paulmfield
Forum Replies Created
-
sorry im an idiot lol found it ??
thanks so much for replying, i actually started to figure it all out
one question, how do you set how many posts are listed? my videos are showing up in rows of three, so i want to set 9 or 12 instead of 10
please give me an email address that i can send my logs to… i opened a ticket on the site…
i have over 50 wordpress sites on my server, and this is the only one with NEXTGEN, and the only one that has been hacked.
And the logs show accessed to files in that folder before the hacked admin accounts show up in wordpress, so one of the files in there is being exploited.
Here are some of the files they accessed as they were getting admin rights in our wordpress site:
195.182.142.73 [03/Mar/2015:07:24:22 +0000] POST /wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ngglegacy/lib/media-rss.php HTTP/1.1 200 238 –
195.182.142.73 [03/Mar/2015:07:24:22 +0000] POST /wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/router/interface.router.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:07:24:23 +0000] POST /wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/mediarss/class.mediarss_controller.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:07:24:24 +0000] POST /wp-content/gallery/error.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:14:41:59 +0000] POST /wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/nextgen_basic_album/adapter.nextgen_basic_album_forms.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:14:42:02 +0000] POST /wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ngglegacy/view/imagebrowser-exif.php HTTP/1.1 200 262 –
195.182.142.73 [03/Mar/2015:14:42:03 +0000] POST /wp-content/themes/twentytwelve/single.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:14:42:04 +0000] POST /wp-content/gallery/nashville-january-2011/dynamic/dir.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:15:44:20 +0000] POST /wp-content/gallery/second-fiddle/dynamic/page.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:15:44:21 +0000] POST /wp-content/themes/twentythirteen/fonts/view.php HTTP/1.1 404 5013 –
195.182.142.73 [03/Mar/2015:15:44:23 +0000] POST /wp-content/uploads/2014/07/alias.php HTTP/1.1 200 291 –The 404 errors are probably files I found that had been used before and I have cleaned up, but they still managed to get in again.
I can send entire logs sorted by IP address if needed.
I am having the exact same problem, same plug-in
spammers are adding admin accounts to my wordpress and placing php files all over my site that spam email.
i have updated to the latest and removed every file i can find, and this morning they were back in the admin console.
please fix this problem.
if there are any logs i can send you, let me know