1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Has your wordpress website been hacked this week?

Discussion in 'HTML & Website Design' started by MobileInternet, Apr 25, 2013.

  1. #1
    I've just come across this interesting aticle on the BBC news website.

    "Wordpress has been attacked by a botnet of "tens of thousands" of individual computers since last week, according to server hosters Cloudflare and Hostgator."

    Take a look here and start working on your site's security if you haven't already done so... www.bbc.co.uk/news/technology-22152296
     
    MobileInternet, Apr 25, 2013 IP
  2. panarasgr

    panarasgr Well-Known Member

    Messages:
    124
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    120
    #2
    If you own a wordpress website make sure to secure the /wp-admin/ path. Either restrict it to your own IP address or install the fail login attempts addon.
     
    panarasgr, Apr 26, 2013 IP
    blackhunter250 likes this.
  3. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #3
    I didn't do anything and my websites are okay.
     
    Devtard, Apr 26, 2013 IP
  4. deathshadow

    deathshadow Acclaimed Member

    Messages:
    9,732
    Likes Received:
    1,998
    Best Answers:
    253
    Trophy Points:
    515
    #4
    I'm SO shocked... oh wait, not shocked... Is there even a word for the opposite of shocked?

    Mutliple entry points, no attempt to prevent direct calls to library files, storing the SQL UN/PW/Host info in DEFINE... I'm shocked 3.x hasn't been as big a train wreck as 2.x all things considered... after all it won the Mass 0wnage Pwnie back in '08 for a reason.

    Every time I look at ANY of it's code, it just sets me to full froth; never have I seen ineptitude on such a scale -- they are quite fortunate most people are too stupid to know any better, or nobody in their right mind would be using it.

    NOT that the competition is much better, but there's a reason I suggest custom solutions instead of off the shelf crap.
     
    deathshadow, Apr 30, 2013 IP
  5. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #5
    Why don't you help them then? I am sure that they would appreciate your advices. :)
     
    Devtard, Apr 30, 2013 IP
  6. deathshadow

    deathshadow Acclaimed Member

    Messages:
    9,732
    Likes Received:
    1,998
    Best Answers:
    253
    Trophy Points:
    515
    #6
    Because there isn't a damned thing I'd even TRY to preserve from it, most of my changes would break every single skin out there... basically if I'm going to rewrite from scratch I'd rather write my own... Which is slow going on my own but I've had too damned many disagreements in trying to work with other developers on what should even go into a blog/cms/forum software. After several attempts about seven or eight years ago to at LEAST get them to neuter the blasted markup they shove down your throat that you have NO control over from the skinning system, I basically gave the entire damned thing the finger and walked away.

    The folks behind it and most people working on it are under this bizarre delusion that more code makes things simpler; the ENTIRE system that makes mods possible is IMHO the biggest security hole in it - disallowing mods/plugins altogether would be one of my first changes since it's where historically 90%+ of it's security holes originate! Again nobody learned the lesson of phpBB 2.x and NeverNoSanity/Santy.

    Much like Dreamweaver, HTML 5, OOCSS, HTML/CSS frameworks, jQuery, and a whole host of other web technologies that have become accepted practice, I cannot fathom how ANYONE is DUMB ENOUGH to use Turdpress on anything important! It is insecure by design, and 'fixing' it involves throwing the entire mess of half-assed idiotic BS in the trash and starting over clean.
     
    deathshadow, Apr 30, 2013 IP
  7. davetrebas

    davetrebas Active Member

    Messages:
    301
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    78
    #7
    Just checked a few of my wp sites on hostgator. They look fine.

    Several years 3 of my hostgator wp sites were hacked and hostgator fixed things and just sent me an email. So it is important to have a good host looking out for you.

    There is also a plug in that I use to totally back up my wp sites. It produces a zip file that I download and save. Of course, I lose any posts beyond that point, but my site can be totally restored within minutes.

    Also, most hosting companies do backups. In some cases I have had the host company restore my site to an earlier state before it was hacked.
     
    davetrebas, Apr 30, 2013 IP
  8. Klikkit

    Klikkit Member

    Messages:
    69
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    43
    #8
    Just checked my sites on HostGator too, they all seem fine to me :/

    Off Topic: deathshadow, you seem like a very angry person :)
     
    Klikkit, May 3, 2013 IP