Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.
Layers:
- core/ vanilla Joomla 3.9.2 official package (installer removed)
- cadline/ own-code from the developer source (beiratkozas, maintenance,
mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
the developer source lacks
- deployed/ third-party module slugs taken from live, vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base
The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently.
Vetting caught two items that content-based YARA did not flag. Both come
from a structural rule: an extra file on a core-component path that is
not a template override is not a module -- it is a leftover or a plant.
Both are excluded through malware-iocs.paths:
- components/com_mailto/mail.php: an unauthenticated file-write webshell
(POST save_file + file_content -> fopen/fwrite, no auth check at all),
present on live since 2021-07-26
- administrator/components/com_joomlaupdate/restoration.php: an Akeeba
Kickstart leftover carrying a security password (known RCE vector)
Verification: build-baseline.sh -> out/ = 12284 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; none of the 291 IOC
paths present; no disguised .json dropper; core verified as 3.9.2; the
only extra file left on a core path is the legit Google reCAPTCHA library.
Assisted-by: claude-code@claude-opus-4-8
41 lines
1.3 KiB
PHP
41 lines
1.3 KiB
PHP
<?php
|
|
/**
|
|
* @package Joomla.Site
|
|
* @subpackage Templates.protostar
|
|
*
|
|
* @copyright Copyright (C) 2005 - 2015 Open Source Matters, Inc. All rights reserved.
|
|
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
|
*/
|
|
|
|
defined('_JEXEC') or die;
|
|
|
|
$app = JFactory::getApplication();
|
|
$doc = JFactory::getDocument();
|
|
$this->language = $doc->language;
|
|
$this->direction = $doc->direction;
|
|
|
|
// Add JavaScript Frameworks
|
|
JHtml::_('bootstrap.framework');
|
|
|
|
// Add Stylesheets
|
|
$doc->addStyleSheet($this->baseurl . '/templates/' . $this->template . '/css/template.css');
|
|
|
|
// Load optional rtl Bootstrap css and Bootstrap bugfixes
|
|
JHtmlBootstrap::loadCss($includeMaincss = false, $this->direction);
|
|
|
|
?>
|
|
<!DOCTYPE html>
|
|
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="<?php echo $this->language; ?>" lang="<?php echo $this->language; ?>" dir="<?php echo $this->direction; ?>">
|
|
<head>
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" />
|
|
<jdoc:include type="head" />
|
|
<!--[if lt IE 9]>
|
|
<script src="<?php echo JUri::root(true); ?>/media/jui/js/html5.js"></script>
|
|
<![endif]-->
|
|
</head>
|
|
<body class="contentpane modal">
|
|
<jdoc:include type="message" />
|
|
<jdoc:include type="component" />
|
|
</body>
|
|
</html>
|