GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Please help me fix our foundation website (wordpress) (https://gfy.com/showthread.php?t=1168317)

xxweekxx 06-12-2015 01:07 PM

Please help me fix our foundation website (wordpress)
 
My mom has a foundation for disabled people and some faggot hacked the wordpress or something and is uploading bunch of pages and hostgator keeps shutting her down..

She's been trying to fix it for a few days and Im not a wordpress guy so im hoping you guys can help.. Hostgator basically said her site is killing all the cpu, and this site is just a simple static website..

From the email i think some fucker either hacked the wordpress or hacked the cpanel, and is now uploading spammy pages..

Can anyone please help.. all the information from the email is below:

Dont mind paying $50 or $100 or w/e for someone to just fix it.


Code:

CPU Seconds used in the past hour: 2527.03, 71% CPU
> Thu Jun 11 23:01:04 CDT 2015
> Running Processes:
> ifeoma 1206 3.8 0.2 472388 179496 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 1416 3.8 0.2 471612 178760 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 1494 3.9 0.2 468796 176060 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 2116 3.9 0.2 467040 173892 ? RN 22:59 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/index.php
> ifeoma 3374 4.0 0.2 460092 167100 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 3456 4.1 0.2 460096 167220 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 3526 4.0 0.2 459580 166572 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 3712 4.0 0.2 461920 169080 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/index.php
> ifeoma 3717 4.2 0.2 459328 166236 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 4228 4.3 0.2 448572 155404 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 4298 4.3 0.2 452156 158920 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 5024 4.5 0.1 420160 127308 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 5150 4.5 0.1 420412 127764 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 6319 5.7 0.1 371512 78656 ? RN 23:00 0:00 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 6965 7.0 0.0 318308 24928 ? RN 23:01 0:00 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 31348 3.4 0.2 416284 189480 ? RN 22:58 0:04 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/post-new.php

Also hostgator put this in the email:

All those links/pages below are all not part of her website.. Im trying to find those pages from cpanel and cant even find them.. Sorry i put her website as hidden so this doesnt come up on google when people search for her foundation

Quote:

