SQL Injection – hacker created pages
-
I am using version 3.9.9 but that wasn’t in the list.
The problem I have involves SQL injection I think. I keep getting pages created on my site, viagra, UK betting, London Hotels…the usual spammy stuff. I checked logins and there were no unauthorised logins which lead me to believe they accessed the site directly through the database. I checked in phpmyadmin and they used the admin ID 0 which doesn’t exist as a user. I gave the database a random prefix as most people advise when I installed the site.
I am blacklisting IPs that have multiple failed logins, my security strength meter reads 380 so I am covering almost all my bases yet they still get in to leave these pages…Any ideas?
https://www.ads-software.com/plugins/all-in-one-wp-security-and-firewall/
- The topic ‘SQL Injection – hacker created pages’ is closed to new replies.