Kamilion
Regular Member
- May 8, 2009
- 365
- 62
Hello, BHW Community.
First of all, I am very sorry,if this is wrong category for this type of threads,if so mods pls delete or move this thread.
Around a month ago, when checking my sites stats I saw huge traffic from search engines with unrelated keywords,1st didnt understand what was that,then I checked my public html directory and saw that each of my site contains files like walmart.php,300 php, i checked codes and saw there were encrypted javascript code,and manually removed all these files and told that to my webhosting customer service. They checked and there were cpaneal login from Romania Ip and he uploaded all files to index his site. My webhosting company banned that Ip and I checked my cpanel pass to strong one.
But,today within a moment all my sites got hacked by a hacker tn scorpion,he replaced all sites' index files with his signature.And deleted all my sites files. I immediately contacted my host,and they said there were no cpanel access, Here is what they messaged me:
I found out there is pretty outdated installation of the wordpress in your public_html directory. The version of the software is 2.9.1, while actual version is 3.2. Also you are using wide range of plugins for your websites, that could be vulnerable as well. I went through server logs and nothing was found that may be related to FTP or cPanel logins and uploading of the pages. So, the conclusion is the account was hacked through a vulnerability in your scripts. You should go through your scripts and make the software you use with them is up to date and is not vulnerable (you may need some research in order to find more information on the plugins.
If so,then how he manage to delete andreplace all my sites' index files with his?
Today,2-3 hours before hacking I installed some plugins to my unused wordpress site,can it be the reason?
And it happened 1st time,as i use this hosting (whb)company already 3 years and completely satisfied with them.
My host managed restore all my sites,but till 19 june,the content after that date already lost.
What are your minds,how to keep our site more secure?
First of all, I am very sorry,if this is wrong category for this type of threads,if so mods pls delete or move this thread.
Around a month ago, when checking my sites stats I saw huge traffic from search engines with unrelated keywords,1st didnt understand what was that,then I checked my public html directory and saw that each of my site contains files like walmart.php,300 php, i checked codes and saw there were encrypted javascript code,and manually removed all these files and told that to my webhosting customer service. They checked and there were cpaneal login from Romania Ip and he uploaded all files to index his site. My webhosting company banned that Ip and I checked my cpanel pass to strong one.
But,today within a moment all my sites got hacked by a hacker tn scorpion,he replaced all sites' index files with his signature.And deleted all my sites files. I immediately contacted my host,and they said there were no cpanel access, Here is what they messaged me:
I found out there is pretty outdated installation of the wordpress in your public_html directory. The version of the software is 2.9.1, while actual version is 3.2. Also you are using wide range of plugins for your websites, that could be vulnerable as well. I went through server logs and nothing was found that may be related to FTP or cPanel logins and uploading of the pages. So, the conclusion is the account was hacked through a vulnerability in your scripts. You should go through your scripts and make the software you use with them is up to date and is not vulnerable (you may need some research in order to find more information on the plugins.
If so,then how he manage to delete andreplace all my sites' index files with his?
Today,2-3 hours before hacking I installed some plugins to my unused wordpress site,can it be the reason?
And it happened 1st time,as i use this hosting (whb)company already 3 years and completely satisfied with them.
My host managed restore all my sites,but till 19 june,the content after that date already lost.
What are your minds,how to keep our site more secure?