I think someone is hacking/trying to hack my blog
-
I was looking at the raw access logs for my web site and saw an IP address that is not mine, in fact from searching it is a Chinese IP associated with hacking attempts (58.241.255.38), that accessed my WP Admin interface and various other pages.
I see from the logs he was apparently looking for user IDs or something?
/index.php?cat=%2527+UNION+SELECT+CONCAT(666,CHAR(58),user_pass,CHAR(58),666,CHAR(58))+FROM+wp_users+where+id=
/index.php?cat=999+UNION+SELECT+null,CONCAT(666,CHAR(58),user_pass,CHAR(58),666,CHAR(58)),null,null,null+FROM
/wp-content/plugins/fgallery/fim_rss.php?album=-1+union+select+1,0x6875616B,3,4,5,6,7/*
I’ve also noticed odd traffic originating from a .ru domain, so I’m wondering if my blog wasn’t posted as a “Hey everyone go try to hack this site!” deal.
I’ve changed my admin password and banned the offending IP, but I don’t know what else to do. Anyone have any suggestions? Thanks.
- The topic ‘I think someone is hacking/trying to hack my blog’ is closed to new replies.