culebras
Forum Replies Created
-
Forum: Fixing WordPress
In reply to: Defacement vulnerability in wordpress 2.7.1Well, I have fixed all the problems. Thanks a lot to jdembowski, because in the link he offered was the solution:
https://ocaoimh.ie/2008/06/08/did-your-wordpress-site-get-hacked/
There were malicious code like:
https://”.base64_decode(“YW55cmVzdWx0cy5uZXQ=”).”/”);
at the beginning of many php files.
I cleaned all the php files affected (all php in theme, almost all php in plugins). Then I downloaded again a fresh installation of worpress, deleted all in my server and I uploaded all the fresh and cleaned stuff.
Speaking with the friend that share the server with me, it looks like that other friend that share the server, uploaded and installed some kind of aplicattion with some security holes. We are not sure if that was the reason to wordpress was hacked. The truth is that was NOT a problem of wordpress.
Anyway, if anybody more has this problem, following the instructions provided by jdembowski will find solution very probably.
Thanks a lot for the help.
Forum: Fixing WordPress
In reply to: Defacement vulnerability in wordpress 2.7.1Well I want to give thanks to jdembowski for the answers, the links and the explanations. As I said before, I am a simple wordpress user, not an expert, so I am sorry if I am not calling the things with the correct name. Therefore, my English is not very good so I am sorry about that too.
By the way, I will take my time to read your explanations carefully and I will try to identify the problem. For example, the blank pages with ad scrap occurs in others pages besides wp-config.php, and the plugins I install and upgrade frecuently withind wordpress new feature. Anyway my wp theme is old, so I will check it with attention. I will ask for help to my friend, the one whe share the server with me.
Anything I discover I will share here soon in order can be useful for anybody.
Forum: Fixing WordPress
In reply to: Defacement vulnerability in wordpress 2.7.1Well, I am not a computer expert. That I wrote is what a friend programmer explained to me. My wordpress site is https://www.culebras.tk and the login page is https://www.culebras.ardeenelinfierno.com/culebras/wp-login.php .
You can see in it that no login box appears, and the wp-login.php is ok in my server, I even uploaded again all the wordpress files.
Looking the code you can see lots of ads links injected in it.
I hope you can find the problem in the code of the my login page.
Thanks.