JoomlaPlug!

JoomlaCloner - Backup and Restore Component

OOPS. Your Flash player is missing or outdated.Click here to update your player so you can see this content.
JoomlaCloner - Joomla backup and restore

 
 
JoomlaPlug.com
Welcome, Guest
Please Login or Register.    Lost Password?
I WAS HACKED! (1 viewing) (1) Guest
Go to bottom Post Reply Favoured: 0
TOPIC: I WAS HACKED!
#5255
tittiger (User)
Junior Boarder
Posts: 30
graphgraph
User Offline Click here to see the profile of this user
I WAS HACKED! 1 Month, 2 Weeks ago  
If you have not patched to Joomla v1.5.7 I strongly urge you to do so. Thankfully I had some recent backups that saved my butt. This event has raised some questions with me though:

1.) I was surprised when I restored that my restore included a copy of all the previous backups! No wonder the darn thing was getting so big (around 30 megs) Is this the default configuration these days? I did not see where to not include all the other backups in the current back up....

2.) My ISP told me that the original hack was about a month ago so I do not know whether or not to trust my backup! May I suggest the addition of some form of CRC of the directory files so that you can easily tell if someone has changed these files and which ones had been altered?

3.) Does is there a write up or instructions on implementing a cron script on GoDaddy. I am clueless and don't even know how to begin, other than noticing something in their control panel about cron scripts but don't even remember where.
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#5256
admin (Admin)
Admin
Posts: 2449
graph
User Online Now Click here to see the profile of this user
joomlaplug JoomlaPlug.com
Re:I WAS HACKED! 1 Month, 2 Weeks ago  
HI there! Regarding issue 1), you should set to No the "Include other backup files" option from the JoomlaCloner Config and see if you have anymore issues, and also make sure you are running the latest version of our backup software

Regarding 2), indeed, that is a nice feature, we will work on implementing it!

As for issue 3), in the JoomlaCloner/XCloner backend there is a left menu link called Cron, you can find there further details, but if you still have issues, you can open a support ticket and let us setup the cron for you

Regards, Ovidiu
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#5258
tittiger (User)
Junior Boarder
Posts: 30
graphgraph
User Offline Click here to see the profile of this user
Re:I WAS HACKED! 1 Month, 2 Weeks ago  
That is what is really strange: "Include backups directory in clone: " is set to no and all of my backups were still included in the restore. Something is definitely not making any sence because from a 30 megabyte backup file when I restore - I have 15 different backups showing that are at least 30 MB each! There is no way the compression is that good! Or are you just storing the differences between the files as in a conventional differential backup? But hiding that fact from the end user and making it look like 15 complete backups?

I am just perplexed both by the switch not working and also how 15 huge files are fitting into one 30 MB archive.

Thanks for considering the CRC I never saw the need until after being hacked and then told by my ISP that I was really hacked over 30 days ago and that all of my intervening backups might be worthless.

I am going to try and handle the Cron issue my self. Perhaps if I get time I will do a write up on it and see if it helps anyone else.

Thanks,
Ovidiu
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#5259
admin (Admin)
Admin
Posts: 2449
graph
User Online Now Click here to see the profile of this user
joomlaplug JoomlaPlug.com
Re:I WAS HACKED! 1 Month, 2 Weeks ago  
The created backups there are full backup with all your site files, have you tried downloading them on your computer? If their size is relatively the same, then no other backups are included in those files, try and recheck that with a clean restore location

Ovidiu
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
#5260
tittiger (User)
Junior Boarder
Posts: 30
graphgraph
User Offline Click here to see the profile of this user
Re:I WAS HACKED! 1 Month, 2 Weeks ago  
Yes they are really there! I FTP'ed and looked in the directory /truthtribune/administrator/backups/

I also DL'ed a few of them. This makes no sence what so ever - as I have 15 - 30 meg files that came out of one 30 MB restore. Which is impossible! A screen capture from FileZilla showing these files is at this location:

http://docs.google.com/Doc?id=dcmqs8s2_104d6bdwp5t



I also discovered another seperate issue:

On one restore - your script deleted the 3 files that you start with for the restore, and the other script the one that did not hang up did not delete the 3 files - so I went in and manually deleted them.
 
Report to moderator   Logged Logged  
 
Last Edit: 2008/10/07 23:06 By tittiger.
  The administrator has disabled public write access.
#5261
admin (Admin)
Admin
Posts: 2449
graph
User Online Now Click here to see the profile of this user
joomlaplug JoomlaPlug.com
Re:I WAS HACKED! 1 Month, 2 Weeks ago  
Weren't those backup files already present in that backups directory? that would explain why they were there after restore! The restored files size is correct if the backup is a .TAR type which is not a compressed archive

As for the delete issue, neither XCloner nor Joomla.Cloner.php can delete themselves, i would advise to check for something from your server or maybe some other user interaction

Ovidiu
 
Report to moderator   Logged Logged  
  The administrator has disabled public write access.
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop

Search JoomlaPlug.com

Download Joomla

All rights reserved to JoomlaPlug.com ©2006-2008!
Site powered by Joomla!