21 Apr 2017

In that folder is just one single file: https://github.com/joomla/joomla-cms/blob/staging/administrator/components/com_tags/helpers/tags.php Which does nothing with mail sending.

This more sounds like a hack to me. Please contact someone that can help you with hacked webseites. https://resources.joomla.org/en/category/joomla-security

If you need assistance with fixing your site, please contact the person or company that originally setup your site. If this is not an option, and you still require assistance, our resources site contains lists of possible consultants.

Please note: Joomla! and Open Source Matters, are not able to recommend a specific person, or company for assistance.

I'm closing this for that reason. thanks for contacting us.

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

Entendu,

Après ce n'est pas moi qui l'a installé mais suivant les dates de création, tout à été installé en même temps et il y a 3 fichiers dans ce dossier, celui que vous avez dit mais également "db78.php" et "index.html"

Cordialement,
L'équipe FréchInfoWeb

Translation :
Heard,

After it was not installed, but according to the creation dates, everything was installed at the same time and there are 3 files in this folder, the one you said but also "db78.php" and " Index.html "

Regards,
The FréchInfoWeb team


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

avatar zero-24
zero-24 - comment - 21 Apr 2017

yes this db78.php is not from the core. So it looks like you are hacked.

avatar FRECHINFOWEB
FRECHINFOWEB - comment - 21 Apr 2017

ok think you


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/15459.

Add a Comment

Login with GitHub to post a comment