Reputation: 1
I have a Joomla 2.5 site with a plugin installed. That plugin sent me an email saying that someone tried to hack my site. What can I do to avoid hacking? This was the email:
** Local File Inclusion [GET:lm_absolute_path] => ../../../
** Local File Inclusion [REQUEST:lm_absolute_path] => ../../../
**PAGE / SERVER INFO
*REMOTE_ADDR :
76.8.53.131
*HTTP_USER_AGENT :
*REQUEST_METHOD :
GET
*QUERY_STRING :
lm_absolute_path=../../../&install_dir=http:// www .google. com/humans.txt?
** SUPERGLOBALS DUMP (sanitized)
*$_GET DUMP
-[lm_absolute_path] =>
-[install_dir] => http:// google. com/humans.txt?
*$_POST DUMP
*$_COOKIE DUMP
*$_REQUEST DUMP
-[lm_absolute_path] =>
-[install_dir] => http:// google. com/humans.txt?
Upvotes: 0
Views: 305
Reputation: 5615
my sites get attacked a few hundred times every day.
Depending on their popularity (and sheer luck) they get into "joomla" lists, or php lists, which are then tested for each possible vulnerability.
Keeping a site safe requires a lot of work. This should be enough to get you started - but is not a complete list:
Upvotes: 1