> Current Site Requests:
> 104.156.222.211 hidden.net /wp-login.php?checkemail=registered
> 107.158.40.230 hidden.net /wp-admin/
> 107.168.10.92 hidden.net /
> 108.167.182.249 hidden.net /?test-head=1&test-footer=1
> 108.167.182.249 hidden.net /?test-head=1&test-footer=1
> 108.167.182.249 hidden.net /?test-head=1&test-footer=1
> 108.167.182.249 hidden.net /?test-head=1&test-footer=1
> 108.62.187.146 hidden.net /wp-admin/
> 108.62.70.36 hidden.net /wp-admin/
> 113.108.189.63 hidden.net /what-are-the-benefits-of-using-facebook-marketing/
> 113.108.189.63 hidden.net /what-are-the-benefits-of-using-facebook-marketing/'
> 113.181.216.93 hidden.net /medieval-occasions-supper-event-entertaining-for-kids-and-
> 113.181.216.93 hidden.net /medieval-occasions-supper-event-entertaining-for-kids-and-
> 117.169.1.129 hidden.net /wp-admin/
> 117.187.10.140 hidden.net /a-useful-analysis-of-picking-out-critical-details-for-priv
> 140.129.30.46 hidden.net /medieval-occasions-supper-event-entertaining-for-kids-and-
> 154.16.16.247 hidden.net /if-you-dont-femdom-now-youll-hate-yourself-later/
> 154.16.16.247 hidden.net /if-you-dont-femdom-now-youll-hate-yourself-later/
> 155.94.140.34 hidden.net /wp-admin/
> 162.244.15.96 hidden.net /?p=
> 162.244.15.96 hidden.net /develop-an-internet-marketing-strategy-that-really-works/
> 162.244.15.96 hidden.net /internet-marketing-has-never-been-this-simple-to-understan
> 162.244.15.96 hidden.net /internet-marketing-what-it-takes-to-win-is-a-little-educat
> 162.244.15.96 hidden.net /you-can-mount-a-successful-internet-marketing-campaign/
> 176.9.167.166 hidden.net /
> 176.9.167.166 hidden.net /safe-crash-diets-to-lose-weight-quick/%3Eweight
> 176.9.167.166 hidden.net /safe-crash-diets-to-lose-weight-quick/%3Eweight
> 176.9.167.166 hidden.net /safe-crash-diets-to-lose-weight-quick/%3Eweight
> 185.3.132.75 hidden.net /hair-and-make-up-tips-from-nancy/
> 185.75.57.40 hidden.net /want-to-know-more-about-femdom-3/
> 185.75.57.91 hidden.net /
> 187.147.15.245 hidden.net /medieval-occasions-supper-event-entertaining-for-kids-and-
> 188.165.233.212 hidden.net /employ-a-personal-injury-lawyer-and-also-resolve-your-situ
> 188.165.233.212 hidden.net /hunting-for-the-perfect-car-crash-lawyer/
> 188.165.233.212 hidden.net /quick-guide-to-submitting-a-personal-injury-lawsuit-for-co
> 192.151.147.10 hidden.net /rob-laurdurante-stretch-cid-laine-homme-existe-plusieurs-c
> 192.255.69.143 hidden.net /wp-login.php?action=register
> 212.129.27.117 hidden.net /your-new-apple-cheap-gadget-insurance-tablet-learning-to-m
> 212.129.43.119 hidden.net /wp-login.php?checkemail=registered
> 212.83.136.22 hidden.net /wp-admin/
> 212.83.136.22 hidden.net /wp-admin/post.php
> 212.83.144.77 hidden.net /standards-for-plans-for-womens-clothing/
> 212.83.144.77 hidden.net /wp-admin/
> 212.83.144.77 hidden.net /wp-login.php?redirect_to=http%3A%2F%2Fwww.hidden.n
> 212.83.155.63 hidden.net /wonderful-assistance-for-potential-life-insurance-coverage
> 212.83.155.63 hidden.net /wp-admin/
> 212.83.155.63 hidden.net /wp-admin/
> 212.83.155.63 hidden.net /wp-admin/post-new.php
> 212.83.155.63 hidden.net /wp-login.php?action=register
> 212.83.155.63 hidden.net /wp-login.php?checkemail=registered
> 213.184.111.168 hidden.net /hair-and-make-up-tips-from-nancy/
> 216.158.217.150 hidden.net /if-you-dont-femdom-now-youll-hate-yourself-later/
> 216.158.221.159 hidden.net /safe-crash-diets-to-lose-weight-quick/%3Eweight
> 23.232.132.237 hidden.net /wp-admin/
> 23.232.235.133 hidden.net /
> 23.27.241.175 hidden.net /wp-login.php?redirect_to=http%3A%2F%2Fwww.hidden.n
> 23.94.54.216 hidden.net /what-to-expect-from-best-dating/
> 23.94.77.219 hidden.net /wp-admin/
> 23.95.89.111 hidden.net /wp-login.php?checkemail=registered
> 31.220.30.16 hidden.net /standards-for-plans-for-womens-clothing/
> 31.220.30.16 hidden.net /wp-login.php
> 31.220.30.16 hidden.net /wp-login.php?action=register
> 31.220.30.16 hidden.net /wp-login.php?checkemail=registered
> 31.220.30.16 hidden.net /wp-login.php?checkemail=registered
> 31.220.30.16 hidden.net /wp-login.php?redirect_to=http%3A%2F%2Fwww.hidden.n
> 37.203.215.6 hidden.net /wp-admin/
> 45.33.158.202 hidden.net /safe-crash-diets-to-lose-weight-quick/%3Eweight
> 46.102.103.54 hidden.net /wp-admin/?action=register
> 5.153.237.94 hidden.net /wp-login.php
> 5.157.41.41 hidden.net /xerox-workcentre-5632-review/
> 66.249.65.12 hidden.net /random-thoughts-on-the-nsa-and-metadata/
> 66.249.65.4 hidden.net /6-shocking-facts-about-parking-lot-cleaning-business-plan-
> 82.211.57.116 hidden.net /wp-admin/
> 82.211.57.134 hidden.net /wp-login.php?checkemail=registered
> 89.36.66.223 hidden.net /wp-admin/?action=register
Quote:

