Subscribe via Feedburner Flickr Images Youtube Profile LinkedIn Profile
GD Simple Widgets

Website hacking issues

Thumbnail for Website hacking issues

For some time now, every few days, this website is subject of some kind of injection attack. I made some changes to improve security, and I have installed Firewall plugin, upgraded and reinstalled the blog and all plugins but, attacks continue.

Firewall plugin stops several attack each day, but still some of them got through and only header.php file of the theme ends up changed and code is injected there. If any one has any suggestion on how to stop this type of attack, please leave a comment with suggestions on how to prevent this. I already did everything I can think of including protecting folders, wp-config and all the other things.

If you leave a comment that helps solve the problem, I will award you with premium support license on Dev4Press for GD Star Rating.

GD Star Rating
loading...

Share this:

del.icio.us DiGG Google StumbleUpon Google Buzz Microsoft Live MiXX RSS PDF
Website hacking issues, 6.5 out of 10 based on 20 ratings

29 Responses to “Website hacking issues”

  1. donnacha | WordSkill | January 13, 2010 at 9:50 PM

    Did you completely re-install WP after the first hack? I wonder if they left a back door?

    GD Star Rating
    loading...
    • MillaN | January 13, 2010 at 10:24 PM

      I did it twice with 2.9.1.

      GD Star Rating
      loading...
      • donnacha | WordSkill | January 13, 2010 at 10:36 PM

        Yeah, I kind of guessed you would have, that is why I didn’t suggest it when we exchanged emails about it last month.

        Wow, it’s a real mystery! The prime suspect is some weakness in your theme’s header.php but, of course, I know that you will have already gone over that a hundred times.

        I hope someone manages to solve the mystery, your offer of a premium license is smart, perhaps you should also post this offer to a few of the PHP and WordPress discussion sites.

        GD Star Rating
        loading...
        • MillaN | January 13, 2010 at 10:56 PM

          In the last 2 days, firewall stopped several attacks and header.php is still ok, so maybe the last update solved it. Hopefully problem is gone, but I would like to know how that could happen if the WP is latest version fully reinstalled.

          GD Star Rating
          loading...
    • Randy Brown | February 9, 2010 at 2:46 AM

      WordPress File Monitor Plugin will provide you with
      an email of a time when files are changed.

      get it here:

      http://www.wpbeginner.com/plugins/wp-security-wordpress-file-monitor-plugin/

      Look for a pattern in when events occur that modify the header file. Every little bit of info is critical when trying to solve these issues.

      GD Star Rating
      loading...
      • MillaN | February 11, 2010 at 1:06 PM

        Thanks. I am building much more advanced plugin for this same job, but for now this is a good start.

        GD Star Rating
        loading...
  2. Claudiu Popescu | January 14, 2010 at 4:46 PM

    I’ll gladly help you with this issue, I’m not doing it for money or anything else.
    If you have the knowledge then you can fix this by yourself, it’s rather easy.
    You need to install mod_security for apache, this is if you have apache as web server and if you are the admin of the server where this web site is hosted.
    If this is not the case then send me a email with all the details you can give.

    GD Star Rating
    loading...
    • MillaN | January 14, 2010 at 4:54 PM

      Right now things are OK, and no files got hacked for 4 days. But, firewall plugin registers 10-15 injection and traversal attacks each day.

      As for apache, I am on the BlueHost hosting, and it has no mod_security installed. Hopefully, no injections will happen, but I will monitor things daily.

      GD Star Rating
      loading...
    • MillaN | January 15, 2010 at 12:07 PM

      Well, looks like that problem is still there. The backdoor that hacks only, and only header.php of the active theme is hidden somewhere, so how to find it?

      GD Star Rating
      loading...
      • Claudiu Popescu | January 15, 2010 at 1:42 PM

        You should contact BlueHost, ask them to check the logs, specify the dates on which your web site got compromised.
        Also you should ask for mod_security if you are on a linux/apache server (but keep in mind, that some rules may not be compatible with your web site, making some of it’s sections inaccessible).
        What you can do is to change all the passwords, including ftp, web hosting panel, etc.

        If you have access to the logs then you can find out what is the problem by yourself.

