War Room

Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Featured Warrior Special Offer...
"Members Of The *War Room* Discover Secrets To Immediate Success!"
Reply
 
LinkBack Thread Tools
Old 11-02-2009, 04:10 PM   #1
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default My Wordpress site has been HACKED-should I start from scratch?

My clickbank page is also sending commisions to another clickbank affiliate.

Should I just clear everything and start again?
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:26 PM   #2
Advanced Warrior
War Room Member
 
rosetrees's Avatar
 
Join Date: Aug 2008
Location: UK
Posts: 801
Blog Entries: 5
Thanks: 76
Thanked 89 Times in 82 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Wordpress site has been HACKED-should I start from scratch?

It might be the quickest way. Start by exporting the database - so you have the content. Uninstall WP - use your ftp software to ensure there is nothing left. Reinstall and import your database. See if that fixes it.

rosetrees is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:26 PM   #3
HyperActive Warrior
War Room Member
 
Join Date: Jan 2008
Location: Toronto, Canada
Posts: 161
Thanks: 28
Thanked 26 Times in 24 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Yes, it might be the quickest way. Just make sure you restore a backup you made before your trouble started if possible - or if the blog is new, maybe cut and save your posts and reinstall a fresh copy.
steve39 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:27 PM   #4
Advanced Warrior
War Room Member
 
rosetrees's Avatar
 
Join Date: Aug 2008
Location: UK
Posts: 801
Blog Entries: 5
Thanks: 76
Thanked 89 Times in 82 Posts
Social Networking View Member's Twitter Profile 
Default Re: My Wordpress site has been HACKED-should I start from scratch?

lol Steve 39 - we must be psychic!!

rosetrees is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:30 PM   #5
HyperActive Warrior
War Room Member
 
Join Date: Jan 2008
Location: Toronto, Canada
Posts: 161
Thanks: 28
Thanked 26 Times in 24 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Beat me by a few seconds
steve39 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:40 PM   #6
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Thanks for your time.

"restore a backup you made"

As far as I'm aware, I don't have a back up.

I think the only way to do it is to delete everything and start again. (I have the articles but that's it.)

Should I delete EVERYTHING using my ftp program? (just checking)

Well it took me ages to get this far...but I think I can get it back within a couple of days.


Oh..unless my host (httpme-advised by coach) can restore my site?

I have cpanel if that would help the situation in any way?

Thank you

Steve
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 04:55 PM   #7
HyperActive Warrior
War Room Member
 
Join Date: Jan 2008
Location: Toronto, Canada
Posts: 161
Thanks: 28
Thanked 26 Times in 24 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

I usually delete and restore something like this completely on my reseller account (delete the entire domain and reinstall) just to make sure. If you don't have a reseller account, maybe your host can do this for you. Alternatively, you might be able to get them to restore the site back to before things went bad - depending on how long ago that was and how long your host keeps their backups.
steve39 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 05:16 PM   #8
HyperActive Warrior
 
Abledragon's Avatar
 
Join Date: May 2007
Location: Hong Kong.
Posts: 442
Thanks: 0
Thanked 47 Times in 42 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to Abledragon
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Sorry to hear that - that's a real bummer.

Certainly deleting and re-installing will fix the problem and if you have all your posts on your PC you can re-publish those. Sometimes hackers get into the database so if you don't know when it was hacked re-publishing your posts would be safer.

Remember to ask Google to re-crawl and re-index your site once you're all set up. Depending on their crawl schedule they may have crawled your hacked site and scrubbed it from their indexes. You can do that through Google Webmaster's Tools.

Also, once you're up and running again this article may help to prevent a repetition:

http://www.wealthydragon.com/blog/20...ten-left-open/

Cheers,

Martin.

Abledragon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 05:18 PM   #9
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Quote:
Originally Posted by steve39 View Post
I usually delete and restore something like this completely on my reseller account (delete the entire domain and reinstall) just to make sure. If you don't have a reseller account, maybe your host can do this for you. Alternatively, you might be able to get them to restore the site back to before things went bad - depending on how long ago that was and how long your host keeps their backups.
Httpme are currently looking into it.

