Commit Graph

2 Commits

Author SHA1 Message Date
1eb05cc597 feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2
Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.

Layers:
- core/      vanilla Joomla 3.9.2 official package (installer removed)
- cadline/   own-code from the developer source (beiratkozas, maintenance,
             mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
             the developer source lacks
- deployed/  95 third-party module slugs taken from live, YARA-vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base

The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently. 289
planted paths are excluded through malware-iocs.paths.

Verification: build-baseline.sh -> out/ = 12286 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; not one IOC path
present; no disguised .json dropper; core verified as 3.9.2.

Assisted-by: claude-code@claude-opus-4-8
2026-07-17 12:13:31 +02:00
0da85cbe24 core: add Joomla 3.8.11 official package (deployed-form source)
Official Joomla_3.8.11-Stable-Full_Package (downloads.joomla.org), installer dir
removed. This is the clean deployed core; it byte-matches the live core for the
legit files and provides clean versions of the 3 files the attacker trojanized
(auth/joomla.php credential-stealer, session/storage.php, event/event.php).

Signed-off-by: LÁZÁR Imre <imre@illusion.hu>
Assisted-by: claude-code@claude-opus-4-8
2026-07-16 09:40:46 +02:00