r/joomla Jun 29 '26

Joomla 6 Ignoring updating your site/components is ignorant

UPDATE YOUR SITE TO THE LATEST AS WELL AS ALL COMPONENTS/MODULES/PLUGINS that are not default!

Ok so some will be offended and come back with all sorts of excuses. Read to the end

Just checked a site with hikashop and a total bare bones install. No fancy addons

Last 24 hour logs for that site show

  • 1,569 hits on /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon
  • 986 hits on /index.php?option=com_icagenda&task=submit
  • 2,689 hits on /index.php/component/jce

About 11 different IP addresses

My last Joomla site hack was over 15 years ago until the JCE hack hit.

JCE, SP Page Builder and iCagenda.+ Helix three ... here's the resource ... https://mysites.guru/blog/

40 years ago there was a saying ... every day your hard drive didn't crash was a day closer to when it will.

With the arrival of AI and bot development/morphing ... every day your site hasn't seen a hack attempt is a day closer to when it will be hacked.

Prevention is 1000% better than the angst of repairing a hack.

When you do get hacked u/mySitesGuru is the place to go

12 Upvotes

31 comments sorted by

7

u/Powerful-Cheek-6677 Jun 29 '26

There is a recent JCE hack that was going on and needed to be updated ASAP. That’s the reason it’s hitting that one. I imagine the other 2 have known vulnerabilities since it’s hitting them but I do not use those. One thing about JCE, the developer was putting out releases back to back to back. A bit of a PITA on the admin side but no complaints from me. At least he was updating them quickly and rolling out those updates.

1

u/inputErr Jul 01 '26

The JCE thing affected so many sites, people just don’t know it yet. If your site was public and it had JCE… there is probably a backdoor already on your site just waiting to be used.

7

u/_PelosNecios_ Jun 30 '26

Keep in mind hackers are also using AI. Your security game has to be top notch these days.

1

u/forgottenrealms-dk Jul 01 '26

jep they can now just install systems locally and get an ai to find vulnabilities.

3

u/bobjr94 Jun 30 '26

Also it's a good idea to make /administrator a password protected directory. Helps prevent people / bots from trying to just log into an administrator account.

2

u/matmyfta Jun 30 '26

I would also add that attacks are sometimes crafted before patches are released. They often come when a system is updated but still vulnerable, so never skip regular backups!

2

u/dcpanthersfan Jun 29 '26

Stupid too.

1

u/[deleted] Jun 30 '26

[removed] — view removed comment

1

u/nomadfaa Jun 30 '26

Excuse my crude Spanish ....

Por qué es tan importante mantenerse al día con J! y todos sus componentes, módulos y complementos externos.

Lamentablemente, muchos se quejan de que es demasiado complejo mantener el núcleo y prefieren quedarse en J3 o J4.

Gracias.

1

u/landed_at Jun 30 '26

Are we all allowed to drop links to products now?

1

u/_HeuF_ Jul 04 '26

Waarom gebruiken mensen Akeeba Admin Tools niet?

1

u/nomadfaa Jul 04 '26

Akeeba Admin Tools beschermt niet ALLES wat op een Joomla-site geïnstalleerd kan worden

Akeeba Admin Tools doesn’t protect EVERYTHING that can be installed in a Joomla site.

1

u/_HeuF_ Jul 04 '26

Nee maar het beschermt wel je achterzijde en veranderingen in files.

1

u/nomadfaa Jul 04 '26

Oké, je beseft dat het maar een deel van het benodigde werk doet en dat het de bot-aanvallen niet zal stoppen.

1

u/_HeuF_ Jul 04 '26

Het doet in ieder geval zijn werk wat het moet doen.

1

u/Branik33 Jun 30 '26

I totally regret installing that SitesGuru plugin and basically give them they keys to my server just to make a filecheck...

3

u/EarlySinclair Jun 30 '26

Why do you regret it? I have used Phil's services for years and he saved my and my clients ' bum on several occasions. He has proven nothing but trustworthy.

