Auteur Sujet: Infection sur site Joomla  (Lu 13409 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne Pyrithe

  • Archives
  • Members
  • *
  • Messages: 351
Infection sur site Joomla
« le: février 22, 2013, 11:32:46 »
Bonjour tout le monde!

J'ai un ptit site pour mon boulot (en construction depuis 2 ans au moins), qui ne sert pas à grand chose.
Sur le même espace par contre (derrière le même NDD), j'ai mon logiciel de gestion commerciale en ligne.

J'ai reçu récemment un mail de google :

Dear site owner or webmaster of XXXX.com,

We recently discovered that some pages on your site look like a possible phishing attack, in which users are encouraged to give up sensitive information such as login credentials or banking information. We have removed the suspicious URLs from Google.com search results and have begun showing a warning page to users who visit these URLs in certain browsers that receive anti-phishing data from Google.

Below are one or more example URLs on your site which may be part of a phishing attack:

http://www.XXXXX.com/libraries/joomla/cache/[série de numéros]/[série de numéros]/

Here is a link to a sample warning page:
http://www.google.com/interstitial?url=http%3A//www.XXXXX.com/libraries/joomla/cache/[série de numéros]/[série de numéros]/

We strongly encourage you to investigate this immediately to protect users who are being directed to a suspected phishing attack being hosted on your web site. Although some sites intentionally host such attacks, in many cases the webmaster is unaware because:

1) the site was compromised
2) the site doesn't monitor for malicious user-contributed content

If your site was compromised, it's important to not only remove the content involved in the phishing attack, but to also identify and fix the vulnerability that enabled such content to be placed on your site. We suggest contacting your hosting provider if you are unsure of how to proceed.

Once you've secured your site, and removed the content involved in the suspected phishing attack, or if you believe we have made an error and this is not actually a phishing attack, you can request that the warning be removed by visiting
http://www.google.com/safebrowsing/report_error/?tpl=emailer
and reporting an "incorrect forgery alert." We will review this request and take the appropriate actions.

Sincerely,
Google Search Quality Team

Note: if you have an account in Google's Webmaster Tools, you can verify the authenticity of this message by logging into https://www.google.com/webmasters/tools/siteoverview and going to the Message Center, where a warning will appear shortly.

Suite à ca, je découvre :
Sur le site http://www.phishtank.com. Cette page est référencée, avec une capture d'écran. C'est une fausse page Paypal, en Allemand.
Sur WOT : Trustworthiness 29, Vendor Reliability 43, Privacy 26...   Bref, RED évidemment!!

Bon, je vais donc effacer ce contenu, et mettre à jour Joomla, afin de corriger la faille de sécurité certainement exploitée.

Mais ce que je voudrais savoir, c'est si les choses vont rentrer dans l'ordre d'elles mêmes?
WOT en rouge, c'est moyen, répertorié en site de phishing, moyen aussi, mais alors blacklisté sur les navigateurs et par google, ca c'est vraiment embêtant...
Comment me sortir de cette situation embêtante??  :-\

Hors ligne Quartzkyte

  • Archives
  • Members
  • *
  • Messages: 460
    • Mes vues sur la sauvegarde...
Re : Infection sur site Joomla
« Réponse #1 le: février 22, 2013, 12:40:31 »
 :AAC
Faut réparer le site !  ;D
Changer les mots de passe admin ET FTP.
Surtout, mettre à jour le Joomla! (tu as dû en oublier depuis deux ans)...
Et vider les expirés et caches dans l'admin de Joomla!

P.S. aussi, examiner et mettre à jour tous les modules externes ne provenant pas du dépôt Joomla! de base...
« Modifié: février 22, 2013, 13:45:00 par Quartzkyte »
Life is hard; it's harder if you're stupid. (John Wayne)

Hors ligne hyunkel30

  • Ancien du Staff
  • Mega Power Members
  • ****
  • Messages: 21887
  • Le monde est devenu fou ...
Re : Infection sur site Joomla
« Réponse #2 le: février 22, 2013, 13:54:03 »
Bonjour,

Pour les listes noires de phishing ou autre, il existe des liens pour s'en enlever :
http://support.google.com/webmasters/bin/answer.py?hl=fr&answer=163634&topic=2365140&ctx=topic

http://support.google.com/webmasters/bin/answer.py?hl=fr&answer=168328&topic=2365140&ctx=topic

Concernant WOT, c'est plus compliqué une fois le "mal" fait vu que c'est lié à de la web réputation
http://www.mywot.com/en/faq/website/reputation-problems

 :AAN