I told clickbank 36 hours ago and still haven't heard anything...I emaild httpme and got a reply withing 10 min. Their customer service rocks!

Fingers crossed! I don't know how long my site has been hacked for. And I don't know what caused it either...

Thanks for your help

Steve
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-02-2009, 05:21 PM   #10
PhpMembersScript.com
War Room Member
 
TheRichJerksNet's Avatar
 
Join Date: Aug 2008
Location: South Carolina, USA
Posts: 4,903
Blog Entries: 2
Thanks: 504
Thanked 831 Times in 538 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Yahoo to TheRichJerksNet
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Do as the above suggest and once you done get your blog secured... 100,000's of blogs are hacked each and every year because people do not take the time to secure them. Wordpress is not going to secure it for you, you must secure your own future and business...

James

Article Directory/Auto Syndication Coming | Upto 1800+ Authority Bookmarks WSO - Starts $8.77

Christmas PLR Pack - Articles, Templates, Graphics, Resources and More $8.97 MRR/RR

Block SideWiki | Membership Script | WordPress Security | Facebook App Coming Soon
TheRichJerksNet is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 03:02 AM   #11
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

My host restored my site from the 23 October, all was fine and my affiliate ID was on the clcikbank order page. I went to sleep, woke up and checked. Mysite has been hacked again!!!

I added a picture last night, is it possible that someone used the picture somehow?

I changed my wordpress dashboard password but didn't have time to make any other changes to secure the site.

It seems strange that it was fine last night (restored from Oct 23) yet this morning it has been hacked again.

Can someone please enlighten me?

Thank you

Steve
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 03:07 AM   #12
Warrior Member
War Room Member
 
Mattkau's Avatar
 
Join Date: Sep 2008
Posts: 29
Thanks: 1
Thanked 4 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

send me the ftp details and i will fix it for you it doesnt have much to do with the wodpress password. i would actually change the ftp password, and restore the site, i can do this manually for you (free as i have been doing a few of these lately at work. but yeh definately, change password, correct 'hacked' files (it is usually a one liner ... something like base64_encode, change password again ... also some viruses can actually store themselves within the database, and execute that way ... so they are hard to clean ...
Mattkau is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 03:08 AM   #13
Obsessive Reviewer/Tester
War Room Member
 
Join Date: Oct 2009
Location: Switzerland
Posts: 51
Thanks: 27
Thanked 6 Times in 5 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

I had something similar with one of my blogs. Something was injecting "eval(lotsofgobbledygookhere)" into my .php files.

Turns out, it was an exploit known as the "gifimg" exploit.
I hired a guy on elance to clear everything up for 50 bucks.

Once you have everything back up and running, make sure you use the BackupDB plugin and WP backup to regularly backup all your relevant files.
ShaneRQR is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 03:47 AM   #14
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Thank you! I am in a desperate situation. PM sent.

Thanks again,

Steve


Quote:
Originally Posted by Mattkau View Post
send me the ftp details and i will fix it for you it doesnt have much to do with the wodpress password. i would actually change the ftp password, and restore the site, i can do this manually for you (free as i have been doing a few of these lately at work. but yeh definately, change password, correct 'hacked' files (it is usually a one liner ... something like base64_encode, change password again ... also some viruses can actually store themselves within the database, and execute that way ... so they are hard to clean ...
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 05:54 AM   #15
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Quote:
Originally Posted by Mattkau View Post
send me the ftp details and i will fix it for you it doesnt have much to do with the wodpress password. i would actually change the ftp password, and restore the site, i can do this manually for you (free as i have been doing a few of these lately at work. but yeh definately, change password, correct 'hacked' files (it is usually a one liner ... something like base64_encode, change password again ... also some viruses can actually store themselves within the database, and execute that way ... so they are hard to clean ...
Awaiting reply...
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 06:04 AM   #16
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Before you do ANYTHING you need to diagnose the problem. When you say hacked, what exactly are the symptoms/error messages???

