![]() |
| ||||||||
|
|||||||
![]() |
|
|
LinkBack | Thread Tools |
|
|
#101 |
|
Is a...
War Room Member
Join Date: Sep 2007
Location: In the USA...
Posts: 749
Blog Entries: 5
Thanks: 35
Thanked 14 Times in 13 Posts
|
One more thing, in the interest of easing folks' minds about
wordpress, and the security therein: Hardening WordPress WordPress Codex There you have it... (and that post is a very good read, for FREE!) Be Well! ECS Dave |
|
See my Latest Squidoo - #1 on Google!?!? | Personal Development Audios Sample Video!
Extra Cash Systems Weblog | Instant Traffic Generators FREE Wordpress Guide! http://bit.ly/OMUOU Did I say FREE? ;=) | RAPID ACTION PROFITS Delivers! |
|
|
|
|
|
|
#102 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
So the fact that I was cruising Wordpress when my alarm went off was a coincidence and not a wordpress file.
That is actually good to know - even if I have to admit I was wrong -- Now I have a very good question to ask that maybe a security expert can answer. Why was the URL of the virus www.wordpress...../install/ if it was actually something on another website. I don't understand this at all. Does this thing mimic any URL that you are on at the time when it hits and that is why it's so hard to tell the source? Or did my Avast think that it was that page because that is where I was browsing when the site was hit? Anyone know? Even if this wasn't on Wordpress itself - there is still one hell of a mean and versatile virus out there and it'd be nice to know what's going on with it. I think I'll go to Avast and see what they have to say. Maybe someone there knows. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#103 |
|
don't label me.
War Room Member
Join Date: Jul 2006
Location: Mount Vernon, IL
Posts: 3,643
Blog Entries: 1
Thanks: 162
Thanked 141 Times in 90 Posts
|
It wasnt the other site unless avast checks by IP to.
|
|
She did what?
|
|
|
|
|
|
|
#104 |
|
Senior Warrior Member
War Room Member
Join Date: Dec 2007
Location: , , USA.
Posts: 4,309
Blog Entries: 2
Thanks: 324
Thanked 1,233 Times in 423 Posts
|
You very well could have just stumbled onto a site that was infected or even stuffing cookies...I know my avast goes nuts whenever I go to a site that is cookie stuffing
![]() Also, when I am doing some automated blog commenting I get some alerts from avast too when doing the commenting strictly on wordpress blogs... |
|
|
|
|
|
|
|
|
#105 |
|
Advanced Warrior
War Room Member
|
Amid all the mud slinging here, my previous post was ignored. Looks like I wasn't so far wrong.
(My computer was attacked by something a few weeks ago when I was on the website of a local boarding school. I don't blame the site, and returning to it on another computer produced nothing. Just coincidence. As you probably realise, I don't have the technical knowledge of many on here. I just assume that some of these attacks happen via a server somehwere - either the ISP or another link in the chain.) |
|
|
|
|
|
|
|
|
#106 |
|
Buzz Net Marketing
War Room Member
Join Date: Dec 2002
Location: Pascagoula, MS, USA
Posts: 2,401
Thanks: 16
Thanked 10 Times in 10 Posts
|
Seriously, How much time are you going to waste arguing about this??
