WordPress sites Hacked

Discussion in 'WordPress' started by SEOXpert2011, Mar 12, 2011.

  1. #1
    Hi All;

    I have so many sites in which i install the WordPress.I am using WordPress Since last 5 year But i have never ever seen this problem in my life.Some one Hacked my sites.When i renew it then again after 2 or 3 days later my site is Hacked.Can any one tell me which should i do to secure my WordPress Sites

    Regards
    SEOX
     
    SEOXpert2011, Mar 12, 2011 IP
  2. tbarr60

    tbarr60 Notable Member

    Messages:
    3,455
    Likes Received:
    125
    Best Answers:
    0
    Trophy Points:
    210
    #2
    If you have access to log files, you may be able to find out how they hacked it. I once had a phpNuke site that was hacked. I looked through the log files and saw to odd queries. One got user names and encrypted passwords back and then used these credentials to do an update query including a meta refresh that redirected the site to some Turkish site. I ended up blocking IP blocks in Turkey and did some other things to make it harder for a bot to find a typical hole in phpNuke.

    Do you have WordPress and other software updated on your site? Do you have a strong password?
     
    tbarr60, Mar 12, 2011 IP
  3. galipellisatyanarayana

    galipellisatyanarayana Active Member

    Messages:
    218
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #3
    Yes. Wordpress sites are getting hacked. I faced this problem 3 times in the last 4 months. But didn't found the solution. I am always changing the hostings after the wordpress sites are hacked.
    If any solution is there for this, please let me know.
     
    galipellisatyanarayana, Mar 12, 2011 IP
  4. Philvault

    Philvault Active Member

    Messages:
    1,284
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    80
    #4
    Wordpress is a secure platform and the updates are frequent.
    Poorly written plugins and hacked themes are usually the ones allowing hackers to gain access to your blog.
     
    Philvault, Mar 12, 2011 IP
  5. SSC

    SSC Active Member

    Messages:
    995
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    80
    #5
    SSC, Mar 13, 2011 IP
  6. etc

    etc Well-Known Member

    Messages:
    3,234
    Likes Received:
    30
    Best Answers:
    0
    Trophy Points:
    158
    #6
    uploading plugins that aren't in the wordpress.org directory is something to avoid. do the fresh install..
    but before it you must have the wp-content folder and the wp-config file backed up. always keep these files in your computer.
     
    etc, Mar 13, 2011 IP
  7. atnews

    atnews Peon

    Messages:
    277
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    before 10 days agao, my wordpress site was hacked. I completely check it and found that my theme index was hacked instead of wp index file. I replace theme and now my site is working well.

    You also check theme index file and try to fix it.
     
    atnews, Mar 13, 2011 IP
  8. mccomf

    mccomf Active Member

    Messages:
    517
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    53
    #8
    Beware of using free themes which are not listed in wordpress.org.
     
    mccomf, Mar 13, 2011 IP
  9. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #9
    What do you mean by hacked? Are you running a multisite installation or single? Are you talking about spam registrations? Comments?
    What exactly is happening?
     
    hmansfield, Mar 13, 2011 IP
  10. Nose

    Nose Peon

    Messages:
    73
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Always upgrade to the newest version available.
     
    Nose, Mar 13, 2011 IP
  11. urmick96

    urmick96 Active Member

    Messages:
    236
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #11
    Most likely the plugins / themes have a backdoor in them.

    I doubt wordpress can be hacked that easy if it was it would be a 0day exploit but then it would be patched quickly to
     
    urmick96, Mar 14, 2011 IP
  12. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #12
    Wordpress is not hacked easily. Most times it is an exploit that is hidden in a free theme or bootleg plug in. I have had many people tell me that their site was hacked and that they didn't do anything to cause it, only to find out that they are using a premium theme that they downloaded from a file sharing site that is full of malicious code.

    I have over 30 Wordpres sites and have built hundreds and none of them have ever been hacked.
    If you could provide a link and tell us what they problem is, maybe we can help.
     
    hmansfield, Mar 14, 2011 IP
  13. victa

    victa Peon

    Messages:
    400
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Unfortunately, few months ago there are exploits on the core of wordpress. read here for further detail. While at that site, do your self a favor by checking other exploits regarding some wordpress plugins.
     
    victa, Mar 14, 2011 IP
  14. experttalk

    experttalk Member

    Messages:
    220
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    28
    #14
    secure your .htacces file and folder Permission 755 and lots of others thing u should consider
    dont use free theme
    17 ways to protect your word press
     
    experttalk, Mar 15, 2011 IP
    tankard likes this.
  15. InspiredWriting

    InspiredWriting Member

    Messages:
    28
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #15
    Well, some free themes are even more secure than commercial ones, but it can be hard knowing which ones.

    Also, plugins can often be to blame for unwanted intrusions. Overall, wordpress is pretty good considering how may people are using it.
     
    InspiredWriting, Mar 15, 2011 IP
  16. Philvault

    Philvault Active Member

    Messages:
    1,284
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    80
    #16
    Most of the time, it's the use of hacked themes.
    Get your plugins from wordpress.org alone.
     
    Philvault, Mar 15, 2011 IP
  17. AFAIK

    AFAIK Peon

    Messages:
    7
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Free KeyCAPTCHA has never been passed by any bot.
    Try live demo at keycatcha.com

    Available from
    wordpress.org/extend/plugins/keycaptcha/stats

    Plugins for other CMSs are available from keycaptcha.com
    One can even make his own captcha from his own images with their online designer
     
    AFAIK, Mar 17, 2011 IP
  18. way2tech

    way2tech Member

    Messages:
    245
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #18
    Hi,
    which hosting is used for you?
     
    way2tech, Mar 17, 2011 IP