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 06:06 AM   #17
Shortcuts is my middlena
War Room Member
 
mavensophie's Avatar
 
Join Date: Dec 2006
Location: Syracuse, NY
Posts: 17
Thanks: 3
Thanked 1 Time in 1 Post
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: My Wordpress site has been HACKED-should I start from scratch?

if you just move your database: the hacking is in the database... so it is worthless. My blogs were hacked too on hostgator, and I spent some time removing the hack.

one way to find all the places where there is a hack is in the database by searching... if the actual files were hacked, (one type of iframe hack) then I would find the files that are newer than the last update (wordpress files don't change when you change stuff on your blog) and fix them. If you pm me, I'll take a look for you through teamviewer a free software. that is what I use to help my students. I am a half techie half marketer gal...

Mindset, fast start, listbuilding coach. Shortcuts is my business
mavensophie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 06:07 AM   #18
Shortcuts is my middlena
War Room Member
 
mavensophie's Avatar
 
Join Date: Dec 2006
Location: Syracuse, NY
Posts: 17
Thanks: 3
Thanked 1 Time in 1 Post
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: My Wordpress site has been HACKED-should I start from scratch?

oh, and I have two posts on my blog sophieslist [dot] com on my experiences, if you want to read

Mindset, fast start, listbuilding coach. Shortcuts is my business
mavensophie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 06:14 AM   #19
Warrior Member
 
Join Date: Oct 2009
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Its really very bad...but thanks for sharing this information it might happen to anyone.

VanessaA is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 06:31 AM   #20
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Again, unless you correctly diagnose the problem youre only guessing -- in which case youre wasting your time.

Correctly diagnose the problem THEN fix it.

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 07:02 AM   #21
Glad I Got Canned
 
Join Date: Sep 2008
Location: NY
Posts: 508
Thanks: 260
Thanked 53 Times in 39 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Default Re: My Wordpress site has been HACKED-should I start from scratch?

You'd better clean up your local machine. If there is a sniffer, anything you do will be pointless because ftp isn't encrypted. They'll get your password as soon as you change it.

I'm curious about the Clickbank problem. How did you find out? Was there a different affiliate ID on the order form?

FYI - a primer on 21st Century SEO

Promote yourself from "Internet Marketer" to Web Publisher
SurviveUnemployment is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 07:15 AM   #22
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Thanks to everyone offering their time.

I have no idea how to isolate the problem.

I have tried clamxav (free) to check for computer (mac) viruses but found nothing (I can't afford to buy one)
I have had my host restore my site from a restore point on the 23 October. But it's infected again.

I noticed the problem when I cleared my cookies and clicked on 'buy now' on my affiliate sales page...at the bottom I saw another affiliate id. It's still there despite 3 emails to clickbank.

I have used exploit (for wordpress) which located the 'hacking code.'

I have accepted mattkau offer for help, (above post) but haven't heard anything from him since his post. I hav given him my ftp details.


Since I restored my account, the only thing I have done is added a .jpg picture to my site. (just saying incase it matters)


Heres is where I first found the problem Why is SOMEONE ELSE'S affiliate id on my clickbank page?!!!

I don't know what to do...
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 07:34 AM   #23
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

As already pointed out, infact its been covered numerous times in various threads, if you are FTP'ing to the host, then its highly likely that your local machine is infected. But again you need to be more specific as to what error messages or symptoms you are experiencing.

Exactly what do you mean by "hacking code" ???

If its an IFRAME injection you need to read this...

Have Your Websites Been iframe Hacked Also?

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 07:50 AM   #24
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Thanks for your time ramone,

The only obvious error is the clickbank sales page that has someon esle's affiliate name at the bottom.

I have used exploit for wordpress to scan for a virus ect.
These were the code it pointed out as possibly malicious.
These are exerts of code it found.
(I have removed a letter from each piece of code-would not let me post)


<div id="extra_fields" style="display: none"></div>1

eval

String.fromCharCode

base64_decod

visibility:hidde

uname -

shell_exe

YW55cmVzdWx0cy5uZXQ


Thank you for your help, I will read it as soon as I possibly can.

Steve


Quote:
Originally Posted by ramone_johnny View Post
As already pointed out, infact its been covered numerous times in various threads, if you are FTP'ing to the host, then its highly likely that your local machine is infected. But again you need to be more specific as to what error messages or symptoms you are experiencing.