You could be right, but at the same time, you COULD be WRONG. Who cares. For someone who has had their site compromised, shouldn't you be spending the time to get your stuff straightened out, and prevent it from happening again, instead of trying to prove yourself right? |
|
Join Cash Money Hosting Today, and get a free 1 year domain registration. Use Promo Code: FREEDOMAIN
Applies to .com, .net, .biz or .org |
|
|
|
|
|
|
#107 | |
|
Advanced Warrior
War Room Member
Join Date: Sep 2006
Location: United Kingdom
Posts: 879
Thanks: 4
Thanked 11 Times in 10 Posts
|
Quote:
This wp virus stuff is both troublesome and time consuming especially for non-IT folks. Regards, | |
|
|
||
|
|
|
|
|
#108 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
Yes - a coincidence - but an unsettling one at the very least. I have heard others talk about false positives - but this is really a whole new thing - not only did the alarm go off - the URL was related to the site I was on -- AND - I WAS hit by a virus so I actually wasn't being warned falsely. Had the Virus URL not been a wordpress look-alike I wouldn't have been so positive that it came from there. Michael - The problem HAS been fixed on the server, by a very dilligent Host Admin. Dave chose a responsible host. I wish I had done the same when I put up my main website - they just told me it's my problem. I don't think this is a waste of time - this is one nasty virus and its stealth is staggering. It appears that the codes that are used are encrypted. There are many questions about how it is getting in. This incidence was a "neighboring site on the host", on my main site it was a hacker that signed for membership - a live person. With the escalation of the infection I think its important that we find out just what is going on. Updated etc are good things, but from what I have seen in research, it isn't fool proof. Also - what are the different hosts doing about it? I sure don't want to get stuck on a server that won't help fix such a virulent problem. Anything we can figure out here that helps prevent the spread or saves our sites is a good thing. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
|
|
#109 |
|
Space Bohemian
War Room Member
Join Date: Jun 2005
Location: The Universe
Posts: 272
Thanks: 11
Thanked 2 Times in 1 Post
|
|
|
|
|
|
|
#110 | |
|
HyperActive Warrior
Join Date: Mar 2009
Location: Landers, CA, USA
Posts: 335
Thanks: 30
Thanked 26 Times in 25 Posts
|
Quote:
edit: This kind of thing, being a simple PHP "worm" and not a rootkit or anything like that, should never be able to spread from one hosting account to another on a server like that unless there was some kind of permissions problem (maybe it found something with 777 permissions and spread that way?). I'd recommend hosting on a server that uses PHPSuExec or SUPHP so you have no reason to ever leave any file permissions wide open like that. Now that I've been with HostGator for a couple months I couldn't imagine hosting with anyone that allowed or required 777 permissions.. lol | |
|
This signature intentionally left blank.
|
||
|
|
|
|
|
#111 | |
|
Advanced Warrior
War Room Member
Join Date: Sep 2006
Location: United Kingdom
Posts: 879
Thanks: 4
Thanked 11 Times in 10 Posts
|
Quote:
Can you long story cut short and just give us a LIST of these secure hosting companies that are affordable and reliable for WP users inparticular? Or you may want to put up a WSO for selling such a list. Thanks? | |
|
|
||
|
|
|
|
|
#112 | |
|
Advanced Warrior
War Room Member
Join Date: Sep 2006
Location: United Kingdom
Posts: 879
Thanks: 4
Thanked 11 Times in 10 Posts
|
Quote:
Now I already have these two big boys installed on my wp site, but how I am going to use them? I mean how do I start a scan? Is that mean if I have 10 wp sites, then I have to do 10 separate installations for all my sites? Thanks. | |
|
|
||
|
|
|
|
|
#113 | |
|
there is no spoon
War Room Member
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,095
Blog Entries: 3
Thanks: 115
Thanked 248 Times in 96 Posts
|
Quote:
Running them is easy. After install, go to your WP dashboard. Expand the Dashboard menu and you'll notice "Exploit Scanner". Click this and then select 'Search Files and Database'. I can't help you with the results as I'm no expert, best to Google any results you're not sure of. With The Security Scanner you should have an extra menu at the bottom of your WP Dashboard home menu labelled 'Security'. Click this to see its suggestions. Once again, I'm no expert in how to interpret the results, but if you purchase Craig Desorcy's product, Blog Lock Down, he goes into detail - well worth the investment Peter | |
|
Don't click here. No, please, you're far too stressed, you'll only feel better
www.TwitterPeter.com <- That'll be me on Twitter then! |
||
|
|
|
|
|
#114 |
|
HyperActive Warrior
Join Date: Mar 2009
Location: Landers, CA, USA
Posts: 335
Thanks: 30
Thanked 26 Times in 25 Posts
|
I don't exactly have a "list" but I know kiosk.ws (the host Mike Filsaime recommends and uses) and HostGator both run PHP under a suexec environment (PHPSuExec or SUPHP) so the script actually runs as "you" and not as "apache" or "nobody" (or whatever apache's account name is on that particular server). In that environment, there's no need for 777 permissions, your scripts (Wordpress or whatever else) will be able to write to their files when they need to and nobody on any other account will have write access.. so short of a rootkit it would be impossible for this kind of worm to spread from one account to another on the same server. Of course the drawback is if your own account gets hit it'll spread through your account like wildfire, but at least you only have to worry about the security of the scripts on your own account and not everyone else's.
