Wordpress under attack

not everything is active atm anyway...
and i fixed a fucking shit that setup the webmaster before me.
He used a huge theme and plugins that weren't supposed to be used for the purpose of this ecommerce...
I asked the "boss" several times to fix this shit... but "no budget"
Even if the plugin is not active the exploit still can be accessible. My major freelance was about removing malware from websites. Had great reviews on freelance. I would check your website but I am not sure if I want to go into that venture again :D
 
Well... the first work here is to block the exploit... then is to rework the entire site/template to get something lightweight and more functional (also easier funnels tbh).
Do you have the resources to make a fast check on this?
 
Well... the first work here is to block the exploit... then is to rework the entire site/template to get something lightweight and more functional (also easier funnels tbh).
Do you have the resources to make a fast check on this?
I can fix the exploit but not redesign etc etc. I am backend programmer. I am not good with colors, only code :D
 
Is the support of the hosting helpful? I had this problem months ago, and the team was able to fix it up for by checking the logfile and removing the virus.

Could it be they breached on your system by password if you have an easy one? Brutohackers are just getting better these days
 
  1. Run your website into a virus/wordpress checker
  2. Restrict wp-login to the countries you and the other users are using from
  3. Restrict login attempts to 3 logins then lock to 3-5 mins
  4. Make a list and check the plugins/themes that you didn't download/install from wordpress.org
  5. Check each of these plugins websites, reviews and files
  6. Disable each of the plugins listed (non-relevant, not trusted) 1 by 1 and check if the problem is solved
  7. If none of the above works, hire someone on Fiverr or here to check your website codes manually, do it yourself if you have a good experience
  8. restore the website before the problem (if it's possible) and check if the problem reserve after few days
Google and search for details of any these, you can find plenty of Infos/guides
Good luck, I know how bad it feels, don't worry you will pass threw ;)
 
You don't really have that many plugins

A modern ecommerce site may have 3 times that many (lots of stuff available for woocommerce)

Visit the gpl club called GPLDL for some things to help your site

Try uploading all files to the virustotal and securi sites

Also check the Wordfence website as they have a news system that lists compromised plugins.

If this is just ecommerce you can export your entire woocommerce orders, do a reinstall and re-import them.

If you are trying to run this business on an un-hardened server it could happen again. Find a management company for $29 a month on Web Hosting Talk. Platinum Server Mgt are known to be reliable.

The 1st likely problem are ANY plugins that you did not buy yourself. Check GPLDL. Their are known to be clean.

Consider the Divi theme. You can make it look like any other theme.

Sincerely,

TheEye
 
A scan with Sucuri plugin or Wordfence can give you a quick insight into files that look suspicious. Open those files with notepad and you can immediately tell if there are some malicious code in there. Don't rule out bad passwords. I just cleaned up someone's website last week and their database password was theirbusinessname2017. Who knows how bad their admin password was...
 
This happened to me some years ago. I added these and the problem stopped:

Wordfence Security (Block the country the attack is coming from)
WPS Hide Login (Move the login page)
Stop Spam Comments
Cookies for Comments
 
Thanks
finally i'm rolling back to 1st jan (seems that the attack started on 21st).
Now... what's the fastest possible way to deindex from google those fake redirecting pages?
I hope to not submit page by page to search console... cause there are over 1k fake pages...
 
Now... what's the fastest possible way to deindex from google those fake redirecting pages?
If you mean reindex,

well, using search console would be the best way,
however, try to submit your sitemap to search console inspection (not sitemap section),
If everything works fine, the links should be added and listed in the crawling queue
IDK if it should work for all the links tho...

or, if that doesn't bother you, you can use indexing service such bulkaddurl (1k URLs will cost $20), they will be reindexed very soon (usually 1 day)


update us after a few days if the problem still exists, best of luck :D
 
attack restarted.
i found some proof that someone uploaded (upload root) some files like cloner.php, mc4wp-debug-log.php, .htaccess. ecc....
how the hell is this possible?
 
I counted 36 plugins, as previous stated, there were likely breaches found in a number of plugins.

Duly note, I'm currently overseeing around 250 WP installs, I haven't had a breach issue in years since I've been using iThemes Security Pro + the free version of Sucuri.

My admin login URLs are all changed to random characters.

Login authentification demands users: (a). solve captcha and, then (b). go through the 2FA login process.

To expedite the process, have your host scan your site to find the breach(es). Once you find and delete them, you might want to consider iThemes Security Pro + Sucuri.

Keep us posted.
 
Back
Top