Exactly what do you mean by "hacking code" ???

If its an IFRAME injection you need to read this...

Have Your Websites Been iframe Hacked Also?
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 08:05 AM   #25
HyperActive Warrior
War Room Member
 
Join Date: Jan 2008
Location: Toronto, Canada
Posts: 161
Thanks: 28
Thanked 26 Times in 24 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Steve, Sent you a PM
steve39 is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to steve39 For This Useful Post:
Old 11-03-2009, 08:19 AM   #26
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Without spending too much time investigating this I would firstly check your index files and over write those - thats if you are infact FTP'ing to the site. I dont think you've answered yet regarding this? Are you?

Secondly, again without knowing more about your actual problem and based on what you have provided here, Id consider the *possible* chance of your local machine being infected, BUT...

before you do anything, maybe have a read of this. The code you have provided above appears to be similiar.

WordPress › Support I think my wordpress blog has been hacked-What can I do?

As a side note - ALWAYS be sure to be running the latest copy of WP - ALWAYS!! Your site will be a sitting duck otherwise. Upgrading WP is a piece of cake.

Lastly, post your issue and ask for assistance over at the WP support forum. Youll be much more likely to get a better answer over there.

I wouldnt suggest blowing anything away until you correctly diagnose the issue. Blowing your site away could result in you losing SERP positioning and god know what else - inbound links to specific pages, bookmarks etc etc ....

Blowing the site away should only be considered as an absolute LAST option.

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to ramone_johnny For This Useful Post:
Old 11-03-2009, 08:42 AM   #27
Active Warrior
 
Join Date: Sep 2009
Posts: 63
Thanks: 20
Thanked 2 Times in 1 Post
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Sorry, I am using an ftp program.
I have always used the updated version of wordpress. I am having trouble isolating the problem and am debating wheteher or not to reinstall my OS. As painful as it would be to loose all my info/favourites ect. (I don't know where the infection is) it may be my best option.

Thank you

Quote:
Originally Posted by ramone_johnny View Post
Without spending too much time investigating this I would firstly check your index files and over write those - thats if you are infact FTP'ing to the site. I dont think you've answered yet regarding this? Are you?

Secondly, again without knowing more about your actual problem and based on what you have provided here, Id consider the *possible* chance of your local machine being infected, BUT...

before you do anything, maybe have a read of this. The code you have provided above appears to be similiar.

WordPress › Support I think my wordpress blog has been hacked-What can I do?

As a side note - ALWAYS be sure to be running the latest copy of WP - ALWAYS!! Your site will be a sitting duck otherwise. Upgrading WP is a piece of cake.

Lastly, post your issue and ask for assistance over at the WP support forum. Youll be much more likely to get a better answer over there.

I wouldnt suggest blowing anything away until you correctly diagnose the issue. Blowing your site away could result in you losing SERP positioning and god know what else - inbound links to specific pages, bookmarks etc etc ....

Blowing the site away should only be considered as an absolute LAST option.
Steve36 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 08:49 AM   #28
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Quote:
Originally Posted by Steve36 View Post
Sorry, I am using an ftp program.
Well my guess is, especially if your site is hacked immediately after restoring it -- is that your local machine is infected.

I had this issue myself - and it turned out to be a nightmare!

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to ramone_johnny For This Useful Post:
Old 11-03-2009, 09:10 AM   #29
Web Developer, IT Support
War Room Member
 
n7 Studios's Avatar
 
Join Date: Dec 2008
Location: Birmingham, UK
Posts: 290
Thanks: 7
Thanked 37 Times in 35 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to n7 Studios
Default Re: My Wordpress site has been HACKED-should I start from scratch?

I'll start with the obvious question:
What version of Wordpress are you using? (i.e. the version number - not 'the latest version')

There will be one, or a combination of the following, causing your issues:
- an insecure script (either Wordpress or a third party script or plugin),
- a file / directory permission security issue on your web hosting,

This exploited script / file permission / whatever that's sat on your web host is allowing somebody to exploit your web site, and write / amend files on there (i.e. parts of your Wordpress web site) over and over again. They don't need your FTP / cPanel passwords etc (although it's good security practice to change these); an insecure script will allow a hacker the potential to exploit your web site through issuing a specific URL command, or running a script on their own web server.