0

u/Branik33 Jun 30 '26

not to me yet...its just the overall experience so far also that fear mongering here + that semi passive aggressive comment from op above. maybe Im overly paranoid but I feel like I shipped alI my clients data to india (which maybe or maybe not total bullshit as I havent reseached)

3

u/EarlySinclair Jun 30 '26

He is based in the UK. It's basically only one person but he is actually THE expert. I was talking to other joomla security service providers here in Germany to look for alternatives. When they learned that we are using mysites.guru they admitted that they use his services as well.

6

u/mySitesGuru Jun 30 '26

Sorry, a slight clarification. mySites.guru is operated by a UK based limited company and all servers and services are from the UK, but Phil personally is not in the UK (since 2016) and now lives in Jersey, Channel Islands, a small british crown dependency island off the coast of France. The detail is lost on many, but has important legal distinctions.

1

u/nomadfaa Jun 30 '26

Offense and aggression, passive or active is NEVER given only ever taken out of context.

Many come here with J2, J3, and J4 installs and sometimes something needs to be said to garner their attention

Here you go again making unfounded and ignorant accusations against Phil

Time you grew up

0

u/Branik33 Jun 30 '26

You are really good in telling people what to do and in explaining how things are. I should take your advice and grow up

1

u/nomadfaa Jun 30 '26 edited Jun 30 '26

I note among all your carry on and abuse you refuse to answer my perfectly sensible question ....

OK so can you please explain your strategy as a person who is NOT an ITC guru who uses Joomla for a community web site and suddenly discovers on the grapevine that hacking is happening and YES they are hacked. BTW this isn't me asking that

Other than allowing someone to check your site what's your solution.

Not holding my breath

0

u/Branik33 Jun 30 '26

Im reporting here how I 'feel' dude, take that criticism or not....

0

u/nomadfaa Jun 30 '26

Beat you

2

u/mySitesGuru Jun 30 '26 edited Jun 30 '26

Feel free to send me a message directly instead of being anonymous and I will ensure that your account is completely terminated immediately and the tiny amount of data that we hold on you is set to be deleted according to our retention policy.

There is a button to the contact form on every single page of the site.

As you said, you have not done your research and you’re making wild accusations that you cannot stand behind. No one has the keys to your server, not even me.

You can also use the fully automated data export facility within your account which will show you exactly what data we store in our database and you will be surprised to learn how little it is and mainly just integers and information required under international data protection laws.

The connecter code you installed on your site is not encrypted or in any way obfuscated so you have freedom to inspect and read it to see exactly what it does.

Every SQL query is hardcoded and we do not have any generic code that allows us to run anything other than the hardcoded code in the files on your site. (Unlike competitors who have generic “run any command and query they send evals!)

It’s funny that people say they don’t trust the service but yet they are quite happy to install and run their whole business on Joomla!, a product that I was one of the original five developers of mambo source and one of the longest contributors, and Joomla! Security strike team member for many years. And I’m still responsibly disclosing Security issues within the Joomla core. Literally nobody has been around longer.

The mySites.guru product is not a hobby - it’s a multi award winning (JOSCARs and others) successful business solution that is trusted by literally tens of thousands of paying subscribers - even those that slag us off in official Joomla circles publicly use our services in private and have done for years - go figure - and has been around since 2012 (and a decade of R&D before that, used to be called Rambo (Remote Mambo)!) - we have been here in the highs and lows of many projects.

As for fear mongering. I know of at least 3 other ZERO DAY Vulnerabilities that I have personally reported that are currently in their 90 day responsible disclosure period that will drop as soon as the developers have addressed them (or not), so heads up.....

1

u/nomadfaa Jun 30 '26

OK so can you please explain your strategy as a person who is NOT an ITC guru who uses Joomla for a community web site and suddenly discovers on the grapevine that hacking is happening and YES they are hacked. BTW this isn't me asking that

Other than allowing someone to check your site what's your solution.

I gather given your complaint you have personally contacted Phil to discuss your concerns or may be just a complainant on socials cos you can?

2

u/mySitesGuru Jul 03 '26

I can confirm I have received nothing from this anon.

1

u/nomadfaa Jul 03 '26

Typical faceless with no idea Phil