supereek
Power Member
- Dec 28, 2012
- 727
- 298
Hi,
I found malware today on my sites (wp vdc). They are all in the same DirectAdmin account but run as separate sites.
Luckily I have dealt with this malware before, so I knew what code to remove and what files to clean it up.
The strange thing is this:
- All sites run paid themeforest themes and plugins (NO cracked/nulled stuff anywhere)
- Most of them were frequently updated
- All have strong passwords and anti-bruteforce plugins like Loginizer with strict whitelisting rules
- All have altered login paths by 'wps hide login' so no standard /wp-login/ or /wp-admin/
So I can't figure out how this could have happened... As far as I know the files of 1 WP instance cannot access the other website's roots as they have no path privileges to it. Or am I wrong here?
I have set some additional security plugins now like Wordfence, but they make the sites slower in my opinion.
Any ideas how this could've come and if the theory above is plausible?
I found malware today on my sites (wp vdc). They are all in the same DirectAdmin account but run as separate sites.
Luckily I have dealt with this malware before, so I knew what code to remove and what files to clean it up.
The strange thing is this:
- All sites run paid themeforest themes and plugins (NO cracked/nulled stuff anywhere)
- Most of them were frequently updated
- All have strong passwords and anti-bruteforce plugins like Loginizer with strict whitelisting rules
- All have altered login paths by 'wps hide login' so no standard /wp-login/ or /wp-admin/
So I can't figure out how this could have happened... As far as I know the files of 1 WP instance cannot access the other website's roots as they have no path privileges to it. Or am I wrong here?
I have set some additional security plugins now like Wordfence, but they make the sites slower in my opinion.
Any ideas how this could've come and if the theory above is plausible?