Go to file
imre.agent 61d176fb5e feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2
Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.

Layers:
- core/      vanilla Joomla 3.9.2 official package (installer removed)
- cadline/   own-code from the developer source (beiratkozas, maintenance,
             mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
             the developer source lacks
- deployed/  third-party module slugs taken from live, vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base

The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently.

Vetting caught two items that content-based YARA did not flag. Both come
from a structural rule: an extra file on a core-component path that is
not a template override is not a module -- it is a leftover or a plant.
Both are excluded through malware-iocs.paths:
- components/com_mailto/mail.php: an unauthenticated file-write webshell
  (POST save_file + file_content -> fopen/fwrite, no auth check at all),
  present on live since 2021-07-26
- administrator/components/com_joomlaupdate/restoration.php: an Akeeba
  Kickstart leftover carrying a security password (known RCE vector)

Verification: build-baseline.sh -> out/ = 12284 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; none of the 291 IOC
paths present; no disguised .json dropper; core verified as 3.9.2; the
only extra file left on a core path is the legit Google reCAPTCHA library.

Assisted-by: claude-code@claude-opus-4-8
2026-07-17 12:18:26 +02:00
cadline/own feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2 2026-07-17 12:18:26 +02:00
core feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2 2026-07-17 12:18:26 +02:00
deployed feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2 2026-07-17 12:18:26 +02:00
lib build(baseline): add lib/jmap.py Joomla manifest-mapper + tests 2026-07-16 11:27:45 +02:00
overrides feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2 2026-07-17 12:18:26 +02:00
tests build(baseline): add lib/jmap.py Joomla manifest-mapper + tests 2026-07-16 11:27:45 +02:00
.gitignore build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00
build-baseline.sh security: purge planted malware from baseline + content-based IOC filter 2026-07-16 15:21:49 +02:00
malware-iocs.paths feat(archlinexp.eu): add clean deployable baseline on Joomla 3.9.2 2026-07-17 12:18:26 +02:00
PROVENANCE.md build(baseline): constituents+generator skeleton 2026-07-16 09:40:46 +02:00
README.md docs(readme): clear build guide for the HIDS/verifier side 2026-07-16 13:57:47 +02:00
RUNBOOK.md docs: remove operator-internal (git.illusion.hu) references 2026-07-16 12:14:05 +02:00

www.archline.hu — clean baseline (constituents + generator)

This repo produces the clean code baseline of the www.archline.hu docroot (Cadline, Joomla 3.8.11, host tanis.cadline.hu) — the post-compromise, malware-free, faithful reproduction of the live server's source files.

The baseline is the input to the HIDS baseline-diff verifier: a per-vhost, known-good reference tree the verifier compares the live docroot against (baseline-match / data / malware / residual). This repo only produces that tree; the verification runs on the HIDS side.


Building the baseline (read this first)

The repo does not contain the deployed docroot — it contains the baseline constituents plus a generator script. Run the script to produce the deployed tree:

# 1. Clone WITH submodules (common_cadline_libraries + maintenance are submodules):
git clone --recurse-submodules ssh://git@git.cadline.hu:22222/cadline_web/www_archline_hu.git
cd www_archline_hu
#    (if you already cloned without --recurse-submodules:)
git submodule update --init

# 2. Generate the baseline:
./build-baseline.sh            # → ./out/

# 3. Use ./out/ as the per-vhost vanilla_ref (the known-good reference tree).

out/ is the deployed code docroot (~23.5k files). It is git-ignored and fully regenerated on every run (the script is idempotent — it rm -rf out/ first). Point the verifier's baseline-diff at out/, or copy it to wherever the verifier expects the ref.

Prerequisites: bash, rsync, git (for submodules), find, sed. No PHP, no build toolchain, no network at build time (submodules are already cloned). lib/jmap.py (python3) is a maintenance tool used only when authoring a package's pristine commit — it is not invoked by build-baseline.sh.

What out/ contains / excludes:

  • Contains: Joomla 3.8.11 core + every installed extension (110 components, ~98 modules, 164 plugins, 8 templates) + the Cadline-own code — all as deployed files.
  • Excludes: malware/IOCs (see malware-iocs.md) and runtime data (cache/, tmp/, logs/, images/, public/, media data). The result is code only.
  • Byte-matches the live docroot for all legit code; it is intentionally clean on the 4 files the attacker infected (3 trojanized core files + shaper_helix3/index.php), so the verifier flags those on the live server. Verified: non-malware code residual = 0.

Repo layout (the constituents)

Path What How build-baseline.sh uses it
core/ Joomla 3.8.11 official package (deployed form) rsync → out/, minus demo assets + data dirs
packages/<slug>/ 5 upstream-obtainable extensions, deployed-layout, reconciled to live bytes. Modified ones are two commits (pristine upstream → live delta) so git log/git diff shows exactly how we differ from upstream. rsync → out/
deployed/<slug>/ ~55 no-source extensions: vetted live files (deployed layout). _shared/ holds cross-extension language/vendor/manifests. rsync → out/
cadline/<slug>/ Cadline own-code. cadline/backend/common_cadline_libraries and …/maintenance are git submodules of the developer repos (cadcommonlib / maintenance). rsync → out/ (.git excluded)
overrides/ Cadline core modifications (live versions overlaid on the package core) + a few package-missing core files. rsync → out/ (last, so it wins)
lib/jmap.py Generic Joomla manifest→deployed-path mapper (authoring aid only). not used at build time

Details: RUNBOOK.md (recipe + module inventory), PROVENANCE.md (per-extension origins), malware-iocs.md (excluded IOC set).


Updating the baseline

  • Developer-controlled code (common_cadline_libraries, maintenance): the developer pushes to the cadcommonlib / maintenance repos, then:
    git submodule update --remote     # pull the developer's latest
    ./build-baseline.sh               # regenerate out/
    git add -A && git commit          # record the new submodule pointers
    
  • Everything else (Joomla core EOL, 3rd-party extensions): effectively frozen; if a legit change ever lands, re-sync the affected deployed/<slug>/ or overrides/ from the live docroot and commit.

Known divergence (heads-up for the verifier): common_cadline_libraries and maintenance currently take the authoritative submodule HEAD content, which differs from the current live docroot (mixed CRLF/LF + a content drift on crm_hardlock.class.php / POfile.php) because live was not last deployed from those HEADs. The verifier will flag this until live is re-deployed from the submodules or the drift is reconciled. Line-ending normalization, if wanted, is a verifier-side choice.


Authority

The live docroot (RO mirror) is the source of truth for reproduction; the developer git repos are authoritative for the code they own. The earlier single-commit "monolith" baseline is an unvalidated helper only (it dropped extension manifests and clean core files and kept installer junk) — it is not a target.

References

  • The archline.hu 2026 security audit and incident analysis (operator-held).
  • The excluded malware set is documented in malware-iocs.md.