Official Joomla_3.8.11-Stable-Full_Package (downloads.joomla.org), installer dir removed. This is the clean deployed core; it byte-matches the live core for the legit files and provides clean versions of the 3 files the attacker trojanized (auth/joomla.php credential-stealer, session/storage.php, event/event.php). Signed-off-by: LÁZÁR Imre <imre@illusion.hu> Assisted-by: claude-code@claude-opus-4-8
33 lines
836 B
Plaintext
33 lines
836 B
Plaintext
# If the Joomla site is installed within a folder
|
|
# eg www.example.com/joomla/ then the robots.txt file
|
|
# MUST be moved to the site root
|
|
# eg www.example.com/robots.txt
|
|
# AND the joomla folder name MUST be prefixed to all of the
|
|
# paths.
|
|
# eg the Disallow rule for the /administrator/ folder MUST
|
|
# be changed to read
|
|
# Disallow: /joomla/administrator/
|
|
#
|
|
# For more information about the robots.txt standard, see:
|
|
# http://www.robotstxt.org/orig.html
|
|
#
|
|
# For syntax checking, see:
|
|
# http://tool.motoricerca.info/robots-checker.phtml
|
|
|
|
User-agent: *
|
|
Disallow: /administrator/
|
|
Disallow: /bin/
|
|
Disallow: /cache/
|
|
Disallow: /cli/
|
|
Disallow: /components/
|
|
Disallow: /includes/
|
|
Disallow: /installation/
|
|
Disallow: /language/
|
|
Disallow: /layouts/
|
|
Disallow: /libraries/
|
|
Disallow: /logs/
|
|
Disallow: /modules/
|
|
Disallow: /plugins/
|
|
Disallow: /tmp/
|
|
|