Wordpress hacked

Discussion in 'WordPress' started by experttalk, Feb 25, 2011.

  1. #1
    Most of the time word press based website have been hacked how.
    and they only replace index.php file how they enter in to the word press admin where is loop whole i want to resolve this issue
     
    experttalk, Feb 25, 2011 IP
  2. Dodger

    Dodger Peon

    Messages:
    1,494
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Shorter sentences would be helpful. I do not understand what you are saying.

    There are a number of ways that you could have been hacked. You could have given out your login credentials. You could be using a FREE theme that has malware in it (see my sigline). Maybe even your hosting is compromised.
     
    Dodger, Feb 25, 2011 IP
  3. experttalk

    experttalk Member

    Messages:
    220
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    28
    #3
    Hii Dodger...

    when any website have been hacked why hackers changes only index.php .and how we can stop them
    i am using studio press and its Paid theme
     
    experttalk, Feb 25, 2011 IP
  4. Dodger

    Dodger Peon

    Messages:
    1,494
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #4
    What did they do to your index.php?
     
    Dodger, Feb 26, 2011 IP
  5. experttalk

    experttalk Member

    Messages:
    220
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    28
    #5
    upload own file with graphics images and write hacked by "......."
     
    experttalk, Feb 26, 2011 IP
  6. Philvault

    Philvault Active Member

    Messages:
    1,284
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    80
    #6
    Wordpress is a very safe platform.
    Hacked sites usually use faulty plugins or themes.
    As always, be careful in using hacked themes. Oftentimes, hackers create backdoors and callback functions
    to locate your site just easily.
     
    Philvault, Feb 26, 2011 IP
  7. Dodger

    Dodger Peon

    Messages:
    1,494
    Likes Received:
    60
    Best Answers:
    0
    Trophy Points:
    0
    #7
    They gotcha, eh. Well like I said before, they got a hold of your login credentials somehow. And there are a number of ways they could do that. It could be a plugin. It could be somebody knows your login and is messing with you. It could be an extension/plugin in your browser that is logging keystrokes. It could be shareware on your computer that is logging keystrokes. It can be a number of things.

    You need to scan your computer for nasties. Review your WordPress plugins and toss anything that is suspicious, not needed, or coming from unreliable sources (something not from WP.org). You need to change all of your passwords in MySQL, FTP, Hosting CP, Computer Login, and WordPress Admin Login. In general, you need to clean house!
     
    Dodger, Feb 26, 2011 IP
  8. hexiumvii

    hexiumvii Member

    Messages:
    11
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #8
    Go to wordpress site and look for "security" plugins, download 2-3 of them and follow all the instructions. This should help a lot.
     
    hexiumvii, Feb 26, 2011 IP
  9. mccomf

    mccomf Active Member

    Messages:
    517
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    53
    #9
    Security plugins like [WordPress Firewall Plugin ] or others should help you.
     
    mccomf, Feb 26, 2011 IP
  10. k4sper

    k4sper Peon

    Messages:
    103
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Maybe You have a popular password? Have You checked if they logged onto admin panel?
     
    k4sper, Feb 26, 2011 IP