Administrator accounts were modified
-
Hi,
On different websites I’m getting an email warning that administrator accounts were modified in the database. I’m wondering if these are false positives or if people got in. Below is one example.
Between 07:45 and 07:49 someone was hammering on one page a couple of 100 times.
128.199.104.110 - - [19/Nov/2018:07:48:17 -0500] "GET /produk HTTP/1.1" 200 0 "https://www.domain.com/" "Mozilla/5.0 (Linux; Android 8.1.0; Redmi 5 Plus Build/OPM1.171019.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 128.199.104.110 - - [19/Nov/2018:07:48:18 -0500] "GET /produk HTTP/1.1" 200 0 "https://www.domain.com/" "Mozilla/5.0 (Linux; Android 8.1.0; Redmi 5 Plus Build/OPM1.171019.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 128.199.104.110 - - [19/Nov/2018:07:48:22 -0500] "GET /produk HTTP/1.1" 500 199 "https://www.domain.com/" "Mozilla/5.0 (Linux; Android 8.1.0; Redmi 5 Plus Build/OPM1.171019.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 128.199.104.110 - - [19/Nov/2018:07:48:19 -0500] "GET /produk HTTP/1.1" 200 0 "https://www.domain.com/" "Mozilla/5.0 (Linux; Android 8.1.0; Redmi 5 Plus Build/OPM1.171019.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36"
At 07:48 I got the “Alert: Database changes detected” email, but I don’t see any changes. I’m 100% sure I didn’t change anything and there are no plugins that could make changes to my admin account.
In the Firewall log I saw these lines that worry me:
19/Nov/18 17:40:30 #7642992 HIGH 310 144.76.81.29 GET /wp-admin/setup-config.php - Access to a configuration file - [SERVER:SCRIPT_NAME = /wp-admin/setup-config.php] - domain.com 19/Nov/18 19:48:12 #4861949 INFO - 0.0.0.0 N/A - - Database changes detected - [administrator account] - www.domain.com 19/Nov/18 19:48:12 #3372061 INFO - 0.0.0.0 N/A - - Database changes detected - [administrator account] - www.domain.com
Did people get in using the setup-config.php file?
I just went to that file and I was blocked by Ninja Firewall so I assume that they didn’t get in. But still, why do I get these “Administrator accounts were modified” emails?
- The topic ‘Administrator accounts were modified’ is closed to new replies.