Wordpress hackers? Pls Check this

Discussion in 'Site & Server Administration' started by cheetuh, Jul 31, 2008.

  1. #1
    Are any wordpress hackers out there? I mean. I'm on a dedicated machine, site on wordpress and someone hacked my logo image.

    check urself http://www.britneyfans.org

    How come they did that?
     
    cheetuh, Jul 31, 2008 IP
  2. cheetuh

    cheetuh Peon

    Messages:
    410
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I just cleaned it. They had changed my header image with some bad words on it.

    When i logged in in my ftp i saw that the "owner" of the files was some "99 99" instead of my login name.
     
    cheetuh, Jul 31, 2008 IP
  3. awesomehosting

    awesomehosting Banned

    Messages:
    409
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    130
    #3
    mmm did someone hack the machine or did someone use a flaw in the template...is wordpress dodgy?> surely wordpress is safe and they did it some other way?>
     
    awesomehosting, Jul 31, 2008 IP
  4. cheetuh

    cheetuh Peon

    Messages:
    410
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Well they changed the main image with some words in spanish like "slut" and things like that.

    When i login via ftp. Those files they changed (and some others also) have their owner under a name "99 99" instead of my login name "XXXXX".

    Weird.

    The cache pages and public_html also have two onwers now. my login name and some login called 99
     
    cheetuh, Jul 31, 2008 IP
  5. cheetuh

    cheetuh Peon

    Messages:
    410
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Form What i know my images were "DEFACED". Dunno whats that about
     
    cheetuh, Jul 31, 2008 IP
  6. Yousif

    Yousif Banned

    Messages:
    233
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Well, you didn't configure your script properly, or it was an out-dated version which lead to a vulnerability the attackers could exploit.
     
    Yousif, Jul 31, 2008 IP
  7. god_archang3l

    god_archang3l Peon

    Messages:
    43
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    You've got hacked with an exploit for wordpress, they have used a remote file to access your c99 or other script that can get your server information and modify the files.

    Try to upgrade to latest if you are running the latest wp see your chmod of scripts.

    Take care
     
    god_archang3l, Jul 31, 2008 IP