Hackers Giving Me Trouble - Help Needed

4 replies
Hi,

For the last 2 weeks or so I've been having problems with hackers, especially with one WP site, they even deleted a whole site but luckily is wasn't an important one.

The one site that seems to be getting hacked most, they keep adding links to the admin.php , last night I added a plugin that tells me if there has been any file changes, and last night it warned me that both error_log and index.php had been changed, and sure enough the links were back.

My host says that usually is caused by not having .htaccess however that is in place, they also said it looks like something could be missing in the rewrites (whatever that is!) but said it's not their problem.

This site is on shared hosting with my other sites and I've replaced WP several times.

Also, on the main domain, none of the pages show on the blog except the home page, and I get this error message for all the other pages even though I can see them in WP admin:-

The requested URL /your-category/your-page/ was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

Any ideas?

Cheers
Neil
#giving #hackers #needed #trouble
  • {{ DiscussionBoard.errors[3461500].message }}
    • Profile picture of the author Havenhood
      Start off by downloading the server access logs (cPanel) and looking for any questionable strings/access URLs. Find any IPs associated with strange activity and add them to your .htaccess file.

      Something like this:
      <Limit GET POST >
      order allow,deny


      deny from 123.123.123.123

      allow from all
      </Limit>


      Where 123.123.123.123 is the IP address to be banned. Do that for all questionable references to your site. The parts in bold are only needed if they are not there.
      Signature

      --= -Spazzle- =--

      {{ DiscussionBoard.errors[3462047].message }}
  • Profile picture of the author jminkler
    Start by installing one of the WP security plugins.



    you probably have wrong permissions on folders and/or weak password (change it, and change admin name)
    {{ DiscussionBoard.errors[3462972].message }}
  • Profile picture of the author CrowX
    Wordpress shouldn't be your choice if you're focused on security. They suck at it. But they're the best blogging cms if security isn't your primary concern.
    If you don't mind getting your hands dirty, you should consider going with Drupal.
    {{ DiscussionBoard.errors[3469775].message }}

Trending Topics