Wordpress under attack

elPimps

Regular Member
Joined
Oct 8, 2014
Messages
358
Reaction score
11
Hi all
i need some help, at least what to do and how to start.
1) today i discovered that a client website start generating some spamming content with 301 redirect to spam/porn website
2) there is a bruteforce on wp-login.php and xmlrcp.php (all login failed)
3) at the end the homepage got redirected to a porn website.

Atcually i put the website under mantainance, i backuped the db and downloaded all the files.
We can rollback to 1th january 2020 but i have to understand where was the hole in the system.
 
If it is wordpress then use wordfence plugin to scan the whole website. This plugin will also protect you from brute force attacks.

Wordfence will find any backdoor. You can also scan the files with notepad++ for keywords like exec, shell_exec, base64_decode etc etc
 
I installed wordfence but it is unable to make any scan or anything else atm...
 
Akismet for spam, and theres like 10+ security plugins that can help with the bruteforce, changing wp-login.php url, etc
 
I hope you had a backup before it was hacked. You'll need a clean install.

If you got a porn redirect it means they got in.
 
zip the whole website and upload the zip file to virustotal. you will see everything and all the kind of threats hidden in yoursite.
 
Is it possible to clean it instead of rollingback?

and... how can this happen?
A bad coded plugin?
 
Try to get help from the hosting
If you have budget then can also try sitelock.com - very expensive though
 
We never used pirated things since it's an e-commerce...
 
I know... i just do what the "man who pay my bills" ask...
 
not everything is active atm anyway...
and i fixed a fucking shit that setup the webmaster before me.
He used a huge theme and plugins that weren't supposed to be used for the purpose of this ecommerce...
I asked the "boss" several times to fix this shit... but "no budget"
 
Back
Top