Malicious files frequently in wordpress upload directory

Discussion in 'WordPress' started by postcd, Sep 4, 2014.

  1. #1
    Hello, when i find malicious .php files on my WP sites, they are usually in uploads directory, i want to ask why?

    i already disabled php execution in these dirs.

    anyone please know how to discover in which way these phps was uploaded into uplaods directories? im root admin of the server, so i have access. thx
     
    postcd, Sep 4, 2014 IP
  2. carrieathomer

    carrieathomer Greenhorn

    Messages:
    108
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    18
    #2
    Change your admin password, don't save any pwd in the ftp client. update all the plugins and the wordpress.
     
    carrieathomer, Sep 4, 2014 IP
  3. WLEadmin

    WLEadmin Active Member

    Messages:
    119
    Likes Received:
    55
    Best Answers:
    5
    Trophy Points:
    55
    #3
    You might have a "back door" active in a plugin or a theme. Install TAC to check the theme, and make sure you only use plugins from reliable sources. That said, I've had trouble with a plugin I downloaded from wp.org in the past, so it seems nothing is safe any more! You might also want to consider the "Ultimate Security Checker" plugin (from wp.org), which will hunt for problems as well (and is free).
     
    WLEadmin, Sep 5, 2014 IP