Been hacked fourth time in WP

Discussion in 'WordPress' started by xira, Aug 1, 2011.

  1. samie

    samie Member

    Messages:
    269
    Likes Received:
    8
    Best Answers:
    1
    Trophy Points:
    45
    #21
    Wordpress - The safest CMS and impossible to get hacked? I highly doubt that :p Why do you think Wordpress has came out with so many updates? There are probably at least tens of thousands of Wordpress sites that get hacked every day and all on various different Web Hosts. I've had two Wordpress sites on two different hosts and a VPS server and had them all get hacked within the same month. Yes mostly a lot of the sites are because they don't update their Wordpress often, and in some cases the Web Host does get hacked too, but that's not any easy task and it's not very common.

    I used to work for a Web Hosting company and I would take about 10 calls every day with people screaming and complaining that our servers are not secure yet they don't even keep their Wordpress up to date and so I restore a backup have to prove them wrong by showing them vulrabilties in their Wordpress site.

    However, one time we really did get hacked. Someone somehow got remote access to our main database (which also contained credit card information) and started downloading the table containing all of our customers logins. There was so much information being downloaded due to the amount of customer we have and luckily the servers started getting overloaded and our NOC team discoverred the download in progress and purged it. But with what they were able to download they started doing a mass insertion of malicious scripts to accounts causing hundreds of calls to be in queue. That then triggered us to do a mass password reset and even more calls coming in. I guess it's good that some people don't check their website too often. Or that they never downloaded the database table with all of our customers credit card information.

    Anyways, I wouldn't jump to that conclusion.
     
    samie, Sep 17, 2011 IP
  2. waziuz

    waziuz Active Member

    Messages:
    783
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    80
    #22
    ^^

    That is why I mentioned with proper permissions and combination of plugins.

    99% of the hacks are either due to server issues from the hosting end where the server or some portion gets hacked, or due to running age old Wordpress versions and for not updating wordpress, or due to using all xyz plugins without checking the reliability and security of the plugins. I doubt a regularly updated wordpress without any plugins installed and on a well maintained and hardened dedicated to get hacked easily. That is why Wordpress brings out updates so frequently so that they can remain ahead of hackers instead.
     
    waziuz, Sep 19, 2011 IP
  3. coolroxx

    coolroxx Peon

    Messages:
    37
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #23
    just install a good anti spam plugin..
     
    coolroxx, Sep 24, 2011 IP
  4. khanter

    khanter Peon

    Messages:
    210
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #24
    Anti spam? Why anti spam?
     
    khanter, Sep 24, 2011 IP
  5. omniscient

    omniscient Active Member

    Messages:
    256
    Likes Received:
    0
    Best Answers:
    1
    Trophy Points:
    61
    #25
    May be you are using a premium theme for free?
     
    omniscient, Sep 24, 2011 IP
  6. wwws

    wwws Notable Member

    Messages:
    3,385
    Likes Received:
    285
    Best Answers:
    0
    Trophy Points:
    225
    #26
    Look into your folders which could be different from others. One folder where this malicious might be is on the "UPLOAD" folder, also it is best to check your .htaccess files, down at the bottom it might look like this:

    DELETE this and continue to look for this codes in files and folders, compare the files with Wordpress, sometimes replacing this files by over-writing could do the trick too.

    Good luck!
     
    wwws, Sep 24, 2011 IP
  7. pranavr

    pranavr Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #27
    none of the above works as well as restricting access to WP admin, ftp, ssh, cpanel, etc, to only your ip address.
     
    pranavr, Oct 1, 2011 IP
  8. vna1611

    vna1611 Well-Known Member

    Messages:
    1,080
    Likes Received:
    22
    Best Answers:
    0
    Trophy Points:
    150
    #28
    This is always the case with WP -
    especially if you do not have a good hosting company.
    You need to create a back up for this kind of issue.
    regards:)
     
    Last edited: Oct 1, 2011
    vna1611, Oct 1, 2011 IP