Joomla websites abused as open proxy for Denial-of-Service attacks

Date posted: 2014-11-16
Last updated: 2026-10-04

Joomla websites with the vulnerable Googlemaps plugin are abused as open proxy for DoS attacks. Here is how to block plugin_googlemap2_proxy.php.

Joomla websites using the Googlemaps plugin for Joomla are actively abused as open proxy for launching Denial-of-Service (DoS) attacks. Even though the Googlemaps plugin vulnerability in plugin_googlemap2_proxy.php was disclosed over one and a half years ago, I still see these DoS attacks happening on a regular basis...

The Joomla Googlemaps plugin file plugin_googlemap2_proxy.php lets anyone use your web server as a proxy to flood other websites. Remove the file, or block requests to it with an .htaccess RewriteRule, IIS URL Rewrite or IIS Request Filtering, and keep Joomla and its extensions up to date.

I originally wrote this post in 2014, when many of the abused websites still ran Joomla 1.5.x. Joomla 1.5, 2.5 and 3.x are all end-of-life now, and so is version 2 of the Googlemaps plugin. The blocking techniques for Apache and IIS still work for any file you don't want requested.

Joomla security track record

Bad... Very bad.

Security in Joomla has a bad track record... This isn't the first vulnerability in a Joomla plugin or component (and won't be the last). We all remember the Joomla Content Editor (JCE) and Media Manager vulnerabilities and exploits.

And it seems Joomla website owners tend to not update their sites, which is very bad of course.

Joomla Googlemaps plugin vulnerability

The problem with the Joomla Googlemaps plugin lies in the fact that anyone can request /plugins/system/plugin_googlemap2_proxy.php in their browser or script, to execute cURL HTTP requests to remote websites. The url parameter is vulnerable to Cross Site Scripting (XSS) attacks, and allows the retrieval of remote website content.

When this happens a lot, a website becomes overloaded and unresponsive: a successfully executed Denial-of-Service attack.

This is not only a problem for the website owner on the remote end, or its hosting company. Your web servers transmit a lot of HTTP traffic to remote ends, increasing server load, usage and network bandwidth (for which you pay). Therefore it's important to stop this abuse.

An example request I pulled from a website log file:

2014-11-16 08:54:25 1.1.1.1 GET /plugins/system/plugin_googlemap2_proxy.php
  url=www.victim_site.example 80 -
  193.23.181.130 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+
    (KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 
  example.com 200 0 64 0 252 42558

Learn about the Top Ten Joomla Security Problems (Wayback Machine)... and how to avoid them. And while you're at it, read my 8 Tips to improve Joomla performance.

Mitigate Joomla Googlemaps plugin proxy Denial-of-Service attacks

A quick search on one web server for the file plugin_googlemap2_proxy.php showed me it's used a lot. Those Joomla sites are running older 1.5.x versions too, sigh... So, let's stop these Denial-of-Service (DoS) attacks on remote sites.

Update & tune Joomla security & performance

It's important to update Joomla, to improve its security and performance.

Project Honey Pot - mitigate DDoS & web attacks

A mitigation is to implement a Project Honey Pot solution to filter and block IP addresses on the HTTP level. They call their HTTP blacklist Http:BL. Join and work with Project Honey Pot to add IP addresses of abusers to their database, create new, or improve existing implementations for Http:BL, or donate a small amount of money to the cause. Of course you can create your own HTTP blocklist easily as well.

Remove plugin_googlemap2_proxy.php!

The simplest - and best - way to stop being a proxy for DoS attacks is to just remove the plugin_googlemap2_proxy.php file. This file is often located in the folder /plugins/system/ or /plugins/content/.

This will break the Joomla plugin, but be honest: who cares?! Version 2 of this plugin is deprecated, update to version 3.1 (both links: Wayback Machine).

.htaccess security for Joomla

You can easily block access to plugin_googlemap2_proxy.php with an .htaccess RewriteRule. Open up Joomla's default .htaccess file and locate the line RewriteEngine On. Directly below that line, add:

RewriteRule plugin_googlemap2_proxy.php - [F,L]

This denies any request to the URI plugin_googlemap2_proxy.php with a 403 Forbidden status code. (I updated this RewriteRule after a reader's comment.)

Running Joomla on Windows Server? Learn how to use .htaccess files on Windows Server IIS.

IIS web.config protection from Joomla plugin_googlemap2_proxy.php DoS attacks

The same block as in .htaccess can be made with the IIS URL Rewrite module in the web.config file. Use the following rewrite rule:

<rule name="Block plugin_googlemap2_proxy">
  <match url=".plugin_googlemap2_proxy\.php" ignoreCase="false" />
  <action type="CustomResponse"
    statusCode="403"
    statusReason="Forbidden: Access is denied."
    statusDescription="No DDoSing remote websites!" />
</rule>

This sends an HTTP 403.0 - Forbidden status code with the message "No DDoSing remote websites!".

IIS Request Filtering denyUrlSequences rule

You can block requests to the plugin_googlemap2_proxy.php file with IIS Request Filtering too. Either in IIS' root node, or on the website level. To add this Request Filtering denyUrlSequences rule to a particular website, fill out a website name after config and use /commit:webroot instead of /commit:apphost.

IIS root node:

AppCmd set config -section:system.webserver/security/requestFiltering /+"denyUrlSequences.[sequence='plugin_googlemap2_proxy.php']" /commit:apphost

Website level:

AppCmd set config "Default Web Site" -section:system.webserver/security/requestFiltering /+"denyUrlSequences.[sequence='plugin_googlemap2_proxy.php']" /commit:webroot

This displays an HTTP Error 404.5 - Not Found response.

Update Joomla, plugins and components

And last but not least...: update Joomla, and update all plugins and components! Frequently!

Remove unused plugins and components. The websites I inspected running this file all still ran ancient 1.5.x versions of Joomla. Joomla 1.5.x is ancient, unsafe, vulnerable, and should be banned from the internet IMO.

Every new Joomla version comes with new optimized PHP code, functions and settings. Use them! Always run an as high as possible Joomla version to make use of these improvements.

From my post 8 Tips to improve Joomla performance.

Joomla Googlemaps plugin plugin_googlemap2_proxy.php abusers

Back in November 2014, 25(!) IP addresses were responsible for millions of hits a day to this plugin_googlemap2_proxy.php file on the web servers I manage. Unfortunately not all of them were listed at services like Project Honey Pot, so I blocked them on our network. That list is many years old now and no longer useful: check your own log files for the IP addresses requesting plugin_googlemap2_proxy.php, and block those.

Tune PHP performance: ensure the performance of your PHP & Joomla websites by following these tips to set a good PHP realpath_cache_size and optimize PHP OPcache configuration.

This post is part of my IIS administration & hardening guide.

I write these posts in my spare time, based on real problems from my day job as a sysadmin. If this one saved you some debugging time, a small donation is much appreciated. Thanks! 🙏

Leave a Comment