1. Megan_Dyer
  2. General
  3. Tuesday, January 12 2016, 04:26 PM
Hello,
I hope you're doing well!
I'm sorry but we're getting an error message that is messing with people being able to login into Easy Profile:

'Warning: session_start(): Cannot send session cookie - headers already sent by (output started at /home/sites/http://powysparticipation.co.uk/public_html/index.php:3) in /home/sites/http://powysparticipation.co.uk/public_html/libraries/joomla/session/session.php on line 658 Warning: session_start(): Cannot send session cache limiter - headers already sent (output started at /home/sites/http://powysparticipation.co.uk/public_html/index.php:3) in /home/sites/http://powysparticipation.co.uk/public_html/libraries/joomla/session/session.php on line 658 '

Any ideas on how to fix this?
Thanks so much!
Megs
Accepted Answer
admin Accepted Answer
Admin
This error is not due to Easy Profile, your site has been hacked (see screenshot of your HTML source code) . I think the causes are the recent Joomla =< 3.4.7 vulnerability.
Attachments (1)
  1. more than a month ago
  2. General
  3. # Permalink
Megan_Dyer Accepted Answer
Pro
Oh wow. Ok. Thanks!

I know it's not your job but do you have any ideas on how to get rid of the hack or move forward? The only way I know is to wipe the site and rebuild it but that is usually long and difficult. Especially with this site!

Don't worry if you can't I am fully aware that it's not your job.
Thanks!
Megs
  1. more than a month ago
  2. General
  3. # 1
admin Accepted Answer
Admin
Hi,
first of all make a backup.

the most simplest way (also if you not have SSH access) is to find recently modified files, for each found file:
- If it is Joomla file then replace it with Joomla original file (same Joomla version)
- If this is Component file then replace it with original file (same component version)
- If it is not Joomla file and it is .php delete it (make backup before) - this is a backdoor

This could solve your problem, to avoid future hack you need to update your Joomla version and/or install some security tool like Admin Tool (https://www.akeebabackup.com/products/admin-tools.html)

There are many other efficient methods to clean your site, but you need to have SSH access and run some antivirus tool (ClamAV for Linux servers)
  1. more than a month ago
  2. General
  3. # 2
Megan_Dyer Accepted Answer
Pro
Content Protected
  1. more than a month ago
  2. General
  3. # 3
Megan_Dyer Accepted Answer
Pro
Content Protected
  1. more than a month ago
  2. General
  3. # 4
admin Accepted Answer
Admin
It's a very small hack since the only thing it is affecting is our ability to login into Easy Profile.
You can't login into Joomla (this is not due to Easy Profile).

Don't worry if you can't I am fully aware that it's not your job.
We born as expert in IT security :D

Anyway, this is simple to solve, I have fixed this on your site, you had a malicious code in your index.php (I have get your FTP data from oldest topic).

In your system I see also many backdoors, please delete it:
- /images/1index.php
- /libraries/x.php
- /libraries/index.php

I do not know if the hack is completely removed, but the login problem is gone.
  1. more than a month ago
  2. General
  3. # 5
Megan_Dyer Accepted Answer
Pro
Content Protected
  1. more than a month ago
  2. General
  3. # 6
Megan_Dyer Accepted Answer
Pro
Seriously, how/where can I donate because I'm using the free version of Easy Profile and you've been excellent from the beginning!
  1. more than a month ago
  2. General
  3. # 7
admin Accepted Answer
Admin
it is not necessary ;)
  1. more than a month ago
  2. General
  3. # 8
Megan_Dyer Accepted Answer
Pro
Content Protected
  1. more than a month ago
  2. General
  3. # 9
  • Page :
  • 1


There are no replies made for this post yet.
However, you are not allowed to reply to this post.