Backdoor on all my joomla sites DOORWAYISWORKCONTENT - Joomla! Forum - community, help and support


i have problem backdoor. sites has "legacy.php" file inside library folder code:
doorwayiswork
====================
doorwayisworkcontent";}if(!empty($page)&&!empty($clienttype)){if($q!="this-is-the-test-of-door")

and 1 cache folder.

what causing backdoor on joomla sites? extension problem or joomla issue?
i keep updating extensions , joomla sites , folder privileges right, passwords strong.

what can do?

if date , extensions you're using not in joomla vel, can think of following 3 possibilities:

- template vulnerable
- there hack in cron.
- have php backdoor file somewhere on website causing mess.

check template malicious entries, check cron jobs (both in cpanel , whm), , finally, scan website (using maldet) backdoor files. (please note maldet not 100% accurate - it's still good.)





Comments

Popular posts from this blog

Joomal 3.6.3 update error - PHP temporary folder is not set - Joomla! Forum - community, help and support

Upgrade 3.4.8 to 3.5.1 failed "download package failed" - Joomla! Forum - community, help and support

Fatal error during instalation - Joomla! Forum - community, help and support