> Doc Root: /home4/ifeoma/public_html
> Shell: /usr/local/cpanel/bin/jailshell
>
> CPU Usage: 64.1% (warning)
> LimitPHP: Limit file exists. (warning)
>
>
> Snapshot 1
> ifeoma 1206 3.8 0.2 472388 179496 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 1416 3.7 0.2 471612 178760 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 1494 3.8 0.2 468796 176060 ? RN 22:59 0:03 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 2116 3.8 0.2 467040 173892 ? RN 22:59 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/index.php
> ifeoma 3374 4.0 0.2 460092 167100 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 3456 4.0 0.2 460096 167220 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 3526 3.9 0.2 459580 166572 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 3712 4.0 0.2 461920 169080 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/index.php
> ifeoma 3717 4.1 0.2 459328 166236 ? RN 23:00 0:02 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 4228 4.2 0.2 448572 155404 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 4298 4.2 0.2 452156 158920 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 5024 4.3 0.1 420160 127308 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-login.php
> ifeoma 5150 4.3 0.1 420412 127764 ? RN 23:00 0:01 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 6319 5.1 0.1 371512 78656 ? RN 23:00 0:00 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 6965 3.5 0.0 318308 24928 ? RN 23:01 0:00 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/index.php
> ifeoma 31348 3.4 0.2 416284 189480 ? RN 22:58 0:04 /opt/php53/bin/php-cgi /home4/ifeoma/public_html/wp-admin/post-new.php

>

ruff 06-12-2015 01:10 PM

So why isn't Hostgator helping you out?

xxweekxx 06-12-2015 01:10 PM

by the way if someone wants i can just pay you $50 or $100 or whatever and give you the admin login so you can fix it...

Thanks

xxweekxx 06-12-2015 01:10 PM

Quote:

Originally Posted by ruff (Post 20497056)
So why isn't Hostgator helping you out?

They're being bitches.. Told her either she fixes it or they keep her site still shut down..

ruff 06-12-2015 01:15 PM

Quote:

Originally Posted by xxweekxx (Post 20497058)
They're being bitches.. Told her either she fixes it or they keep her site still shut down..

I have an account at Hostgator and have not run into a problem with tech support. Sounds odd.
If you have admin priviledges, you might want to change passwords in cpanel and wordpress ASAP before you do anything else.

Va2k 06-12-2015 01:16 PM

Quote:

Originally Posted by xxweekxx (Post 20497058)
They're being bitches.. Told her either she fixes it or they keep her site still shut down..

Damn wish I saw this earlier, I am leaving now for the day!! Look if this isn't fixed tomorrow morning hit me up. You can keep your money and I will fix this for you free. If worse comes to worse I can move you and your mom over to one of our shared servers.

Sad when this happens.

TOM

xxweekxx 06-12-2015 01:20 PM

Quote:

Originally Posted by Va2k (Post 20497063)
Damn wish I saw this earlier, I am leaving now for the day!! Look if this isn't fixed tomorrow morning hit me up. You can keep your money and I will fix this for you free. If worse comes to worse I can move you and your mom over to one of our shared servers.

Sad when this happens.

TOM

Yeah at this point if some other host wants to move her completely and can solve this problem I dont mind paying for a new host.... Im getting frustrated and feel bad for her..

xxweekxx 06-12-2015 01:21 PM

Quote:

Originally Posted by ruff (Post 20497062)
I have an account at Hostgator and have not run into a problem with tech support. Sounds odd.
If you have admin priviledges, you might want to change passwords in cpanel and wordpress ASAP before you do anything else.

I do have cpanel login but they disabled the site so im not sure how to get into wordpress and change the password... I can still get into cpanel OK...

They put a button to re-enable the site, but said if i do and it kills the cpu again they will close it permanently . so obviously im scared to re-enable it.. Want someone to fix it first..

HomerSimpson 06-12-2015 01:57 PM

Contact me if you want that fixed...

celebempire{at}gmail.com or check my sig...

DVTimes 06-12-2015 02:23 PM

Make a backup of the database and files just in case.

