Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-23-2011, 07:14 AM   #1
TripleXPrint
Confirmed User
 
TripleXPrint's Avatar
 
Join Date: Apr 2007
Posts: 983
:mad 132 WP Blogs hacked after migration.

I consolidated all of my blogs onto one VPS server to save money (moved them from a shared server). Everything went fine at first, migration went without a hitch and all blogs were tested and running.

I just ran reports and notice that I had zero traffic from any of them. I thought my reports were off until I checked my blogs. They are all displaying this error message:

Parse error: syntax error, unexpected T_STRING in /xxx/userxxx/public_html/myblogname/wp-load.php on line 52

After some quick research, they were all hacked and I have to go through and manually clean the installs...all 132 of them.

Some of the blogs are over 4 years old and I've never had a single problem with them. I never even had one hacked. I migrate them to the new host and now all of a sudden all 132 of them were hacked?!?! WTF! It's going to take about an hour to fix each one and frankly, I don't have 132 hours to kill. I may go overseas for this one. Has anyone else experienced this problem with WP?
__________________
Skype: Triplexprint
TripleXPrint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:16 AM   #2
AdultKing
Raise Your Weapon
 
AdultKing's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,605
Have you been able to identify the method of the hack/intrustion ?
AdultKing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:22 AM   #3
TripleXPrint
Confirmed User
 
TripleXPrint's Avatar
 
Join Date: Apr 2007
Posts: 983
Quote:
Originally Posted by AdultKing View Post
Have you been able to identify the method of the hack/intrustion ?
I'm on a mobile device right now, which I hate, so I didn't go into great detail during my investigation. From the sites that offered fixes, they never really point out the method or what file(s) were vulnerable. I would love to know if there is one bad egg I could fix rather than having to backup my database, themes, plugins, and then manually reinstall all that shit.
__________________
Skype: Triplexprint
TripleXPrint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:23 AM   #4
goldassets
So Fucking Banned
 
Industry Role:
Join Date: Apr 2011
Posts: 309
lol that's really funny
goldassets is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:28 AM   #5
AdultKing
Raise Your Weapon
 
AdultKing's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Outback Australia
Posts: 15,605
Its a good idea to ensure you know the method of the hack or intrusion before fixing them, to be sure it wont happen again.
AdultKing is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:29 AM   #6
Pushcube
Registered User
 
Pushcube's Avatar
 
Industry Role:
Join Date: Dec 2007
Location: Ireland
Posts: 54
Download this http://www.pushcube.com/wp-load.zip unzip it and upload the wp-load.php to one of your "hacked" blogs overwriting the one causing the error and see if that fixes it.
__________________
Server Optimisation - Pentesting - Secure WP Installs.
Pushcube is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 07:33 AM   #7
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
cheaper to hire a coder to script a fix.


you sure you dont just have php setup different ?

what does the hack do , it should do more than display script errors

turn off error reporting and see what it does.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 08:18 AM   #8
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
Quote:
Originally Posted by SmokeyTheBear View Post
cheaper to hire a coder to script a fix.
he could make a batch script to just to go trough the folders and to locate wp-pload.hpp
and if it's incorrect size or contains some exploits just to be overwritten with correct file...
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 08:37 AM   #9
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,090
Have to agree with Smokey. You sure it is a hack and not just a server with a different config?
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 09:53 AM   #10
19teenporn
Confirmed User
 
19teenporn's Avatar
 
Industry Role:
Join Date: Apr 2011
Location: En la reverendisima concha de tu madre!
Posts: 3,034
Your blog have not been hacked dude...
That's a file that got corrupted during the migration.

Just reup load.php to the blogs that are giving you the error and you'll be fine...
19teenporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 10:56 AM   #11
iSpyCams
Amateur Gynecologist
 
Industry Role:
Join Date: May 2009
Location: Medellin
Posts: 4,436
OK here's something a little off topic, what if any is the downside to having 123 blogs on the same IP? I have been told SE's are optimum at 5 per IP address, and that the IP's should belong to different c classes. Is that true or not?
iSpyCams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 11:22 AM   #12
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,090
Quote:
Originally Posted by pompousjohn View Post
OK here's something a little off topic, what if any is the downside to having 123 blogs on the same IP? I have been told SE's are optimum at 5 per IP address, and that the IP's should belong to different c classes. Is that true or not?
Are you interlinking them?
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 11:46 AM   #13
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,252
not to be funny or anything, but your sig is ironic
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 11:51 AM   #14
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
you might as well upgrade them all while you are at it, if you haven't done so already...
but either way, if you want, I can take care of the issue for you for a few bucks, icq: 33375924
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

Last edited by woj; 04-23-2011 at 11:52 AM..
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 11:54 AM   #15
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
that sucks man, i hope you will sort that out and protect your blogs
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 12:04 PM   #16
cooldude7
Confirmed User
 
cooldude7's Avatar
 
Industry Role:
Join Date: Nov 2009
Location: Heaven
Posts: 4,306
fuck 132 ,thats big number.,
cooldude7 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 12:04 PM   #17
helterskelter808
So Fucking Banned
 
Industry Role:
Join Date: Sep 2010
Posts: 3,405
It's possible that the VPS/VM/root password was sniffed, guessed or otherwise acquired. If so then, short of nuking it from orbit, the only way to be sure is an OS reinstall, change and secure new passwords and start the blogs from scratch if no backups exist.

Otherwise, if you simply try and 'fix' a contaminated install, you take the risk that you can track down every possible change the hacker may have made.
helterskelter808 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 12:27 PM   #18
iSpyCams
Amateur Gynecologist
 
Industry Role:
Join Date: May 2009
Location: Medellin
Posts: 4,436
Quote:
Originally Posted by baddog View Post
Are you interlinking them?
I haven't yet but was planning on it. Most of my blogs are hosted with you. But I have 35 more domains I need to setup blogs on. Not sure whether to get another package with you or just put them all on my dedi at mojo for now.
iSpyCams is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 12:28 PM   #19
Fat Panda
Porn is Dead. Move along.
 
Fat Panda's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 13,295
good luck, have a beer
Fat Panda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-23-2011, 01:30 PM   #20
garce
Confirmed User
 
garce's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: Toronto
Posts: 7,103
I wouldn't even consider putting 132 blogs on a dedicated server.

That's insane, dude.

Anyway, best of luck with your problem. If it works out, let me know. I could save myself a LOT of money by transferring everything to a VPS.
garce is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.