        GD Star Rating
        loading...
      • pamelad | January 16, 2010 at 3:58 PM

        Have you checked all of your javascript files? Those are notorious for having back doors and being infected. Also, have you deleted the admin role that is standard with wordpress? Just another way to get hacked :(

        I use a sister company of BlueHost (HostMonster) and I haven’t had any problems so far. Hopefully, I won’t…

        GD Star Rating
        loading...
  3. MillaN | January 16, 2010 at 4:21 PM

    I will install PHP IDS (Bluehost suggestion) to monitor every type of requests and try to find out exactly where the attack is done.

    Also I have many websites on BlueHost and this is only one being hacked.

    GD Star Rating
    loading...
  4. c hanna | January 17, 2010 at 5:40 AM

    Hi,
    I have the Star rating now on my wordpress site. I went to the IP part to ban this one commenter that leaves strange stuff, but it won’t ban his IP. I banned another IP that was selling drugs and that worked fine. Why would this one IP not ban?

    Sorry to butt in on this forum…I didn’t know where else to leave question.

    After reading this hacking issue I realize that my site may be vulnerable too. I use bluehost. How do you know if someone is getting into your site?

    Thanks.

    GD Star Rating
    loading...
    • MillaN | January 17, 2010 at 12:16 PM

      I will check why IP is not banning.

      GD Star Rating
      loading...
  5. c hanna | January 17, 2010 at 7:35 PM

    thanks. So far just tried the two. One banned ok the other one did not.

    GD Star Rating
    loading...
    • MillaN | January 18, 2010 at 1:07 AM

      Is the IP added to the banned list on IP panel? And if it is, how do you now that plugin is not banning that one. I have tested and it’s working fine. On this website I have some 20 IP’s in the list and as far as I can tell, banning works fine.

      GD Star Rating
      loading...
      • c hanna | January 18, 2010 at 1:29 AM

        Right. I went into the IP for Gd starrating and that is where I banned the one person. The other one I tried but it doesn’t take.

        Do you think its some kind of hacker? I don’t know why they would, I don’t have any sales or pay pal stuff.

        It must not be anything to do with the gd rating. I will call my host and maybe they can tell what’s going on with this particular IP.

        Thanks. At least I narrowed it down a little.

        GD Star Rating
        loading...
        • MillaN | January 18, 2010 at 2:25 AM

          You add IP and it’s not saved to the banned list on the IP panel? The only known way for this to happen is if the IP is invalid. Plugin checks the format before saving it.

          GD Star Rating
          loading...
  6. c hanna | January 18, 2010 at 6:23 PM

    I just used the ban IP Masked and it took it. I’m not sure what masked means, but it took it there. Hopefully this will do the trick. He just left another comment, always uses different name but its the same IP each time.

    GD Star Rating
    loading...
    • MillaN | January 18, 2010 at 6:51 PM

      Plugin IP filter only works for plugin, and filters votes, doesn’t prevent user for doing anything else on the website.

      GD Star Rating
      loading...
      • c hanna | January 18, 2010 at 11:15 PM

        Do you know how to ban this guy. He is in again. here is the strange website that they come in from:
        mmacomments dot com

        Ya, he’s in there again right now. hahaha!

        GD Star Rating
        loading...
        • MillaN | January 19, 2010 at 2:04 AM

          Try finding some plugin that can filter IP addresses completely and prevent access to website.

          GD Star Rating
          loading...
        • Claudiu Popescu | January 19, 2010 at 9:20 AM

          You can ask your web hosting provider to block that IP from the server’s firewall, explain to them what is that ip doing and maybe you will get lucky. If you have a dedicated ip address for your web site, then they can block this ip only for your web site.

          GD Star Rating
          loading...
          • c hanna | January 20, 2010 at 1:20 AM

            Thank you everyone for the help. I’ll try these last two ways. thankyou

            GD Star Rating
            loading...
  7. Grant | January 29, 2010 at 12:48 AM

    Hi Millan.

    Ban them at .htaccess level!

    Also check that your .htaccess file is setup properly. I had a similar problem when a plugin modified my .htaccess than a few days later I had modified header.php and footer.php

    GD Star Rating
    loading...
    • MillaN | January 29, 2010 at 1:57 AM

      Already did that, but I can do it again, maybe I overlooked something. Also, this website will soon get new theme and most of the things will be made from scratch starting with full WP install, DB and files cleanup and server settings review.

      GD Star Rating
      loading...

Comments are closed.

www.dev4Press.com

Dev4Press is a premium service dedicated to developing of high quality plugins and themes for WordPress, custom development and consulting. Follow this link to find out more...

Feedburner Feedburner updates

Sign up to receive all latest news about GD Star Rating directly to your email.
xScape Premium Themes