Sites compromised
-
I run a handful of sites on WP 3.0 (now 3.1). Each morning over the past couple of days I awaken to broken sites. The primary busted file is usually wp-includes/functions.php but there are others. Been able to find them quickly via the php errors reported.
I upload a clean file and that fixes the problem temporarily until the next incident. I’ve been unable to find the malicious code that’s causing the problem. Have changed db passwords, ftp passwords, toughened chmod on wp-config and other content folders, but I’m getting nowhere. I guess the problem is buried somewhere in my database.
They are also breaking my admin panel. I’ve had to reupload the entire wp-admin folder. These are temporary fixes because overnight, and sometimes during the day the sites break again.
Has anyone else had this problem and found where the vulnerability is? I’m tearing my hair out. Even upgrading to 3.1 did not fix the problem.
My “hosing” company is Rackspace. They tell me that this is a widespread problem affecting many of their WP users. Why is there no news or info on this anywhere?
- The topic ‘Sites compromised’ is closed to new replies.