![]() | | ||||||||
| | #1 |
| Advanced Warrior War Room Member Join Date: Feb 2006 Location: Kerala - India
Posts: 999
Blog Entries: 1 Thanks: 178
Thanked 26 Times in 23 Posts
|
Yesterday I had someone new register to my wordpress blog with the username "admin" and then reset the password and changed it. I am not able to access the blog with my username and password now. And today the same thing happened to another one of my blogs, and the hacker was trying the same technique, but this time, my admin username wasn't admin and so the hacker failed. Then as a precaution I went on and unchecked the setting that allow anyone to register inside my blogs. So all the rest of my blogs must be secure now. Anyway I would like to know how to get that hacked blog back to my hands? Thanks Spencer Jones |
| | |
| | |
| | #2 |
| Senior Warrior Member War Room Member Join Date: May 2008 Location: South Florida
Posts: 3,054
Blog Entries: 8 Thanks: 345
Thanked 975 Times in 487 Posts
|
Sorry! In order to help, what version of Wordpress are you running?
|
| Warrior Banner Alert System: Get Instantly Emailed when WF Banner Slots Open Up Wordpress Sales Page Theme: Create Salesletters, Reviews, Squeeze Pages Wordpress One Time Offer Plugin: Expiring countdown timers for Wordpress Wordpress Exit Popup Plugin: Unstoppable Exit Popups for Wordpress My Blog | |
| | |
| | #4 |
| Guest
Posts: n/a
|
Spencer, Grab my WSO before I remove it ... Was fixing to do just that .. James |
|
| | #5 |
| Senior Warrior Member War Room Member Join Date: May 2008 Location: South Florida
Posts: 3,054
Blog Entries: 8 Thanks: 345
Thanked 975 Times in 487 Posts
|
Open up PHPMyAdmin via your control panel. Navigate to the users database, change the admin name and password. When saving the password, select MD5. You will have access to your WP folder again. More detail...How to Reset Wordpress Admin Password |
| Warrior Banner Alert System: Get Instantly Emailed when WF Banner Slots Open Up Wordpress Sales Page Theme: Create Salesletters, Reviews, Squeeze Pages Wordpress One Time Offer Plugin: Expiring countdown timers for Wordpress Wordpress Exit Popup Plugin: Unstoppable Exit Popups for Wordpress My Blog | |
| | |
| | #6 |
| Programmer Extraordinaire War Room Member Join Date: Jun 2007 Location: Olathe, KS USA.
Posts: 700
Thanks: 39
Thanked 30 Times in 26 Posts
|
You don't have to go through the hassle of reinstalling anything. Go into your PHPMyAdmin and navigate to the wp_users table for the blog in question. Find the admin user and click on Edit to edit that row. In the functions dropdown, select "MD5" then for the value enter in the password that you want to change it to. Click Save and you should now be able to enter your blog with that password. As long as user registration is disabled, you shouldn't have that problem any more. That doesn't mean your blog is completely secured, but you won't have that specific problem again. |
|
I'm tired of my signature... Deleted.
| |
| | |
| | #8 |
| Affiliate Marketer Join Date: Jan 2008 Location: Birmingham, United Kingdom.
Posts: 451
Thanks: 37
Thanked 47 Times in 18 Posts
|
Somebody has hacked one of my wordpress blogs as well - I keep getting this "Casino En Ligne" link appearing in my blogroll- every time I delete it, it just comes back!
|
| | |
| | #9 |
| Advanced Warrior War Room Member Join Date: Feb 2006 Location: Kerala - India
Posts: 999
Blog Entries: 1 Thanks: 178
Thanked 26 Times in 23 Posts
|
Any other ways? I don't have access to the phpmyadmin of this particular blog, only have access to ftp area. Since I got this domain as part of a competition I was participating and is actually a domain under a main account which is owned by someone else... |
| | |
| | |
| | #10 |
| HyperActive Warrior War Room Member Join Date: Feb 2007 Location: United Kingdom.
Posts: 121
Thanks: 24
Thanked 12 Times in 10 Posts
|
Surely, that will be the reason then. If you won it in a competition, the competition was probably conceived to implement some 'tricky business' - or am I just being paranoid? 2. re: security of blogs, I'd always understood that we should delete the install.php file as soon as we have finished installing. |
| "Life is a lot like jazz... it's best when you improvise" - George Gershwin | |
| | |
| | #11 |
| Advanced Warrior War Room Member Join Date: Feb 2007
Posts: 511
Thanks: 24
Thanked 23 Times in 9 Posts
|
Problem solved? If not, PM me. I'll help you reset your password. |
| | |
| | |
| | #12 | |
| Senior Warrior Member War Room Member Join Date: May 2008 Location: South Florida
Posts: 3,054
Blog Entries: 8 Thanks: 345
Thanked 975 Times in 487 Posts
| Quote:
| |
| Warrior Banner Alert System: Get Instantly Emailed when WF Banner Slots Open Up Wordpress Sales Page Theme: Create Salesletters, Reviews, Squeeze Pages Wordpress One Time Offer Plugin: Expiring countdown timers for Wordpress Wordpress Exit Popup Plugin: Unstoppable Exit Popups for Wordpress My Blog | ||
| | |
| | #13 | |
| Senior Warrior Member War Room Member Join Date: Jan 2007 Location: Johannesburg , South Africa.
