Y T Nuke  
Results 1 to 13 of 13
Hi guys, Ive been running a news publication site/blog for awhile now.. This is the ...
  1. #1
    abusetheuser is offline Newbies
    Join Date
    Sep 2011
    Posts
    15
    Reputation
    10
    Thanks
    7
    Thanked 1 Time in 1 Post

    Default Keep getting hacked, help!

    Hi guys, Ive been running a news publication site/blog for awhile now..

    This is the second time I have been hacked..

    Public HTML is the folder thats been hacked, first time it was shut down for phishing, this time it was spamvertisement. I am losing business here.

    I have been using all of the reccomended security plugins..

    Block Bad Queries
    Bulletproof Security
    Chap Secure Login
    Login Lockdown
    Ultimate Security Checker
    WP Security Scan

    I've also fixed timthumb vulnerability

    Now last time this happened I went into R1 Soft and got one of my backups.. the past two days of backups had in the public html folder a bunch of new folders with random strings... and then i found a clean one (assumed it was clean) then I upped my security.

    This time, I went through the R1 soft backups again, and like before todays and yesterdays public html were filled with random stringed folders with html pages inside of them. Only this time I went through all of the R1 backups, even the one a week ago has a folder named "2c5cf4" with an html inside of it, all the other folders are gone but im assuming that folder as well is mallicious - so I now have no safe backups..

    How can I fix this, and how can i prevent this from happening again... I have a family member dying and I really dont have the time or the energy to be dealing with this right now

    Are they getting in through htaccess? can i prevent that?

    Also Im using a w-p-zoom theme that I got from these forums

    If it matters the inside of my public html looks like such

    _private
    _vti_bin
    _vti_cnf
    _vti_log
    _vti_pvt
    _vti_txt
    2c5cf4
    cgi-bin
    images
    wp-admin
    wp-content
    wp-includes
    .htaccess
    _vti_inf.html
    error_log
    index.hawkhost
    index.php
    license.txt
    postinfo.html
    readme.html
    wp-activate.php
    wp-app.php
    wp=atom.php
    wp-blog-header.php
    wp-comments-post.php
    wp-commentsrss2.php
    wp-config-sample.php
    wp-cron.php
    wp-feed.php
    wp-links-opml.php
    wp-load.php
    wp-login.php
    wp-mail.php
    wp-pass.php
    wp-rdf.php
    wp-register.php
    wp-rss.php
    wp-rss2.php
    wp-settings.php
    wp-signup.php
    wp-trackback.php
    xmlrpc.php
    zend_ioon_index.php

    and that is from my R1 backup from about a week ago.

    please help if you can, ill give you a hug or something.

  2. #2
    heiska's Avatar
    heiska is offline Junior Member
    Join Date
    Dec 2008
    Posts
    139
    Reputation
    36
    Thanks
    17
    Thanked 166 Times in 51 Posts

    Default Re: Keep getting hacked, help!

    Change all passwords, keep WP and all the plugins updated, stop using any nulled themes/plugins if you are, change your hosting provider and scan your computer with malwarebytes for keyloggers.

  3. #3
    resistancee is offline Junior Member
    Join Date
    Jun 2011
    Posts
    102
    Reputation
    15
    Thanks
    1
    Thanked 38 Times in 6 Posts

    Default Re: Keep getting hacked, help!

    Here's what I'd advise.

    1. First off run MalwareMalbytes on your PC in safe mode.
    2. Run ComboFixer in Safemode (This is a big one, my favourite least used tool!)
    3. Change password's to your WP blog, Cpanel, Mysql e.t.c.
    4. Contact host and ask for FTP log's & find out what they changed/edited.
    5. Check date stamp's on files.
    6. You should be clean, run over your CHMOD's & make sure none are set to something stupid.

  4. The Following User Says Thank You to resistancee For This Useful Post:

    ardley216 (01-26-2012)

  5. #4
    abusetheuser is offline Newbies
    Join Date
    Sep 2011
    Posts
    15
    Reputation
    10
    Thanks
    7
    Thanked 1 Time in 1 Post

    Default Re: Keep getting hacked, help!

    Thanks guys.. some of this is a bit new to me so I dont think I understood everything that was suggested...

    like i dont know anything about CHMOD?

    What should I do about my current backup since there is that unknown folder? I'd like to get the site up as soon as possible, i just need to make it safe, and then keep it safe

  6. #5
    ardley216's Avatar
    ardley216 is offline Senior Member
    Join Date
    Mar 2008
    Location
    Dark Corner of London
    Posts
    1,044
    Reputation
    231
    Thanks
    278
    Thanked 756 Times in 236 Posts

    Default Re: Keep getting hacked, help!

    I am considering transferring hosting accounts because of the ongoing hacking! I currently have all my wordpress's 302'd to some polish website!
    Me and my cat will one day rule the world.

