| SYSTEM INFORMATION | |
|---|---|
| OS type and version | Debian Linux 13 |
| Virtualmin version | 8.1.0 Professional |
Over the past weekend (July 25th-26th), I got a notice from my Joomla sites that a file (index.php) had been modified on several sites on my Virtualmin server. Due to work timing, I didn’t get to dig into it until today, when I noticed I was getting 403 Access Denied errors when trying to log into the Joomla sites. Doing a check in Virtualmin, I was able to whack the .htaccess files and gain access, at which point I saw files and directories added to my site’s file structures. I quickly deleted the sites, then restored from a backup from before the compromise.
After this was done, I took a look at ALL my sites hosted on Virtualmin, and found several more that had the same files / folders added - some were simple proxy sites with no content, others were plain HTML sites.
Before I whack and restore them, I wanted to check - should I be doing anything with these file or sites, to find out how they were compromised? If there’s a weakness in my server, I’d like to patch it, but I am not sure how to find out how they got access in the first place - via Joomla, WP, Apache, or something else.