Beware WordPress users!!

What's the best way to backup your Wordpress sites? I see that there are plugins for that. Which is the best?


There really is no best. At the end of the day they all backup. The "best" plugin would be described as a plugin that is easy for YOU to use and preferably one that also has an easy restore option (even though this can be done manually). I use XCloner. Works well and flawlessly for me.
 
Learn a lesson: get a backup plugin that emails backups to you.
 
Be careful guys, I currently host 14 WordPress sites and 9 of them have been hacked with malicious code in certain php files! I'm losing so much money, this is a IM's nightmare. There is a zero day exploit currently out there on the newest version of wordpress and they're using it to gain admin control access

It most likely has to do with the theme that you were using. It has happened to me before.

Simply contact your hosting and ask them when the last backup was, and have them resort to it.
 
Confirmed ! Yesterday 1 of my Servers was shut down, all night was on chat with Hostgator, and they confirmed in the morning, some of the sites was hacked. Change all PSSW, Update all Plugins and Update WP to the latest version.
 
-Backup your site every day.Scan that with some good AV (I am using PURE)
-Make sure your php ini file is secured.Personally i dont use any nulled script that has base64 decode,eval parts i cant decrypt and see what is inside. In more than 70% it is a backdo0r.
-Always always try to prevent injection rather than dealing with restrictions in execurion
-Dont use wordpress for anything serious :(
 
Sorry to hear about everyone that was successfully attacked - thank you for the update! I just backed up all my WP sites to my hard drive... even if they are lost I can at least restore them. Updated the few that were a little behind too...
 
I use BackUpBuddy that was nulled here. But after the last Google update I don't care anymore I just want to sell my site. Moving on to wholesale and social media.
 
Ha :P well i think u are left with no other choice than reinstall everything. Theres this new exploit that gets into ur core files ^_^

dont ask me how i know.. i just know it as i know the scene pretty well.
 
ya... one of my sites got hit.

bad.

noticed a sublisting in google that had a link "buy xanax without a prescription"

thought it was an error... resubmitted the site via google webmaster tools...

then the site has been gone from search since (did this 3 days ago)... but when i do site:url it still has all the pages and site indexed.... so not sure.

got someone trying to fix this.... what a fucking nightmare.

i wanna hang these fuckers by their nuts off a 50 story building
 
3 of my wordpress sites just got hacked too. i thought the zero day exploit was patched but i guess not
 
Same here, had a twist on the old pharma hack on mine, look out for anything called 'style.php' in your theme folder or a directory called 'temp' with the file 'links.db' in it.
Style.php will be linked into the footer so remember to remove the link, then change all your passwords etc and install WP firewall
 
most of the hack is due to timthumb.php

True, my websites were hacked 1 month ago through timthumb.php vulnerability.
The hacker set up a phishing landing page of a big UK Bank and drove the visitors through e-mail spam and then stole their account logins details.

This got me big Problems, my Hosting provider suspended all my websites and the Bank threatened legal actions...

Most wordpress templates are using this little script for cropping, zooming and resizing uploaded images on the fly.

I'm betting more than 50% of those of you who have wordpress websites are vulnerable to this attack.


The solution is simple, dowload this plugin http://wordpress.org/extend/plugins/timthumb-vulnerability-scanner/
It will check if your timthumb.php script is up to date and if not it will download a secure up to date version - better hurry up!
 
Look in your .htaccess, it has a referrer based redirect if you were hacked as far as I know...
 
got hacked too.. one of my top site got hacked and showing just my admin directory files now!

site is again back to normal but G crawled and indexed that page and now im lost with rankings X(
 
A lot of bloggers ignore this off , the security of wordpress , always keep in mind , what you build for need to be protected once it goes value in eyes.
Backupbuddy still rocks.
 
Check out wordfence plugin. Seem pretty good to me, probably nothing will work 100%, but this plugin found me some stuff I could not find with anything else.
 
For a complete noob when it comes to php etc, how can I tell if I've been hacked? Everything seems normal but to be honest I'd probably have no idea if the hack did something subtle. I've always used Wordpress database backup plugin and have it sent to me daily through email. I think im going to make the switch to backup buddy because I believe my current plugin only backsup the database and not the files?

Any other recommendations for security plugins that were not mentioned in this thread?

Shits crazy right now. Sites destroyed by penguin and people getting hacked left and right.
 
Back
Top