Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 10-09-2009, 03:51 AM   #1
Carol
War Room Member
 
rosetrees's Avatar
 
Join Date: Aug 2008
Location: UK
Posts: 2,735
Blog Entries: 13
Thanks: 341
Thanked 736 Times in 516 Posts
Social Networking View Member's Twitter Profile 
Default Wordpress index files hacked - how to remove hackers message

I just answered a thread about this - but it's disappeared. I'm not sure why, so if this is also inappropriate I'll understand if it gets deleted.

The poster was asking how to replace corrupt index.php files in Wordpress.

This is (approximately cos I'm writing it again) the answer I'd just posted before the thread disappeared.

If your Wordpress site is hacked and replaced by a hackers message, it is likely that it is the index.php files that have been changed.

This is what I did when it happened to me.

1) Do a fresh installation of Wordpress in a new directory. This will contain a set of working index.php files (and at one level an index-extra.php file)

2) Use your ftp software to connect to this new installation and download the fresh index.php files to your computer. Rename them as you go so you know where they came from.

3) Now use your ftp software to connect to the hacked site. You will need to do a bit of exploring in both step 2) and this step to find all the files.

4) You should be able to tell which index files have been hacked from their dates.

5) Use your ftp software to upload the appropriate, fresh index file from your computer. Delete the hacked file and then rename the one you uploaded back to index.php

That should, I hope (!!!) cure the problem. If you still see a hacking message, it is likely that you missed an index file somewhere.

Hope this helps someone.

Carol

Offliners - Client Guide to Editing a Wordpress Site
Atahualpa Theme Tutorial. Available to promote via Clickbank
Beginners Guide to SEO - Good, solid, grounding in SEO techniques
rosetrees is online now   Reply With Quote
Old 10-09-2009, 09:38 AM   #2
HyperActive Warrior
 
Join Date: May 2005
Location: , , United Kingdom.
Posts: 372
Thanks: 0
Thanked 15 Times in 15 Posts
Social Networking View Member's FaceBook Profile  View Member's YouTube Profile
Contact Info
Send a message via MSN to markshields Send a message via Yahoo to markshields Send a message via Skype™ to markshields
Default Re: Wordpress index files hacked - how to remove hackers message

I certainly hope it does not happen to my blog

All My Secret Strategies Exposed - http://www.OneMillionIncome.com

View My Blog For $1000 + FREE Info - http://www.MarkMcCulloch.info

Decide Your Own Income - http://www.DecideYourIncome.eu
markshields is offline   Reply With Quote
Old 10-09-2009, 09:53 AM   #3
Watching you...
War Room Member
 
Istvan Horvath's Avatar
 
Join Date: Dec 2008
Location: Waterdown, Ontario, Canada
Posts: 5,984
Blog Entries: 2
Thanks: 1,575
Thanked 2,719 Times in 1,656 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Istvan Horvath
Default Re: Wordpress index files hacked - how to remove hackers message

I don't really see the need for a second installation.

When you download and unzip the WP package on your computer - you have all the files, including the index files, in unaltered, clean version. Use those to replace the corrupted files.

In most of the cases the hacked file is the root index which is in your public_html (or whatever the root is on your server: www, htdocs etc.).

If that's all what the hackers did, i.e. modifying your root index file - you were lucky!
Usually, it is more than that: a malicious script in the uploads directory, a MySQL injection, a new "admin" among the users... depending on what kind of security whole did the hackers use.

In the first half of the year we are supposed to work for the taxman. I think that's a mistake.
Help me to get rid of the taxman ASAP - thanks! (You, too, should make less mistakes!)


Istvan Horvath is online now   Reply With Quote
Old 10-09-2009, 11:52 AM   #4
Carol
War Room Member
 
rosetrees's Avatar
 
Join Date: Aug 2008
Location: UK
Posts: 2,735
Blog Entries: 13
Thanks: 341
Thanked 736 Times in 516 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress index files hacked - how to remove hackers message

@ pension guy. I install via fantastico - I don't have the original, unzipped version of WP on my computer

Offliners - Client Guide to Editing a Wordpress Site
Atahualpa Theme Tutorial. Available to promote via Clickbank
Beginners Guide to SEO - Good, solid, grounding in SEO techniques
rosetrees is online now   Reply With Quote
Old 10-09-2009, 01:56 PM   #5
Watching you...
War Room Member
 
Istvan Horvath's Avatar
 
Join Date: Dec 2008
Location: Waterdown, Ontario, Canada
Posts: 5,984
Blog Entries: 2
Thanks: 1,575
Thanked 2,719 Times in 1,656 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Istvan Horvath
Default Re: Wordpress index files hacked - how to remove hackers message

Quote:
Originally Posted by rosetrees View Post
@ pension guy. I install via fantastico - I don't have the original, unzipped version of WP on my computer
Ah, since I never do that (use Fantastico) I alwasy forget about that "option". I like to be in control.
Still, if you are going to download/upload the files via FTP... wouldn't be simpler to get the WP package on your machine and upload the clean files?
Just wondering why to have an overloaded database with ten WP installs just to change some files? (Because even if you delete the subdirectory where you installed WP, the database tables are still there.)

In the first half of the year we are supposed to work for the taxman. I think that's a mistake.
Help me to get rid of the taxman ASAP - thanks! (You, too, should make less mistakes!)


Istvan Horvath is online now   Reply With Quote
Old 10-09-2009, 03:34 PM   #6
Carol
War Room Member
 
rosetrees's Avatar
 
Join Date: Aug 2008
Location: UK
Posts: 2,735
Blog Entries: 13
Thanks: 341
Thanked 736 Times in 516 Posts
Social Networking View Member's Twitter Profile 
Default Re: Wordpress index files hacked - how to remove hackers message

I'm sure you're right - but when my sites were attacked I probably wasn't thinking long term. I was trying not to panic and find a simple, short term fix! This was the answer I came up with in the heat of the moment - and hey, it worked and saved me a fortune as I might have had to turn to drink to drown my sorrows if it had failed.

I don't think I was panicking that much that I installed 10 times. Just once - but I take your point about leaving a redundant database on my server.

Offliners - Client Guide to Editing a Wordpress Site
Atahualpa Theme Tutorial. Available to promote via Clickbank
Beginners Guide to SEO - Good, solid, grounding in SEO techniques
rosetrees is online now   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
files, hacked, index, wordpress

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 11:22 AM.