Domain Forum from Acorn Domains Free Domain with 12 months of Website Builder
Domain Meet Weds 5th June in London
Today's Drop Dates are: 14-02-2013 or 21-02-2013   All times are GMT. The time now is 02:06:07 AM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking
Go Back   UK Domain Forum Acorn Domains > Website Design and Promotion > Content Management Systems > Wordpress

Wordpress Wordpress Blogs

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 18-03-2012, 08:47:23 PM     #11 (permalink)
Member
 
Join Date: Jul 2010
Location: Birmingham
Posts: 92
MASSEY is a glorious beacon of lightMASSEY is a glorious beacon of lightMASSEY is a glorious beacon of lightMASSEY is a glorious beacon of lightMASSEY is a glorious beacon of light

I had some hacked that had been on the old wordpress and with plugins in need of update for around 2 months. It is important as soon as you see the update options to do it there and then. Luckily my hacks were not that bad, just a page added to the site with the guys hacker name.

Last edited by MASSEY; 18-03-2012 at 08:51:38 PM.
MASSEY is offline  
Old 18-03-2012, 09:31:30 PM     #12 (permalink)

 
Blossom's Avatar
 
Join Date: Oct 2010
Location: UK
Posts: 1,243
Blossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond repute

Would recommend installing the Ultimate Security and Bulletproof Security plugins along with Block Bad Queries.
__________________
Jenni | Blossom | Video Tutorials

@blossomnu (tell me you're from Acorn & I'll add you back!)
Blossom is offline  
Old 18-03-2012, 10:34:37 PM     #13 (permalink)

 
Join Date: Dec 2005
Location: Midlands
Posts: 753
murph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond reputemurph has a reputation beyond repute

Quote:
Originally Posted by Aegean

I agree with not always needing a CMS, but there are many professional level CMS systems that have much more sophisticated security than wordpress does. WP is an ultra basic CMS and it's very structure makes it vulnerable. I have about 4 WP sites, which run just fine on the latest version, but I don't use it for client work unless they ask for it.
Agreed. I take the stance: stay away from very common public scripts as these are regularly targeted for malware hacking etc. Also, forever having to apply security patches and updates is a constant headache avoided if you roll your own
murph is offline  
Old 19-03-2012, 10:10:08 AM     #14 (permalink)

 
Join Date: Nov 2005
Posts: 2,468
stender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond reputestender has a reputation beyond repute

I've got loads of mentions of base64_decode in one of my plugins w3-total-cache I assume these aren't malicious?
stender is offline  
Old 19-03-2012, 07:29:27 PM     #15 (permalink)

 
Join Date: Nov 2008
Posts: 1,028
dashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond repute

Quote:
Originally Posted by stender View Post
I've got loads of mentions of base64_decode in one of my plugins w3-total-cache I assume these aren't malicious?
Hard to tell, some plugins do have it in - have you got a load of code at the top of your other php files?

It's obviously imperative to keep all plugins and wordpress installs up to scratch, which can be a big headache if you have lots of sites - so I guess the answer is that if you're going to have lots of sites - don't have lots of CMS sites.

With regards to bulletproof security - I did have a very hardened htaccess file on some of these that was practically the code from BPS with a few extra bits thrown in, and they still got hacked.

I think if you have vulnerable files that no security plugin will help - like having the best car alarm & security on the market but leaving the car unlocked and the keys in the ignition.

Anyway, I hope no one else has had problems, it's supposedly an organised crime gang thats doing this to upload trojans and the fake antivirus software, you know the kind of stuff.
dashu1 is offline  
Old 19-03-2012, 09:43:51 PM     #16 (permalink)

 
Brassneck's Avatar
 
Join Date: Apr 2005
Location: Surrey, UK
Posts: 2,488
Brassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond reputeBrassneck has a reputation beyond repute

If you do have lots of sites then you might want to check out www.managewp.com. It's pricey but makes managing updates of everything real easy and quick.

I've got 400 wordpress installations being managed on it.

Cheers
Stephen.
Brassneck is offline  
Old 19-03-2012, 09:58:37 PM     #17 (permalink)

 
ProDomains's Avatar
 
Join Date: Apr 2010
Posts: 1,256
ProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond reputeProDomains has a reputation beyond repute

I keep getting errors malware/virus notifications like this:

# Regular expression match = [decode regex: 1]:

Where several Header, Footer and other .php files seem to infected

# (compressed file: plupload.silverlight.dll) MS Windows Binary/Executable [application/x-winexec]:

Something about something being wrong with a Silverlight file?

# ClamAV detected virus = [PHP.Shell-51]:

bit-64 encryption?

Anyone familiar with this and now how to solve it?
ProDomains is offline  
Old 20-03-2012, 04:02:05 AM     #18 (permalink)

 
JMOT's Avatar
 
Join Date: Feb 2007
Posts: 1,019
JMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond reputeJMOT has a reputation beyond repute
Classified Rating: 100% (1)

One of my sites just got hacked and its being cleaned up and sorted out for me right now.

Luckily I'd already signed up for Sucuri heres my link

Its well worth the money!!
JMOT is offline  
Old 20-03-2012, 09:38:45 AM     #19 (permalink)

 
Join Date: Nov 2008
Posts: 1,028
dashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond reputedashu1 has a reputation beyond repute

Another useful plugin is the exploit scanner.

In it's control panel it gives you the checksum for your wordpress core files, and on their homepage the checksum for WP-whatever version is the latest

So you can see if any core wordpress files have been altered. Even changing a letter from a capital to a lower case would give a totally different string, so you can see quickly and easily whether or not your core files have been fiddled with.
dashu1 is offline  
Old 14-04-2012, 02:15:00 PM     #20 (permalink)
Member
 
Join Date: Aug 2009
Posts: 66
steww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond reputesteww has a reputation beyond repute

Just a note to watch out, I installed a plug named "Ultimate Security Checker" to toughen up a wordpress install, about a week later the site had malware, have just cleaned the site and found (I think) that the security plugin contained malware (or at least became infected), here is the clean up report:

"Site is now clean and malware-free. The following files were compromised and fixed:

CLEARED: Cleared malware from file: ./wp-content/plugins/ultimate-security-checker/securitycheck.class.php"

Hope that helps!

Cheers
steww is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
Abandonded Wordpress sites Wanted Brassneck Website Wanted 0 24-12-2011 09:49:34 AM
Best Hosting for multiple Wordpress sites ? KingDomainNames New Domainers 30 31-08-2011 12:22:07 PM
making wordpress and other sites faster dashu1 Content Management Systems 3 23-06-2010 10:03:54 AM
Example of sites built in Wordpress WaftyCrank Wordpress 13 18-03-2009 07:53:02 PM


All times are GMT. The time now is 02:06:07 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.1
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".