Wordpress sites keep getting hacked...help!?

Discussion in 'WordPress' started by brandon93s, Aug 7, 2009.

  1. #1
    My wordpress blogs (x2) have been hacked twice in the last week. Is there a security hole in the current version I don't know about?

    Please help!

    Anyway to prevent this?
     
    brandon93s, Aug 7, 2009 IP
  2. deluxdon

    deluxdon Catch Me If You Can...!!!™ Staff

    Messages:
    25,481
    Likes Received:
    1,943
    Best Answers:
    32
    Trophy Points:
    480
    #2
    Give it a try by changing host.

    DON.
     
    deluxdon, Aug 7, 2009 IP
  3. brandon93s

    brandon93s Active Member

    Messages:
    798
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    85
    #3
    I don't think changing the host would make a difference. Only the wordpress sites were hacked and not all of my sites. Thanks.

    Just installed the most recent update, see if it helps.
     
    brandon93s, Aug 7, 2009 IP
  4. Oranges

    Oranges Active Member

    Messages:
    2,610
    Likes Received:
    92
    Best Answers:
    0
    Trophy Points:
    90
    #4
    Its pretty tough to identify the reason and giving solution for the hack. Is it Mysql injection? Iframes? or XSS vulnerability?
    because 2.8.2 wordpress was having XSS attack security issues. Try to upgrade your wordpress setup to latest version, Else give them a try

    How to secure your wordpress installation & This
     
    Oranges, Aug 7, 2009 IP
  5. brandon93s

    brandon93s Active Member

    Messages:
    798
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    85
    #5
    I don't know what XXS vulnerabilities are but I'm assuming this was the issue. I was running 2.8.2 until a few moments ago and have just upgraded to 2.8.3.

    Hopefully this should help.
     
    brandon93s, Aug 7, 2009 IP
    sundaybrew likes this.
  6. sundaybrew

    sundaybrew Numerati

    Messages:
    7,294
    Likes Received:
    1,260
    Best Answers:
    0
    Trophy Points:
    560
    #6
    Hi,

    Do the following:

    1) Change your DEFAULT user login to ANYTHING but "admin"

    2) Change your wordpress DB table prefix to something besides "wp_" which is the default.

    3) Download a plugin called "Bad Behavior"

    http://wordpress.org/extend/plugins/bad-behavior/

    Bad Behavior complements other link spam solutions by acting as a gatekeeper, preventing spammers from ever delivering their junk, and in many cases, from ever reading your site in the first place. This keeps your site's load down, makes your site logs cleaner, and can help prevent denial of service conditions caused by spammers.

    4) Down load a plugin called "wordpress security scan"

    http://wordpress.org/extend/plugins/wp-security-scan/

    Scans your WordPress installation for security vulnerabilities and suggests corrective actions.

    -passwords
    -file permissions
    -database security
    -version hiding
    -WordPress admin protection/security
    -removes WP Generator META tag from core code

    Do the above and also have the most recent version of WP installed and you won't get hacked.

    Hope this helps.
     
    sundaybrew, Aug 7, 2009 IP
    Oranges and Pixelrage like this.
  7. brandon93s

    brandon93s Active Member

    Messages:
    798
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    85
    #7
    @ sundaybrew - thanks i'll check out everything you have suggested. Should help I would imagine.

    The main problem was that my sites were on 2.8.2 still which had a security vulnerability. :/
     
    brandon93s, Aug 7, 2009 IP
  8. Tearabite

    Tearabite Prominent Member

    Messages:
    4,628
    Likes Received:
    429
    Best Answers:
    0
    Trophy Points:
    300
    #8
    dont overlook the obvious.. if you have FTP/root/cPanel access to the server, change all your passwords and make sure they are 'strong' - for example, instead of passwords like "iloveMydog", use "8ej4%gjcbd#WSx4%1`Qa"; and store those passwords in a secure place.
    and, for accessing the server, make sure you use SFTP instead of FTP and SSH instead of Telnet (if you use either)..
     
    Tearabite, Aug 8, 2009 IP
    Oranges likes this.
  9. newwebbie

    newwebbie Peon

    Messages:
    41
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    newwebbie, Aug 8, 2009 IP
  10. brandon93s

    brandon93s Active Member

    Messages:
    798
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    85
    #10
    Yep, I found this too. Thanks.
     
    brandon93s, Aug 8, 2009 IP
  11. ArmKaz

    ArmKaz Well-Known Member

    Messages:
    435
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    100
    #11
    Contact host about this issue. I think theres a hole in the host because my wordpress blogs haven't been hacked.
     
    ArmKaz, Aug 8, 2009 IP
  12. uycw

    uycw Active Member

    Messages:
    262
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    60
    #12
    Use Wordpress GD Press Tool plugin and Have High degree security for your FTP password and wordpress Password
     
    uycw, Aug 9, 2009 IP
  13. brandon93s

    brandon93s Active Member

    Messages:
    798
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    85
    #13
    Hacked again.

    All of my passwords are extremely secure. "7980dsad##ifjidsao84109jdsa" equivalents.
     
    brandon93s, Aug 9, 2009 IP
  14. mangomagic

    mangomagic Guest

    Messages:
    43
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    yes, my blog also hacked by untlexy.net iframe trojan .. after upgradation it's fine.
     
    mangomagic, Aug 10, 2009 IP
  15. tonks

    tonks Peon

    Messages:
    50
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    create a .htaccess file in wp-admin

    Deny all
    Allow from xx.xxx
    Code (markup):
    Insert that code for .htaccess file.. the "x" is the first 5 digits of your IP address
    This will deny everyone except you.

    But remember if your IP changes then change the number in the .htaccess file

    Its what I did to stop this guy from hacking into my WP site
     
    tonks, Aug 10, 2009 IP
  16. bobchrist

    bobchrist Active Member

    Messages:
    4,102
    Likes Received:
    95
    Best Answers:
    0
    Trophy Points:
    88
    #16
    Thanks for that info.
     
    bobchrist, Aug 10, 2009 IP
  17. Tearabite

    Tearabite Prominent Member

    Messages:
    4,628
    Likes Received:
    429
    Best Answers:
    0
    Trophy Points:
    300
    #17
    i'm a little rusty on my .htaccess, but, wouldn't that also block anyone else trying to view the blog?
     
    Tearabite, Aug 10, 2009 IP
  18. prashantban

    prashantban Well-Known Member

    Messages:
    1,202
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    100
    #18
    Yeah.. even my site got hacked which had so much securities.. need a solution asap..
     
    prashantban, Aug 10, 2009 IP
  19. tonks

    tonks Peon

    Messages:
    50
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #19
    No it won't
    because you're making this .htaccess file in your "wp-admin" file
    not your root directory.
     
    tonks, Aug 10, 2009 IP
  20. Oranges

    Oranges Active Member

    Messages:
    2,610
    Likes Received:
    92
    Best Answers:
    0
    Trophy Points:
    90
    #20
    Right! That will save wp-admin folder, but what about root index.php deface?
     
    Oranges, Aug 10, 2009 IP