Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 03-15-2016, 09:50 PM   #1
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
Found the domain hacking my wordpress

KoMexX.net

found his domain name inserted into my wordpress theme.. which leads to that website. what gives man with these guys?
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-15-2016, 10:05 PM   #2
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
Bots man.. we're the last humans left.
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-15-2016, 10:30 PM   #3
bearjew
Registered User
 
bearjew's Avatar
 
Industry Role:
Join Date: Dec 2014
Posts: 17
clean out then secure your wordpress
bearjew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-15-2016, 11:01 PM   #4
_Lush_
Confirmed User
 
_Lush_'s Avatar
 
Industry Role:
Join Date: Jul 2005
Location: GDL Jal.
Posts: 536
stop downloading nulled plugins and themes from free dl sites. You dont think all those cool plugins and themes that you are suppose to pay for are being shared by kind uploaders who just want to share the love. most are coded with injection scripts that bleed a percentage of your traffic from your site.

easy fix just ssh into your site and grep -nr komexx.net /www/wordpress/wp-content
or whatever the path to your wp is on your server and find what plugin or theme contains instances of this domain and delete the whole plugin or theme.
__________________
IcQ 50611033
_Lush_ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-15-2016, 11:13 PM   #5
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Quote:
Originally Posted by _Lush_ View Post
easy fix just ssh into your site and grep -nr komexx.net /www/wordpress/wp-content
or whatever the path to your wp is on your server and find what plugin or theme contains instances of this domain and delete the whole plugin or theme.
I suggest adding -i (case insensitive compare) to the grep options, so it catches mixed capitalisation instances like "KoMexX.net" too.

grep -nri komexx.net /path/to/wp-content/

Also it's possible that the plugin has stashed a file outside of that directory, or obfuscated the name so that a simple text search won't find it (eg $domain = "kom"."exx".".net")
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-16-2016, 01:30 AM   #6
bearjew
Registered User
 
bearjew's Avatar
 
Industry Role:
Join Date: Dec 2014
Posts: 17
also search for 'base64_decode' and 'eval'
bearjew is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-16-2016, 01:11 PM   #7
anexsia
Confirmed User
 
anexsia's Avatar
 
Industry Role:
Join Date: May 2010
Posts: 5,735
Install OSSEC and clamav with maldet for daily scans.

Save your wp-config.php file, uploads folder, and your MySQL database (after making sure all 3 are clean) and just redownload a fresh copy of Wordpress and then put your wp-config.php and uploads folder back and your MySQL database. Run a scan on everything and then you should be good to go.
anexsia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-16-2016, 02:06 PM   #8
adentio99
So Fucking Banned
 
Industry Role:
Join Date: Jul 2015
Location: USA
Posts: 366
script kiddies.
adentio99 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
wordpress, found, domain, website, guys, theme, komexx.net, hacking, inserted, leads



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.