Download all Joomla templates including quickstart (demo)only $29

Next Release

Procar Template for Joomla 6

Procar Template for Joomla 6 is in progress (Without eccomerce) until Virtuemart 5 will be launched!

Progress93%
Important - Hands Up!

- Please ask using the account with which you made the purchase or download of our products and in its respective category.

* ADD PRODUCT NAME IN START OF SUBJET

Good news template

  • A
  • ardal2025 Junior Member
  • Topic Author 4 weeks 14 hours ago #1
See  gresfordathleticfc.co.uk/index.php/compo...?catid=36&Itemid=128

Why are " and > showing in menu items please

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #2
Which version of Helix are you using?
It appears you haven't updated Helix Ultimate, and an attacker exploited a vulnerability discovered before version 2.2.7 to inject attacks into your site. What you need to do as soon as possible is first create a backup (for analysis), check if a new superuser has been created (if so, delete it), update all of Helix, SP Page Builder, Joomla, and any other extensions you might be using to the latest versions, and change your administrator password. Change the `$secret` in `configuration.php` to a 32-character alphanumeric key (services like Avast can help you generate these keys). Change your FTP password and your database password.

If you have a healthy backup, restore from it and perform the updates as soon as possible.

If you don't have a backup, update your production backup and clean up the menu items from the database. What you need to look for in the menu table is <script>............the entire script</script>"> and delete

IMPORTANT: Password, username, and key changes are made after the cleanup is complete.
You can read the list of vulnerabilities and their solutions here mysites.guru/blog/ . It's not just Helix; perhaps some extension you use is vulnerable.
You can also install the extension github.com/zkrana/joomla-security-scanner to help with cleaning, but before deleting everything it lists, verify that it is a malicious file or folder because it can give false positives.

Regards

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #3
I have no idea how to do this

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #4
If you wish, we can help you with that problem.

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #5
Yes please

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #6
Okay, so how would you like us to do this? From your computer via remote control, or would you prefer to send us the administrator and hosting access details, i.e., the main accounts?

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #7
This message contains confidential information

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #8
Backend access alone isn't enough; we need full access, FTP access, hosting access, database access, and access to your website's backend. If you don't want to share it, you can give us remote access to your computer using UltraViewer or TeamViewer. The passwords are dynamic; they're never the same because accessing them without your permission is impossible. This way, I can do everything while you watch, and you don't share any web access. You'll enter the passwords yourself, and obviously, it's not visible to me because I only see your screen.

Or you can do it yourself; it's up to you. What we're offering is assistance. Normally, this costs $50 per hour for non-clients and $30 per hour for clients, but since it's a security issue, even though the vulnerability wasn't caused by our product, we want to help.

Regards

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #9
This message contains confidential information

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #10
Is need FPT access and you Joomla Admin Access also.

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #11
This message contains confidential information

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #12
Your Joomla amin access?

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #13
This message contains confidential information

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #14
JCE needs to be updated or removed because that extension isn't part of our package. The same goes for Regular Labs Cache Cleaner. Both are vulnerable, and there's nothing we can do about it.

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #15
JCE updated - cache cleaner removed

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #16
JCE is not up to date. The latest version is 2.9.99.10 and you have 2.9.99.7. See here: mysites.guru/blog/jce-2-9-99-10-security-update/
Write Us to chat.

Please Log in or Create an account to join the conversation.

  • A
  • ardal2025 Junior Member
  • Topic Author 3 weeks 6 days ago #17
JCE Editor Pro 2.9.99.10 installed

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #18
Write to us in the chat to make decisions

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 6 days ago #19
In simple terms, your site is a mess! You should always update your site.

Please Log in or Create an account to join the conversation.

  • L
  • leoalv Moderator
  • 3 weeks 5 days ago #20
Hello.

The findings were:
over 500 fonticons with backdoor PHP files
Modified Index.php
Modified .htaccess
Injected database
over 23,000 malicious files.

What we've done:
File cleanup, extension updates, comparison with original Joomla files, change of Joomla secret key, deletion of all existing sessions.

What you still need to do:
- Change your superuser password in the Joomla backend
- Change your FTP password
- Change your database password (if you do, enter this new password in the Joomla configuration)
- Change your hosting master password
- Delete the OLD folder on your site. This folder contains older versions of vulnerable extensions, so you must delete it, otherwise a scanner can detect it and attack again.

This service normally costs a lot, but something happened, and we decided to make it free. We've had a lot of coffee, though, and we don't know who's going to pay for it .

Keep your site updated.

NOTE 1: We have installed Akeeba Backup, and in Backup Manager there are two copies. The larger one is the infected site, and the smaller, more recent one is the clean site. First, download these two copies to your local drive.

NOTE 2: Your hosting account has two backups that were made before July 27th. If you haven't changed any data since then and the site is clean, you can restore it and update your extensions and Joomla.

Please Log in or Create an account to join the conversation.

77,734+
Happy customers guarantee our Templates and Extensions