Possible Hack Alert
-
I am pretty sure my website has been hacked. Luckly I have installed a security plugin that (among other things) scans my files for any changed files. I has located 3 files which were added at a time that I was not modifying code in my website.
Upon investigation these file seem highly suspicious. The code in them seems like hacker code (confusing and not normal code), and also, the files added are named extremely similar to the standard WordPress core files.
I am looking for help form the community and also to alert the community if this is truly a hack.
Files added that are suspicious are:
/wp-logon.php
/wp-radmin.php
/wp-content/plugins/tinymce-advanced/mce/code/wp-comments-blog.phpThere were added in the order listed above, seconds apart from one another.
I am running wordpress version 4.1.1
I am running Elegant Themes Divi Theme version 2.2 (I will also post on the Elegant Theme support site just in case)Plugins running are:
Admin Menu Editor – Version 1.4.3
All In One WP Security – Version v3.9.0
CMS Tree Page View – Version 1.2.31
Contact Form 7 – Version 4.1.1
Custom Facebook Feed – Version 2.3.4
Duplicate Post – Version 2.6
Enable Media Replace – Version 3.0.3
Envira Gallery Lite – Version 1.2.1
Global Content Blocks – Version 2.0.1
Google Analytics by Yoast – Version 5.3.3
Google Places Reviews – Version 1.1.3
Google XML Sitemaps – Version 4.0.8
Imsanity – Version 2.3.5
Jetpack by WordPress.com – Version 3.4.3
Media File Sizes – Version 1.8
TinyMCE Advanced – Version 4.1.7
Under Construction – Version 1.12
User Role Editor – Version 4.18.3
WordPress SEO – Version 2.0.1
WP-Optimize – Version 1.8.9.10Of course I have no idea what plugin might have been vulnerable, of maybe the theme?? I am a very experienced developer, but the honest truth is that I don’t even know where to begin digging through these plugins to determine the breach. Or, maybe it was a breach through FTP or through my hosting provider (godaddy).
For now, I have deleted the files, I desperately hope they do not return, but if the security hole is still there then they likely will.
I will go and update wordpress, every plugin, and change FTP passwords.
If anyone can suggest other items to look at, please let me know!!
- The topic ‘Possible Hack Alert’ is closed to new replies.