How to protect my WordPress Blog from hacking / index editing?

Discussion in 'WordPress' started by b7r, Jun 21, 2009.

  1. #1
    Hi DPers, :)

    I have a blog hosted at cirtex hosting.

    This is the second time my blog has been hacked. :confused:

    Previously in early june, it was cloaked with links on index.php in www_root

    Now, it got hacked ai index.php of www_root as well as wp-content/themes/theme/index.php

    This time I found the following code in it at the end:
    Please advice how I can avoid such third party edits! :mad:
     
    b7r, Jun 21, 2009 IP
  2. ~kev~

    ~kev~ Well-Known Member

    Messages:
    2,866
    Likes Received:
    194
    Best Answers:
    0
    Trophy Points:
    110
    #2
    You do NOT have to anser these questions. They are just some suggestions.

    Is your wordpress up to date?

    Have your modifications been verified as not having any security holes?

    Are all of your modifications up to date?

    Is the server operating system and all of the server services up to date? - apache, mysql, php, the operating system

    Has the hosting provider done a security audit of the server?

    Do you allow anonymous FTP access to the server?

    Are you using weak passwords?

    Do you have brute force protection installed?

    Those are some of the first things I would look at.
     
    ~kev~, Jun 21, 2009 IP
  3. mrhrk01

    mrhrk01 Well-Known Member

    Messages:
    664
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    145
    #3
    As kev says those are definetly the main things to look at:
    Another two things i would say are:
    1) Change the default wordpress username whcih is "admin" to something else
    2) Protect the wp-admin directory so that only you can log in
     
    mrhrk01, Jun 21, 2009 IP
  4. noone.productions

    noone.productions Banned

    Messages:
    51
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I've seen a lot of hacks such as what you have and the most common denominator is, outdated versions of wordpress.

    I would suggest that you start with that one and move on through what ~kev~'s has listed.

    As an addition, you can always setup a .htaccess password protected directory for you wordpress admin folder.
     
    noone.productions, Jun 21, 2009 IP
  5. sylv3rblade

    sylv3rblade Peon

    Messages:
    292
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #5
    send a ticket to cirtex so they can help you track down how hackers gained access to your files
     
    sylv3rblade, Jun 22, 2009 IP
  6. sandeepdude

    sandeepdude Well-Known Member

    Messages:
    1,741
    Likes Received:
    69
    Best Answers:
    0
    Trophy Points:
    195
    #6
    there is a plugin called wp-content protector.
    it disables right click and text copy...

    you can try it...
     
    sandeepdude, Jun 22, 2009 IP
  7. sspy

    sspy Member

    Messages:
    38
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #7
    1) Install 2.8 version
    2) Install WP - Security Scan plugin - it shows all security bugs
     
    sspy, Jun 22, 2009 IP
  8. mrhrk01

    mrhrk01 Well-Known Member

    Messages:
    664
    Likes Received:
    28
    Best Answers:
    0
    Trophy Points:
    145
    #8
    It does NOT show all security bugs ...
     
    mrhrk01, Jun 22, 2009 IP
  9. Lastbutnotleast

    Lastbutnotleast Peon

    Messages:
    2,612
    Likes Received:
    105
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Yep. This is scaring. Is CIRTEXHOSTING a good host?
     
    Lastbutnotleast, Jun 22, 2009 IP
  10. Sake7

    Sake7 Well-Known Member

    Messages:
    1,098
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    110
    #10
    Well... it shows a few common security bugs. It is very useful in my opinion.
     
    Sake7, Jun 22, 2009 IP
  11. eliyah

    eliyah Greenhorn

    Messages:
    24
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    21
    #11
    Check your local computer for viruses and spyware.
     
    eliyah, Jun 22, 2009 IP
  12. b7r

    b7r Well-Known Member

    Messages:
    528
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #12
    Problem identified

    I used to use AceFTP
    This is a very weak software and password can be easily taken off if there are infected files on PC.
     
    b7r, Jun 30, 2009 IP