Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-10-2010, 12:54 AM   #1
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
Wordpress stealth hack

Wordpress sites are being hacked by the hundreds, and you may not even realize that yours is too if you host on any number of shared servers (Network Solutions, Dreamhost, GoDaddy, etc...).

http://www.wpsecuritylock.com/breaki...-on-dreamhost/
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 01:15 AM   #2
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Thanks man bump for more awareness
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 01:36 AM   #3
SGS
Confirmed User
 
SGS's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Mallorca - Nottingham
Posts: 5,176
Wordpress = fucking nightmare.
__________________
See sig...
SGS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 01:42 AM   #4
CunningStunt
Confirmed User
 
CunningStunt's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 5,594
Where there's a will, there's a way.

Any mass software solution is going to be hit sooner or later. Stinks, but it's inevitable.

Thanks Brujah. Now I remember why I let a 100 domain experiment die on its ass.
CunningStunt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 04:32 AM   #5
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
thats what you get for hosting on a shitty web host, serves them right
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 04:58 AM   #6
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
Quote:
Originally Posted by Brujah View Post
Wordpress sites are being hacked by the hundreds, and you may not even realize that yours is too if you host on any number of shared servers (Network Solutions, Dreamhost, GoDaddy, etc...).

http://www.wpsecuritylock.com/breaki...-on-dreamhost/
thanks for notice
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 05:09 AM   #7
LoveSandra
So Fucking Banned
 
Join Date: Aug 2008
Location: Just Blow Me
Posts: 10,551
Quote:
Originally Posted by SGS View Post
Wordpress = fucking nightmare.
sometimes , yes
LoveSandra is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 06:37 AM   #8
CPimp
Confirmed User
 
CPimp's Avatar
 
Industry Role:
Join Date: Aug 2009
Posts: 2,346
That friggin sucks.
__________________
three 997 three 55 three 1 ← That's my ICQ. Contact me there. Thanks.
CPimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 06:41 AM   #9
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
This seems like a hosting issue, not wordpress.

Any php site on these affected shared hosts are vulnerable. There are people with phpld, joomla sites, even custom php sites that are getting hit. Only thing they have in common is that they used one of the above-mentioned shared hosts.
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 06:41 AM   #10
bloggerz
Too lazy to set a custom title
 
bloggerz's Avatar
 
Industry Role:
Join Date: Dec 2006
Posts: 16,256
its only on shared hosting? so blogs on dedicated servers aren't being affected?
__________________
I SELL ADULT BACKLINKS! Email: eroticweb>gmail SKYPE: gfybloggerz

$$$$$ MAKE HUGE MONEY IN CAMS - CLICK HERE $$$$$
bloggerz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 06:50 AM   #11
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
Quote:
Originally Posted by bloggerz View Post
its only on shared hosting? so blogs on dedicated servers aren't being affected?
Yes, that's what I have read, only certain shared hosts are being hit right now.
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 08:12 AM   #12
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Wonder if it is the same shitheads that did the big attack last time.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 10:47 AM   #13
ottopottomouse
She is ugly, bad luck.
 
ottopottomouse's Avatar
 
Industry Role:
Join Date: Jan 2010
Posts: 13,177
Thanks for that. Can't find any with a problem
__________________
↑ see post ↑
13101
ottopottomouse is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 10:56 AM   #14
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 11:54 AM   #15
MrBottomTooth
Confirmed User
 
MrBottomTooth's Avatar
 
Join Date: Sep 2009
Posts: 5,795
Quote:
Originally Posted by Why View Post
has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge
Dreamhost, network solutions, godaddy are all being hit, all kinds of php sites. Not exclusive to wordpress at all.
MrBottomTooth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 11:58 AM   #16
TheDA
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 4,665
Quote:
Originally Posted by Why View Post
has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge
I wondered the same to be honest. I haven't seen a site listed that's been hit yet.
TheDA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 11:59 AM   #17
TheDA
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 4,665
Quote:
Originally Posted by MrBottomTooth View Post
Dreamhost, network solutions, godaddy are all being hit, all kinds of php sites. Not exclusive to wordpress at all.
Do you know of any that have been hit by any chance?
TheDA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 12:31 PM   #18
Brujah
Beer Money Baron
 
Brujah's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: brujah / gmail
Posts: 22,157
On wordpress.org forums there's a list of people who claim their sites were hacked.
http://wordpress.org/support/topic/396524?replies=1

Add BlueHost to the list of shared hosts. Also, this doesn't seem to be exclusive to wordpress, but sometimes other .php files on the servers.
__________________
Brujah is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 12:38 PM   #19
Dirty Lord
Confirmed User
 
Dirty Lord's Avatar
 
Join Date: Nov 2007
Posts: 2,681
Quote:
Originally Posted by SGS View Post
Wordpress = fucking nightmare.
dont say that
__________________
Dirty Lord is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 12:41 PM   #20
icymelon
Confirmed User
 
Industry Role:
Join Date: Dec 2007
Location: Las Vegas
Posts: 3,220
cant you set wordpress to only let your ip login?
__________________
Network Of Adult Blogs With Hardlink Rentals Available
icymelon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 12:48 PM   #21
harvey
Confirmed User
 
harvey's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: 127.0.0.1
Posts: 9,266
the attacks are on Apache, not WordPress, that's why it only works on shared hosting. They attacked WP, ZenCart, Drupal and almost any PHP file at sight. Thing is WP has millions of users, hence you'll see "WP is under attack". Or do you expect to see "some custom php script is under attack"? geez, some people

Quite curiously, you'll rarely see "some idiots at shared hosting have no clue about what they're doing", and in 99% of cases that is the issue.
__________________
This post is endorsed by CIA, KGB, MI6, the Mafia, Illuminati, Kim Jong Il, Worldwide Ninjas Association, Klingon Empire and lolcats. Don't mess around with it, just accept it and embrace the truth
harvey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 12:50 PM   #22
harvey
Confirmed User
 
harvey's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: 127.0.0.1
Posts: 9,266
Quote:
Originally Posted by icymelon View Post
cant you set wordpress to only let your ip login?
yes you can with some easy custom mod. However, the attacks were from inside the server, so how do you stop that? Last time, when the NetSol fiasco shown up (1 month ago or so) it was proven they had a rogue admin that changed permissions to allow access to account. Same with GoDaddy hosting. How do you plan to stop that?
__________________
This post is endorsed by CIA, KGB, MI6, the Mafia, Illuminati, Kim Jong Il, Worldwide Ninjas Association, Klingon Empire and lolcats. Don't mess around with it, just accept it and embrace the truth
harvey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 01:18 PM   #23
Davy
Confirmed User
 
Davy's Avatar
 
Industry Role:
Join Date: Apr 2006
Location: Germany
Posts: 4,323
I have no problems with my php sites on Dreamhost.
__________________
---
ICQ 14-76-98 <-- I don't use this at all
Davy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 02:57 PM   #24
Argos88
So Fucking Banned
 
Industry Role:
Join Date: Sep 2009
Posts: 1,732
This is a sever config problem.. NOT Wordpress....
Argos88 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-10-2010, 03:14 PM   #25
TheDA
Confirmed User
 
Industry Role:
Join Date: May 2006
Posts: 4,665
I checked all my WP stuff on shared earlier and it was OK!
TheDA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.