This issue isn't because of your Mac:
- you've virus scanned your Mac, and nothing's been found.
- your host has restored the site to a previous backup, yet the problem still occurs (you mention having this done, going to bed and the next day finding the problem on your web site again - no mention of you uploading via FTP meantime).

To fix this problem, you'll need to:
- take a backup of your database and Wordpress assets (images etc you've uploaded in posts, pages and so on),
- ensure your Wordpress version is up to date - I appreciate you say you use the updated version, but what version is that?
- ensure any other scripts are up to date
- ensure the folders on your web site have the correct permissions (commonly known as CHMOD).

If you don't know how to do the above, get somebody to do it over at the Warriors for Hire forum.

And c'mon guys - a thread with 27 replies, and nobody's thought of the above, or asked about the OP's Wordpress version. I think we can do a bit better than that...!

n7 Studios is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 09:43 AM   #30
No excuses - Just do it
War Room Member
 
ramone_johnny's Avatar
 
Join Date: Mar 2009
Location: Bris Vegas
Posts: 489
Thanks: 50
Thanked 79 Times in 61 Posts
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Quote:
Originally Posted by n7 Studios View Post
I'll start with the obvious question:
What version of Wordpress are you using? (i.e. the version number - not 'the latest version')

There will be one, or a combination of the following, causing your issues:
- an insecure script (either Wordpress or a third party script or plugin),
- a file / directory permission security issue on your web hosting,

This exploited script / file permission / whatever that's sat on your web host is allowing somebody to exploit your web site, and write / amend files on there (i.e. parts of your Wordpress web site) over and over again. They don't need your FTP / cPanel passwords etc (although it's good security practice to change these); an insecure script will allow a hacker the potential to exploit your web site through issuing a specific URL command, or running a script on their own web server.

This issue isn't because of your Mac:
- you've virus scanned your Mac, and nothing's been found.
- your host has restored the site to a previous backup, yet the problem still occurs (you mention having this done, going to bed and the next day finding the problem on your web site again - no mention of you uploading via FTP meantime).

To fix this problem, you'll need to:
- take a backup of your database and Wordpress assets (images etc you've uploaded in posts, pages and so on),
- ensure your Wordpress version is up to date - I appreciate you say you use the updated version, but what version is that?
- ensure any other scripts are up to date
- ensure the folders on your web site have the correct permissions (commonly known as CHMOD).

If you don't know how to do the above, get somebody to do it over at the Warriors for Hire forum.

And c'mon guys - a thread with 27 replies, and nobody's thought of the above, or asked about the OP's Wordpress version. I think we can do a bit better than that...!
Theres a reason why I never went into such detail and thats because the OP probably has NO IDEA what half of your post means.

".....you've virus scanned your Mac, and nothing's been found."

So?

Dude I spent a good three days on this attempting to rectify the issue which NO AV scanner, spyware or malware app could detect. Everything came back clean. Infact the only way I could overcome the issue and prevent further infection was to blow my machine away and reinstall the OS.

Every site listed within my FTP application resulted in all my index files being infected. IFRAME injection attacks - which stemmed from an Adobe vulnerability.

It had nothing to do with usernames or passwords, it was an infection on my local workstation. I could've changed passwords all day long - day in day out.

Im not here to argue with you - you've raised valid points, but when you question the assistance given and the way in which it was provided - thats lousy.

Anyway, Im outta here. GL.

ramone_johnny is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-03-2009, 10:34 AM   #31
Web Developer, IT Support
War Room Member
 
n7 Studios's Avatar
 
Join Date: Dec 2008
Location: Birmingham, UK
Posts: 290
Thanks: 7
Thanked 37 Times in 35 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to n7 Studios
Default Re: My Wordpress site has been HACKED-should I start from scratch?

Apologies for this post - I have since spoken with John and we've put our differences aside.

Sorry for going off topic.


Last edited by n7 Studios; 11-03-2009 at 01:31 PM. Reason: Went off topic.
n7 Studios is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
easier, hackedis, site, start, wordpress

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 12:13 PM.