• I’m hoping that someone can help me out on this. I have a site that files were added to. I had WP File Monitor added and it notified me that files were added to wp-includes/images and then a couple of files were changed. I removed them and then added WP Defender in the hopes that it would tell me if I had security setup wrong on a folder or something.

    WP Defender did find a couple of things but they were all very minor, low alerts. But whatever is going on, keeps happening. I will go through and remove/restore things and then in a day or so, they are all right back. Here is a list of the files added/changed from the WP File Monitor plugin. I’m hoping that someone here recognizes what this is and now I can fix my site to not let them in anymore.

    Files Changed:

    /wp-content/plugins/index.php
    /wp-includes/post-template.php

    Files Added:

    /wp-content/plugins/jquery-lightbox-for-native-galleries/wp-ajax-gadget.php
    /wp-content/plugins/wassup/zipper-class.php
    /wp-includes/images/list10.gif
    /wp-includes/images/list106.gif
    /wp-includes/images/list914.gif
    /wp-includes/images/list98.gif
    /wp-includes/images/nix156.doc
    /wp-includes/images/nix252.doc
    /wp-includes/images/nix380.doc
    /wp-includes/images/nix572.doc
    /wp-includes/images/nix580.doc
    /wp-includes/images/nix676.doc
    /wp-includes/images/nix732.doc
    /wp-includes/images/nix772.doc
    /wp-includes/images/nix828.doc
    /wp-includes/images/nix868.doc
    /wp-includes/images/pub281.jpg
    /wp-includes/images/pub377.jpg
    /wp-includes/images/pub608.doc
    /wp-includes/images/pub665.jpg
    /wp-includes/images/pub705.jpg
    /wp-includes/images/pub761.jpg
    /wp-includes/images/pub801.jpg
    /wp-includes/images/pub857.jpg
    /wp-includes/images/pub953.jpg
    /wp-includes/images/sched15.tar
    /wp-includes/images/sched734.gif
    /wp-includes/js/scriptaculous/query.js.php

    Has anyone else experienced this or have any idea what I can do to make this stop happening?

Viewing 15 replies - 1 through 15 (of 63 total)
  • it could be a plugin
    the only way to tell is deactivate them all and test

    if it stops re-activate one by one – testing in between

    Have you figured out how they managed to add this backdoor to your site?
    I see many sites affected by this (including mine): wp-ajax-gadget.php

    Any info on this would be appreciated.

    Thread Starter rsconsult

    (@rsconsult)

    No, I have found no other info so far other than it is not a plugin. Hopefully some other people can chime in and offer some suggestions or info.

    Are you by any chance hosted by Dreamhost?

    Thread Starter rsconsult

    (@rsconsult)

    Yes. That site is being hosted with Dreamhost. Although, I was having the issue way before they reset everyone’s password due to the security issue. Still think it may be related?

    That’s the only thing I could think of.

    Thread Starter rsconsult

    (@rsconsult)

    I was thinking they were not related due to the time I’ve had issues but who knows. I’ve cleaned out everything and reset my shell password so we’ll see if it works or not.

    I have also changed all the passwords. But damn, it just happened again!

    Added:
    wp-includes/images/nix549.jpg
    wp-includes/images/nix853.jpg
    wp-includes/images/sched399.tar
    wp-includes/images/sched958.gif
    wp-includes/images/pub137.jpg
    wp-includes/images/pub392.doc
    wp-includes/images/sched558.gif
    wp-includes/images/sched430.gif
    wp-includes/images/pub360.doc
    wp-includes/images/pub785.jpg
    wp-includes/images/pub112.doc
    wp-includes/images/nix997.jpg
    wp-includes/images/list123.tar
    wp-includes/images/nix917.jpg
    wp-includes/images/list211.tar
    wp-includes/images/pub225.jpg
    wp-includes/images/pub64.doc
    wp-includes/images/sched463.tar
    wp-includes/images/nix668.doc
    wp-includes/js/jquery/query.js.php
    wp-content/plugins/bulletproof-security/wp-ajax-gadget.php
    wp-content/plugins/wordpress-file-monitor/zipper-class.php

    Changed:
    wp-includes/post-template.php
    wp-admin/includes/.svn/class-wp-theme-edit.php
    wp-content/plugins/hello.php
    wp-content/plugins/index.php

    Any ideas?
    By the way, which Dreamhost machine are you hosted on? I’m hosted on Warsaw.

    Thread Starter rsconsult

    (@rsconsult)

    Sorry, no ideas here other than maybe put in a support ticket with DH and see if they can give more info. Most of my stuff is hosted on Proty.

    Ok, thanks anyway. I already contacted support yesterday so I’m just waiting for their reply.

    Cheers!
    Erko

    Thread Starter rsconsult

    (@rsconsult)

    I’m curious what they come up with. I hope they can give you some answers.

    Has anyone figured anything out regarding this? I’ve been having the same issue with these same files being added to my site every couple days.

    Thread Starter rsconsult

    (@rsconsult)

    @timeuser – As far as I can tell it is some type of malware. I’m not sure when it got loaded on my sites but after working on it for several months and it just kept coming back, I finally got fed up with working on it on my own. I’ve been using https://sucuri.net for the last couple of weeks and they have cleaned up several sites with no new infestations. To me it was well worth the money to not have to fight with it anymore.

    Good luck with your site.

    Yeah, I’ve considered Sucuri. I’d still like to know where this is getting in, whether it’s through a hole in WordPress or one of the plugins it’d be good if it could be reported and patched.

    Thread Starter rsconsult

    (@rsconsult)

    Agreed. I think my original issue was back over the summer so it is too far gone to check logs to see what may have been happening. I made the mistake of using ftp instead of sftp a couple of times and was thinking it may have been a contributing factor. It is just as likely that something else happened though. It would be nice to know for sure so we could find a way to stop it.

Viewing 15 replies - 1 through 15 (of 63 total)
  • The topic ‘Files being added to one of my sites’ is closed to new replies.