For the 5th time, someone was able to create an own administrator account within our wordpress environment.
How can I prevent it?
What seems to be the caus?
Many thanks!
]]>In other words, there has clearly been a data breach on www.ads-software.com that has leaked its login addresses and passwords in cleartext.
]]>Example of fake urls with a 404 redirect.
https://alternativesmallbusiness.fund/www.cashadvance.com/unsubscribe
https://alternativesmallbusiness.fund/common-questions? https://alternativesmallbusiness.fund/scams? https://alternativesmallbusiness.fund/www.cashadvance.com/account-center? https://alternativesmallbusiness.fund/www.cashadvance.com/sitemap
https://alternativesmallbusiness.fund/fees
https://alternativesmallbusiness.fund/account-center/forgot-password
https://alternativesmallbusiness.fund/www.cashadvance.com/start-here
https://alternativesmallbusiness.fund/www.cashadvance.com/sitemap
https://alternativesmallbusiness.fund/www.cashadvance.com/scams
https://alternativesmallbusiness.fund/www.cashadvance.com/policy/
https://alternativesmallbusiness.fund/www.cashadvance.com/policy
https://alternativesmallbusiness.fund/www.cashadvance.com/locations
https://alternativesmallbusiness.fund/www.cashadvance.com/loan-alternatives/
https://alternativesmallbusiness.fund/www.cashadvance.com/fees/
https://alternativesmallbusiness.fund/www.cashadvance.com/fees
https://alternativesmallbusiness.fund/www.cashadvance.com/espanol
https://alternativesmallbusiness.fund/www.cashadvance.com/econsent
https://alternativesmallbusiness.fund/www.cashadvance.com/disclosure
https://alternativesmallbusiness.fundhttps/www.cashadvance.com/disclaimer
https://alternativesmallbusiness.fund/www.cashadvance.com/contact-us/
https://alternativesmallbusiness.fund/www.cashadvance.com/contact-us
https://alternativesmallbusiness.fund/www.cashadvance.com/common-questions/
https://alternativesmallbusiness.fund/www.cashadvance.com/common-questions
https://alternativesmallbusiness.fund/www.cashadvance.com/
https://alternativesmallbusiness.fund/www.cashadvance.com
https://alternativesmallbusiness.fund/partner/
https://alternativesmallbusiness.fund/locations
https://alternativesmallbusiness.fund/fees
https://alternativesmallbusiness.fund/econsent
https://alternativesmallbusiness.fund/disclosure/
https://alternativesmallbusiness.fund/disclosure
https://alternativesmallbusiness.fund/account-center/forgot-password
https://alternativesmallbusiness.fund/www.cashadvance.com/account-center
https://alternativesmallbusiness.fund/scams/
https://alternativesmallbusiness.fund/common-questions/
]]>Today, my blog started to redirect to spammy websites.
As I did not know where the hack came from, I asked OVH to restore my FTP files thanks to a back-up. And I did the same for the database.
But the issue was still here with clean files.
I was not able to access my WP-Admin because of the redirect, so I tried to deactivate Javascript via Chrome. And the issue was gone.
Then, I deactivated all my plugins thanks to my FTP, and I reactivated them to see where was the issue.
And the issue is… CLASSIC EDITOR!
Apparently, the hack used a breach in Classic Editor and a Javascript redirect.
So, be careful!
]]>plugins/customer-area/libs/js/bower/fancytree/xprofiled.php: SiteLock-PHP-INJECTOR-1-ewp.UNOFFICIAL FOUND
plugins/customer-area/src/php/core-addons/addresses/rtemplate.php: JCDEF.PHP.CMDSHELL-01N.UNOFFICIAL FOUND
Other errors found were:
themes/freedom/js/dfhstyle.php: SiteLock-PHP-BACKDOOR-GENERIC-aug.UNOFFICIAL FOUND
uploads/2016/06/zyhtypes.pl: SiteLock-PHP-SHELL-et.UNOFFICIAL FOUND
I’ve already deleted the files and they are reactivating my account.
Regards,
A.R.
iPage Support Message:
“Thank you for your patience and holding.
Sorry, I have checked your account and currently it is suspended due to malware found on routine scan in your account, so CGI scripting too is disabled in your account.”
What it didn’t tell me, and I’ve subsequently found out from my hosting company – an attack on June 20th got through and my entire site and subsites are now showing a great many hacks. In fact, even images were hacked. This was neither reported NOR blocked by Wordfence. I didn’t get a single email about this – only visibility when I happened to log into one of my sites.
Clearly, this wasn’t blocked, and I understood that was a function of the free version. I’ve considered the paid version, but if this can happen where it shouldn’t, how am I to know my paid version would protect me any better?
]]>