I am with webair.com and I find they fix things. You may want to consider moving the site to them. I bet they will copy the files and stuff for you too.

xxweekxx 06-12-2015 02:58 PM

Its being fixed now.. Thanks a lot guys :)

Va2k 06-13-2015 06:43 AM

Quote:

Originally Posted by xxweekxx (Post 20497129)
Its being fixed now.. Thanks a lot guys :)

Hey sorry I had to leave yesterday. Should of said go a head and sign up for a new server. I had another Apt that I couldn't miss! :( Glad to see someone is helping you. Hope you aren't having to pay a lot.
TOM

Vendzilla 06-13-2015 07:48 AM

Quote:

Originally Posted by ruff (Post 20497062)
I have an account at Hostgator and have not run into a problem with tech support. Sounds odd.
If you have admin priviledges, you might want to change passwords in cpanel and wordpress ASAP before you do anything else.

And your MySql database passwords as well

Sly 06-13-2015 08:18 AM

Your mom is most likely not updating WordPress or any plug-ins that she may have installed. Those are massive security issues, as you can see. Unless there is someone available to update WordPress and plug-ins on a regular basis, WordPress is really not the greatest idea for a site, especially not for the tech unsavvy that don't even know what WordPress is.

I suggest you put someone on retainer to check in once a month and make sure everything is up to date. You're only going to see this problem happen again and again. And it is not the web hosting companies fault or responsibility to keep your scripts up to date.

ErectMedia 06-13-2015 09:46 AM

Quote:

Originally Posted by Sly (Post 20497516)
Your mom is most likely not updating WordPress or any plug-ins that she may have installed. Those are massive security issues, as you can see. Unless there is someone available to update WordPress and plug-ins on a regular basis, WordPress is really not the greatest idea for a site, especially not for the tech unsavvy that don't even know what WordPress is.

I suggest you put someone on retainer to check in once a month and make sure everything is up to date. You're only going to see this problem happen again and again. And it is not the web hosting companies fault or responsibility to keep your scripts up to date.

Ditto, wordpress makes it easy to publish but if ya don't keep wordpress/plugins updated bound to happen as since it's a very popular CMS shitheads look for outdated holes in it. :2 cents:

Paz 06-13-2015 12:05 PM

Also ask your tech person to install this plugin;
https://wordpress.org/plugins/better-wp-security/

It changes the default user name, login URL and looks for suspicious query strings in URLs etc.

Most people don't need all this but whoever hacked your mom's blog most likely left a backdoor they can use to get back in later.

Let me know by PM if you decide to go ahead and need any help.

Cheers,
Paz.

plaster 06-13-2015 12:34 PM

I'm a little confused why your CPU usage would go so high. A hacker, hacking files and uploading rogue files, fine. Usually they just put a file deep in the folder structure and it is some type of malware.

High CPU usage may want to check the database that stores all the comments. You likely have approve comments manually set, so spammers will just keep leaving comments which all get saved in a database. When this database gets too big, it will bring the entire server to a screeching halt because every comment left by spammer actually calls the entire database each time.

Fix is to delete every single comment out, stop any ability for anyone to leave a comment.

ruff 06-13-2015 03:19 PM

I have a lot of Wordpress sites and they get hit every single day with bots trying to log in. The bots come from IP addresses all over the entire world. There must be a shitload of compromised slaved computers out there just trying to break into whatever they can find. I use a plugin called WordFence, Paz suggested another one as well. At a minimum, install one of these and make up some difficult passwords.

Darkcrni 06-14-2015 10:26 AM

Is there anyway you can enter your wp-admin and isntall

Anti-Malware
Wordfence
WPSecurity

Darkcrni 06-14-2015 10:31 AM

Also you need to block logging attempts to 1-2 per ip-user, after that they will get locked.

If it's possible change all passwords on Wp and C-panel as well.

DBS.US 06-14-2015 12:26 PM

Why do you use the word "faggot" ? Do you have a little secret you would like to share with the group?

dirtymind 06-15-2015 03:55 AM

If you mom would be willing to move her site, we have free hosting program for foundation sites.

you can mail me at [email protected] or icq 603686929

Cpanel has a build in scanner you can use to see if any pages got infected. Other options are by access the server through ssh.


All times are GMT -7. The time now is 02:56 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc