SItes hacked and keeps coming back .. Please help
-
I have a windows environment All my sites are up to date with the latest version of wordpress, version 5.6 of php and all the plugins are up to date.
I have 6 sites with wordpress and all of them now have wordfence installed. I have followed the guidelines in the article about hardening up worpress. I run multiple scans on all sites. At this point, they all come up clean most of the time. But I still find the problems that I am listing next.
2 or 3 times a day, at least one site or more gets between 8 and 14 new php files in the root dir. the names are sympathy.php, known.php, have.php, enjoy.php, effort.php, chemistry.php and more. Sometimes I will find php files in the uploads dir. of the affected site. (I can provide examples of these files.) Sometimes, that site will also start sending out spam mail. Cleaning up the new files stops the spam, but all of the new files seem to just be a few links in the files. Also, in live traffic, people are trying to access those urls.
In addition to that, at one point a different hack took over many of my sites and added code to many existing pages. (I have that code as well.)
That code had this “onfr64_qrpbqr” and from my searches that seemed to be the virus signature. I removed all that code and that issue has not returned.
All of this started happening a week ago. Although I have checked for vulnerabilities and think I took care of all of them, the first one keeps recurring. I have fixed my php ini files to be secure, blocked my eternal ports that need to be blocked, and used wordfence to harden up the sites. All other sites on the server are just standard html sites, and I have completely turned off ftp. I have changed everyone’s passwords and also changed the secret keys in all the wordpress installs.Sorry if this is a lengthy post, but I tried to give as much info as possible so someone can help.
- The topic ‘SItes hacked and keeps coming back .. Please help’ is closed to new replies.