Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.
Layers:
- core/ vanilla Joomla 3.9.2 official package (installer removed)
- cadline/ own-code from the developer source (beiratkozas, maintenance,
mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
the developer source lacks
- deployed/ third-party module slugs taken from live, vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base
The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently.
Vetting caught two items that content-based YARA did not flag. Both come
from a structural rule: an extra file on a core-component path that is
not a template override is not a module -- it is a leftover or a plant.
Both are excluded through malware-iocs.paths:
- components/com_mailto/mail.php: an unauthenticated file-write webshell
(POST save_file + file_content -> fopen/fwrite, no auth check at all),
present on live since 2021-07-26
- administrator/components/com_joomlaupdate/restoration.php: an Akeeba
Kickstart leftover carrying a security password (known RCE vector)
Verification: build-baseline.sh -> out/ = 12284 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; none of the 291 IOC
paths present; no disguised .json dropper; core verified as 3.9.2; the
only extra file left on a core path is the legit Google reCAPTCHA library.
Assisted-by: claude-code@claude-opus-4-8
34 lines
1.0 KiB
XML
34 lines
1.0 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<extension version="3.9" type="library" method="upgrade">
|
|
<name>Regular Labs Library</name>
|
|
<libraryname>regularlabs</libraryname>
|
|
<description></description>
|
|
<version>18.12.3953</version>
|
|
<creationDate>December 2018</creationDate>
|
|
<author>Regular Labs (Peter van Westen)</author>
|
|
<authorEmail>info@regularlabs.com</authorEmail>
|
|
<authorUrl>https://www.regularlabs.com</authorUrl>
|
|
<copyright>Copyright © 2018 Regular Labs - All Rights Reserved</copyright>
|
|
<license>http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL</license>
|
|
|
|
<scriptfile>script.install.php</scriptfile>
|
|
|
|
<files>
|
|
<folder>vendor</folder>
|
|
<folder>src</folder>
|
|
<file>autoload.php</file>
|
|
<file>regularlabs.xml</file>
|
|
<folder>fields</folder>
|
|
<folder>helpers</folder>
|
|
<filename>script.install.helper.php</filename>
|
|
</files>
|
|
|
|
<media folder="media" destination="regularlabs">
|
|
<folder>css</folder>
|
|
<folder>fonts</folder>
|
|
<folder>images</folder>
|
|
<folder>js</folder>
|
|
<folder>less</folder>
|
|
</media>
|
|
</extension>
|