So, my "short list" would be Kiosk and HostGator, I'm sure there are plenty of others. Before buying hosting I'd contact their support and ask them about it. Aside from learning whether or not their server supports running PHP scripts in a suexec environment, you'll also get a good idea of how their support people respond to questions (which is reall good to know if you ever need them lol). |
|
This signature intentionally left blank.
|
|
|
|
|
|
|
#115 |
|
Advanced Warrior
War Room Member
Join Date: Oct 2007
Location: Colorado, USA
Posts: 588
Blog Entries: 24
Thanks: 65
Thanked 32 Times in 24 Posts
|
I had a weird thing happen today to one of my WP blogs. Well, maybe it wasn't today but I noticed it today.
Under the settings, membership was changed to yes "to anyone can register" and yes to "users must be logged in and registered to comment". Also, the new user default mode was changed to "subscriber" rather than "administrator" as it should be. That meant anyone who registered could access my dashboard. I just installed Peter's recommendations and will check everything. I would guess it's been hacked though. Will changing the permissions from 777 screw anything up? Thanks, Peggy |
|
FREE! Got Questions?? >> Answers To Beginning Internet Marketing Questions Internet Marketing PLR - the good stuff
|
|
|
|
|
|
|
#116 |
|
Active Warrior
War Room Member
Join Date: Jul 2007
Location: Atlanta, GA, USA.
Posts: 94
Thanks: 12
Thanked 4 Times in 4 Posts
|
Peggy,
I have all folders at 755 and files at 644 and WP works fine. I'm no expert by any means, but I don't think you should have any folders at 777 so I would change that immediately. I also recommend Peter's suggestion with running the exploit scanner. Angela |
|
|
|
|
|
#117 | |
|
HyperActive Warrior
War Room Member
Join Date: Jan 2008
Location: USA
Posts: 479
Thanks: 159
Thanked 43 Times in 30 Posts
|
Quote:
Roles and Capabilities WordPress Codex Cindy | |
|
aka Cindy Hohe
|
||
|
|
|
|
|
#118 |
|
HyperActive Warrior
Join Date: Aug 2008
Posts: 104
Thanks: 33
Thanked 10 Times in 10 Posts
|
The proliferation of javascript and the other client side scripting used by web pages has really become of the great absurdities/plagues of the an otherwise great medium. The Internet will never become a stable form of communication until this stuff is dealt with-- but I'm not sure how. I'm constantly dismayed to see javascript used where server side scripting would have worked. But as long as there are lazy programmers, gullible clients and virus pervayors there will be problems like this.
|
|
|
|
|
|
#119 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
|
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#120 | ||
|
Is a...
War Room Member
Join Date: Sep 2007
Location: In the USA...
Posts: 749
Blog Entries: 5
Thanks: 35
Thanked 14 Times in 13 Posts
|
The hosting provider that I have the account on has in place
something that limits the permissions to 755, but I am told that if 777 is needed the machine "knows" to allow the calling script to that level of access... From the support team: Quote:
Quote:
Be Well! ECS Dave | ||
|
See my Latest Squidoo - #1 on Google!?!? | Personal Development Audios Sample Video!
Extra Cash Systems Weblog | Instant Traffic Generators FREE Wordpress Guide! http://bit.ly/OMUOU Did I say FREE? ;=) | RAPID ACTION PROFITS Delivers! |
|||
|
|
|
|
|
#121 | |
|
and his shiny metal ...
War Room Member
Join Date: Apr 2004
Location: Living room
Posts: 1,392
Thanks: 15
Thanked 174 Times in 140 Posts
|
Quote:
First the default user mode should be subscriber like Cindy said. As a subscriber about all they can do is comment they can't get into the admin area. Second change your folder permissions to 755. 777 is so scripts can write to the folder. Also if you have any files with the permissions set to 666 change them to 644 for the same reason. Depending oon your hosting, you may need to change your theme files permission's to 666 to edit the theme files in WP. If you do change them back to 644. Third those membership settings aren't bad really. All it means is if someone want's to comment on a post they must be a registered user. I don't think alot of spammers will take the time to register especially when you can simply delete them. OK three things
| |
|
I got nothing.
|
||
|
|
|
|
|
#122 |
|
Warrior Member
Join Date: Jun 2009
Posts: 15
Thanks: 3
Thanked 0 Times in 0 Posts
|
Well after reading this i thought i might as well end the worries if anyone is wondering if their sites are insecure.
![]() Send me a private message whit the site adress. And i,ll do a security scan on it and give you a list if anything needs to be fixed. ![]() and yes free it won't occupy my time much anyways. I,m new here and might as well provide something positive for the community. sincerly jan lukkarinen owner of jlxsolutions p.s lol that sounded official |
|
|
|
|
|
#123 | |
|
Warrior Member
Join Date: Mar 2007
Location: Canada
Posts: 13
Thanks: 0
Thanked 3 Times in 3 Posts
|
Quote:
This scaremongering needs to stop This happens when someone visits an iframe exploited system and gets the pc trojaned, Then they end up with a keylogger installed that passes off the ftp info. It could be you or someone that has the ftp information on their computer. The talk about 777 being the unsafe chmod is wrong also as 755 will suffice on popular hosts like hostgator etc. That being said one small iframe exploit was done with the phpBB installs. 90% of what is happening today is due to trojaned computers passing off the ftp information. You are busy redoing the pages and not changing the ftp access and the little bots are running wild and uploading new edits to the files. I have spent hours and days with other hosts discussing this and in every case of widespread exploiting it has ended up the users fault. Sure a shell script can be uploaded and maybe other accounts are exploited but in this most recent round it is due to ftp access being gained via trojans Have cleaned this up and watched the ftp logins on a clients site and it ended up his computer was trojaned was almost amusing to watch 3 different ips log in at almost the same time and start downloading and uploading the index.php PS want to really nip it in the bud set all index.php and index.html main.php main.htm and config.php to 0444 chmod ![]() even if they have the ftp information the bots are too stupid to realize it isnt overwriting the files anymore | |
|
|
|
|
|
#124 |
|
Advanced Warrior
War Room Member
Join Date: Sep 2006
Location: United Kingdom
Posts: 879
Thanks: 4
Thanked 11 Times in 10 Posts
|
|
|
|
|
|
|
|
|
|
#125 |
|
there is no spoon
War Room Member
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,095
Blog Entries: 3
Thanks: 115
Thanked 248 Times in 96 Posts
|
A sad post script to this story
I've got a friend who asked me to tell him about IM a few months ago and he was tentatively dipping his toe into having a web presence. We set him up with a blog, he joined WF and was enjoying Twitter. We were working on getting him a static site too to hopefully become his main source of income. He's got an offline business which could easily transfer to being online. His PC and blog got attacked by this virus/trojan and he's been battling with it for about 3 weeks. Because he didn't have the skills to act quickly enough his blog address is now flagged up as an attack site by Google and even his Twitter account has been suspended for suspicious activity. (Presumably because of the link to his blog in his profile) He spoke to me yesterday and has decided that, if this is what it's going to be like being an Internet Marketer he doesn't want the hassle. He's decided to cut his losses and forget all about making money online. Before you go judging him, imagine for a moment you were learning to drive. Nervous about the whole experience you approach your first junction. You gingerly ease out and WHAM! You're hit by a juggernaut. You survive, but you're obviously shaken. You decide to repair everything and venture out once more, only to be hit again - by the same juggernaut. When this happens more than three times you could forgive them for not wanting to drive again. His experience has only been negative. Peter |
|
Don't click here. No, please, you're far too stressed, you'll only feel better
www.TwitterPeter.com <- That'll be me on Twitter then! |
|
|
|
|
|
|
#126 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
It was over 1000 pages so it is just easier to start over from scratch. The instance I just reported - was a normal instance of the virus and just hit us, coincidentally, when I was browsing the WP themes for a new blog, and avast showed a URL for the virus that said http://wordpress..../install/..... so I thought it CAME FROM the wp site. Dave's host told him that it came from a different site on that server and they were able to clean it all up. But It was caught right at the instant it hit my site and wasn't able to get far at all. We were on it too quick for it to do much but land. I don't know what it will do if not detected quick (if you don't have a hacker in your site). It's a worm. I know that the one that hits personal computers eventually delievers a root kit if it's not dealt with quickly, but not sure if the one that hits websites is the same one. I also know that a lot of anti-virus programs fail to detect it and that it also knows how to protect itself from detection - and that it can be a real bear to completely get rid of. Sites like Major Geeks are probably better places to go for info about it than I can give you. When I said that it attacks 777 permission programs -- I meant it will infect programs that have the capability of 777 permissions. I'm not sure which of the actual permissions that you can set those programs to are safe and which aren't or if any are completely safe - I just know it's those programs which can be infected. I have always been told - in fact I think it was even said in this thread, that you shouldn't have permissions set at 777. So all I was saying - is that if you are infected, the programs that have those types of permissions at all are the ones you want to check for infection first, I wasn't saying anything about the particular settings. People seem to think this is just a WP virus, and it's not - it gets forums, etc, too. I hope that clears up some confusion. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
|
|
#127 |
|
Glad I Got Canned
Join Date: Sep 2008
Location: NY
Posts: 511
Thanks: 260
Thanked 53 Times in 39 Posts
|
Everyone running any kind of website should be on guard against cross-site scripting (XSS) attacks. Once you fall for one of those, it doesn't matter if you're using top-secret ultra-secure Pentagon blogging software -- you're vulnerable.
Protect Against XSS Attacks | Charles Linart The site hackers have been extremely active lately. All those guys gloating above about how secure their sites are will find out soon enough. |
|
|
|
|
|
|
|
|
#128 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
On RHS1 we did everything the guy in your article suggested.....and it wasn't enough. I've seen some boasting going on about how secure they are and others must be stupid to get a virus..........and I think about how I was feeling about RHS1.....before the hacker got us. It wasn't that I knew how to secure it...but I know my tech is one of the best and in the long run it didn't matter a twat. I hadn't even had a spammer on the site in over 2 years. Was pretty cocky about it. Lesson learned to the tune of 4 years of work on a site. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
|
|
#129 | |
|
Advanced Warrior
War Room Member
Join Date: Oct 2007
Location: Colorado, USA
Posts: 588
Blog Entries: 24
Thanks: 65
Thanked 32 Times in 24 Posts
|
Quote:
Peggy | |
|
FREE! Got Questions?? >> Answers To Beginning Internet Marketing Questions Internet Marketing PLR - the good stuff
|
||
|
|
|
|
|
#130 | |
|
Advanced Warrior
War Room Member
Join Date: Oct 2007
Location: Colorado, USA
Posts: 588
Blog Entries: 24
Thanks: 65
Thanked 32 Times in 24 Posts
|
Quote:
When I change it back to Administrator, then they can only comment and I can reply as admin. I can't figure out how they were recently changed when I didn't do it. Peggy | |
|
FREE! Got Questions?? >> Answers To Beginning Internet Marketing Questions Internet Marketing PLR - the good stuff
|
||
|
|
|
|
|
#131 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Peggy - don't know anything about settings as I stressed a couple of posts ago, but -- your blog isn't setting off my avast alarms. I clicked about 4 or 5 pages and got nothing but website.
|
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
| The Following User Says Thank You to HeySal For This Useful Post: |
|
|
#132 |
|
Active Warrior
Join Date: May 2009
Location: california
Posts: 63
Thanks: 0
Thanked 4 Times in 4 Posts
|
I have never fall into such situation really appreciate that you share with us. I wanna know if the similar things happens to me what should I do and how harmful this virus is can anyone tell me?
|
|
|
|
|
|
#133 | |
|
Warrior Member
Join Date: Mar 2007
Location: Canada
Posts: 13
Thanks: 0
Thanked 3 Times in 3 Posts
|
Quote:
I now how it works. I know the precautions to take. A few years ago I was on the other team and I know the exploits and how to do them and how to protect against them. People running around like chicken little are the ones these guys bank on. A good Av and real time scanner and common sense WILL protect you. They cant get in unless you give them the keys in the form of weak AV, 5 year old scripts weak passwords running warez even "harmless nulled php scripts" XSS has been around for years and is nothing new. Someone will not spend months hacking a blasted blog there is no money in it for them. and bios problems ... well not even going to go there sounds like someone from a random IRC convo anyway I am going to bow out and if someone does get the problem and wants the site cleaned up contact me have plenty of experience with NO recurrences. | |
|
|
|
|
|
#134 |
|
Warrior Member
Join Date: Jun 2009
Posts: 15
Thanks: 3
Thanked 0 Times in 0 Posts
|
Well as i gathered so far this is not a virus.
![]() Basically what i can tell from this is that a hacker exploited a security hole inserted a XSS attack on the website and redirected the webpage to a malicius one. And what ever comes from there is still unknown.
|
|
|
|
|
|
#135 |
|
HyperActive Warrior
War Room Member
Join Date: Oct 2006
Location: Hildenborough uk
Posts: 271
Thanks: 48
Thanked 10 Times in 9 Posts
|
Interesting stuff
Marcus |
|
Watch me finally make money this year now I have a mentor follow my journey at www.marcuspassey.com
Are you building a list? get my FREE report on list building CLICK HERE! |
|
|
|
|
|
|
#136 |
|
Warrior Member
Join Date: Jun 2009
Posts: 15
Thanks: 3
Thanked 0 Times in 0 Posts
|
Intresting indeed. Well due to the fact i do security checks daily and make sure ppls websites and computers are safe from the bad guys i have come to the conclusion that even mostly the user gets blamed the reason most often lies whit the host not the user.
Like un updated server software for example. If anyone is willing to give me permission to scan their website. i can show some exampels. |
|
|
|
|
|
#137 |
|
Warrior Member
Join Date: Jun 2009
Posts: 15
Thanks: 3
Thanked 0 Times in 0 Posts
|
To the person who PM'ed me sure i do the scan
i,ll post the results here and as you wanted to be anonymous i,ll leave the webpage in question unmentioned. P.S cant reply to your PM until i have 15 posts lol
|
|
|
|
|
|
#138 |
|
Warrior Member
Join Date: Jun 2009
Posts: 15
Thanks: 3
Thanked 0 Times in 0 Posts
|
Well due to the fact you wanted to be anonymous i think i wont post report at all in here
would be to much work to edit the results. but one thing was for sure the hostgator had some issues wich needed urgent attention. |
|
|
|
|
|
#139 |
|
Senior Warrior Member
War Room Member
Join Date: Jul 2004
Location: Jedi Temple
Posts: 1,340
Blog Entries: 12
Thanks: 4
Thanked 315 Times in 71 Posts
|
Peter,
Thanks for the exploit recommendations. Just what I needed and you've pointed out some potential security holes I hadn't thought of. I periodically look at my server data and it is just incredible the number of attacks that are attempted. |
|
|
|
|
|
|
![]() |
|
| Tags |
| redirect, virus, warning, wordpresscom |
| Thread Tools | |
|
|
![]() |