  7. #6
    MKelly's Avatar
    MKelly is offline Regular Member
    Join Date
    Aug 2010
    Location
    UK
    Posts
    237
    Reputation
    31
    Thanks
    98
    Thanked 107 Times in 67 Posts

    Default Re: Keep getting hacked, help!

    First talk to your web host about it, check the server security and activity log e.t.c..

    Be aware that the problem might be on your PC, you might have spyware or malware e.t.c.. where they get your wordpress login info when you log in.

    Chnage all password to long, meaningless random strings of characters like *&%^^%#IUgiuwge^^4$$##weif9^^)*60

    Just out of interest, which web host is this?

  8. #7
    resistancee is offline Junior Member
    Join Date
    Jun 2011
    Posts
    102
    Reputation
    15
    Thanks
    1
    Thanked 38 Times in 6 Posts

    Default Re: Keep getting hacked, help!

    Quote Originally Posted by abusetheuser View Post
    Thanks guys.. some of this is a bit new to me so I dont think I understood everything that was suggested...

    like i dont know anything about CHMOD?

    What should I do about my current backup since there is that unknown folder? I'd like to get the site up as soon as possible, i just need to make it safe, and then keep it safe
    The first thing you should be working on is finding out how they got the information. It's usually through some build in javascript on a website e.t.c. I'd scan exactly how I said in the post above & perhaps get yourself something that offers browser protection e.g. ESET NOD 32. Once your PC is clean, then focus on fixing everything.

  9. #8
    MKelly's Avatar
    MKelly is offline Regular Member
    Join Date
    Aug 2010
    Location
    UK
    Posts
    237
    Reputation
    31
    Thanks
    98
    Thanked 107 Times in 67 Posts

    Default Re: Keep getting hacked, help!

    I forgot to say: make sure that your actual theme is watertight, some themes you download from anywhere, even this forum have built in vulnerabilities where the purpose is to provide a back door into your site.

  10. #9
    TR0J4N's Avatar
    TR0J4N is offline Registered Member
    Join Date
    Jul 2010
    Location
    My PC
    Age
    26
    Posts
    83
    Reputation
    29
    Thanks
    40
    Thanked 15 Times in 7 Posts

    Default Re: Keep getting hacked, help!

    well if you are on Shared hosting it might not be cause of you, maybe someone rooted the server but I think you need to scan your files and check your theme files code too

  11. #10
    BHopkins's Avatar
    BHopkins is offline Jr. VIP
    Join Date
    Dec 2010
    Location
    California
    Posts
    963
    Reputation
    152
    Thanks
    69
    Thanked 213 Times in 156 Posts

    Default Re: Keep getting hacked, help!

    If you're using a good host, just contact them and ask them to look into it. Hostgator has been great for me when my WP installs got hacked (about once a year).
    4/24/12 Update Knock You Down? Get back up! Private blog network built from the ground up with NO FOOTPRINTS! PM me for details.

  12. #11
    Kymon's Avatar
    Kymon is offline Newbies
    Join Date
    Jan 2012
    Location
    In The Cloud
    Posts
    20
    Reputation
    11
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default Re: Keep getting hacked, help!

    Most has been answered but i agree about
    using themes, plugins with potential problems.

  13. #12
    CubanCohibas's Avatar
    CubanCohibas is offline Registered Member
    Join Date
    Jan 2012
    Posts
    57
    Reputation
    10
    Thanks
    12
    Thanked 23 Times in 22 Posts

    Default Re: Keep getting hacked, help!

    Anything you're using (plugins, themes, hosting, etc.) need to be from a trusted source. Also as mentioned earlier, check your computer for any malware, keyloggers, etc.

  14. #13
    resistancee is offline Junior Member
    Join Date
    Jun 2011
    Posts
    102
    Reputation
    15
    Thanks
    1
    Thanked 38 Times in 6 Posts

    Default

    And in future try to use virus/spyware software that supports your browser. My eset nod 32 stops everything JavaScript getting in and I get a hell of a lot from scrapebox!

AdStract


Advertise on Black Hat World

Similar Threads

  1. Replies: 16
    Last Post: 08-27-2011, 01:33 AM
  2. Check weather your website is hacked
    By Jeevs in forum Blogging
    Replies: 8
    Last Post: 03-14-2011, 12:45 PM
  3. Paypal, ymail, fiverr, gmail, scrapebox...Everything Hacked :(
    By uditbhansali in forum BlackHat Lounge
    Replies: 15
    Last Post: 03-08-2011, 05:01 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
  SEnukeX SEO Software
Proudly Powered by Hostwinds.com Web Hosting Click Here For Exclusive BHW Discounts!

Cheap Web Hosting


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76