Posts: 1,999
Thanks: 493
Thanked 99 Times in 30 Posts
| Quote:
If you really want to protect your WP blog in future you have to get the product that James is offering on his WSO above.... He really knows what he's talking about.... Regards Greg | |
| | |
| | #14 |
| Programmer Extraordinaire War Room Member Join Date: Jun 2007 Location: Olathe, KS USA.
Posts: 700
Thanks: 39
Thanked 30 Times in 26 Posts
|
Since you have ftp access, the only thing you can do is to delete the user and and re-register. You can do this with PHP. You will have to get your db connection details from the wp-config.php file, and then use them to make your calls to the database. Or, you can update that row in the database in the same fashion. Just write a php page that calls the db and updates the record to whatever you want the password to be. |
|
I'm tired of my signature... Deleted.
| |
| | |
| | #15 |
| Guest
Posts: n/a
| |
|
| | #16 |
| formerly known as riff War Room Member Join Date: Apr 2007 Location: Ohio, USA.
Posts: 267
Thanks: 39
Thanked 44 Times in 35 Posts
|
I want to piggyback on Greg's comment. I use wordpress as the platform for all of my sites. The recent increase in wordpress hacks has had me nervous. I picked up James' WSO and, while I'm no techno geek, I'm pretty confident my sites won't be getting hacked...once I get around to updating them all with the procedures in the WSO. [Where was the back end offer for paid upgrade services, James? ]I'm not trying to be a shill here. I don't know James from Adam, but his product is top notch and should solve your wordpress issues going forward. |
| | |
| | #17 |
| Guest
Posts: n/a
|
Hi riff, Thanks .. appreciate it Actually did not add any backend offer on WPS .. Thought about it but figure I would wait for v2 which will come out soon and v1 owners will get a huge discount.. So before I pull WPS for good, grab it now as I do plan on pulling v1 real soon.. James |
|
| | #18 |
| YadaText.com War Room Member Join Date: Jun 2005
Posts: 879
Thanks: 27
Thanked 102 Times in 79 Posts
|
I searched the WSO and could not locate James' WSO. Does anyone have a link to it?
|
|
Are you frustrated trying to figure which Text Program to use? Download this FREE Report "Removing The Blinders" No Optin Required www.LegalGap.com/mobile.pdf | |
| | |
| | #19 |
| Guest
Posts: n/a
|
Its the link in my sig ... 2nd link James |
|
| | #20 |
| Advanced Warrior War Room Member Join Date: Feb 2006 Location: Kerala - India
Posts: 999
Blog Entries: 1 Thanks: 178
Thanked 26 Times in 23 Posts
|
Hello Peter, I just sent you a PM. Hello Bishop81, I have access to the wp-config file. Also I can see the database name, user and password. But since I don't know PHP, don't know how to go on from there... Any more help, the ftp way? Thanks & Regards Spencer Jones |
| | |
| | |
| | #22 | |
| Senior Warrior Member War Room Member Join Date: Jan 2008 Location: Alpharetta,GA, USA.
Posts: 1,440
Thanks: 497
Thanked 198 Times in 143 Posts
|
Use this code, just enter it into your admin password table in PHPmyadmin: Quote:
There are also some free Wordpress security resources here: BlogSecurity Blog Archive WordPress Security Whitepaper Best! | |
| | |
| | #23 |
| Advanced Warrior War Room Member Join Date: Jan 2006 Location: Virginia
Posts: 886
Thanks: 5
Thanked 32 Times in 29 Posts
|
James , Wow - what is going to be in version 2 of your Wordpress Secured Guide? I would love to hear what you have up your sleeves !!! Thanks, Jason |
| | |
| | #24 |
| Advanced Warrior War Room Member Join Date: Feb 2006 Location: Kerala - India
Posts: 999
Blog Entries: 1 Thanks: 178
Thanked 26 Times in 23 Posts
|
I am wondering what's going on? It's been a long time since I been here, and now seems like there's no control of promotions of WSO's being done on main discussion board... Can you guys not comment about the WSO on the WSO thread itself? |
| | |
| | |
| | #25 |
| YadaText.com War Room Member Join Date: Jun 2005
Posts: 879
Thanks: 27
Thanked 102 Times in 79 Posts
|
Maybe you should read the post first before making your comment.
|
|
Are you frustrated trying to figure which Text Program to use? Download this FREE Report "Removing The Blinders" No Optin Required www.LegalGap.com/mobile.pdf | |
| | |
![]() |
|
| Tags |
| blog, hacked, wordpress |
| Thread Tools | |
| |
![]() |