GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Wordpress stealth hack (https://gfy.com/showthread.php?t=967671)

Brujah 05-10-2010 12:54 AM

Wordpress stealth hack
 
Wordpress sites are being hacked by the hundreds, and you may not even realize that yours is too if you host on any number of shared servers (Network Solutions, Dreamhost, GoDaddy, etc...).

http://www.wpsecuritylock.com/breaki...-on-dreamhost/

halfpint 05-10-2010 01:15 AM

Thanks man bump for more awareness

SGS 05-10-2010 01:36 AM

Wordpress = fucking nightmare.

CunningStunt 05-10-2010 01:42 AM

Where there's a will, there's a way.

Any mass software solution is going to be hit sooner or later. Stinks, but it's inevitable.

Thanks Brujah. Now I remember why I let a 100 domain experiment die on its ass.

fris 05-10-2010 04:32 AM

thats what you get for hosting on a shitty web host, serves them right

seeandsee 05-10-2010 04:58 AM

Quote:

Originally Posted by Brujah (Post 17124835)
Wordpress sites are being hacked by the hundreds, and you may not even realize that yours is too if you host on any number of shared servers (Network Solutions, Dreamhost, GoDaddy, etc...).

http://www.wpsecuritylock.com/breaki...-on-dreamhost/

:thumbsup thanks for notice

LoveSandra 05-10-2010 05:09 AM

Quote:

Originally Posted by SGS (Post 17124875)
Wordpress = fucking nightmare.

sometimes , yes:2 cents:

CPimp 05-10-2010 06:37 AM

That friggin sucks.

MrBottomTooth 05-10-2010 06:41 AM

This seems like a hosting issue, not wordpress.

Any php site on these affected shared hosts are vulnerable. There are people with phpld, joomla sites, even custom php sites that are getting hit. Only thing they have in common is that they used one of the above-mentioned shared hosts.

bloggerz 05-10-2010 06:41 AM

its only on shared hosting? so blogs on dedicated servers aren't being affected?

MrBottomTooth 05-10-2010 06:50 AM

Quote:

Originally Posted by bloggerz (Post 17125288)
its only on shared hosting? so blogs on dedicated servers aren't being affected?

Yes, that's what I have read, only certain shared hosts are being hit right now.

V_RocKs 05-10-2010 08:12 AM

Wonder if it is the same shitheads that did the big attack last time.

ottopottomouse 05-10-2010 10:47 AM

Thanks for that. Can't find any with a problem :)

Why 05-10-2010 10:56 AM

has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge :)

MrBottomTooth 05-10-2010 11:54 AM

Quote:

Originally Posted by Why (Post 17126020)
has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge :)

Dreamhost, network solutions, godaddy are all being hit, all kinds of php sites. Not exclusive to wordpress at all.

TheDA 05-10-2010 11:58 AM

Quote:

Originally Posted by Why (Post 17126020)
has anyone found one of these websites or is it just dreamhost bashing?

considering the source is a person who makes money selling WordPress security software and knowledge :)

I wondered the same to be honest. I haven't seen a site listed that's been hit yet.

TheDA 05-10-2010 11:59 AM

Quote:

Originally Posted by MrBottomTooth (Post 17126192)
Dreamhost, network solutions, godaddy are all being hit, all kinds of php sites. Not exclusive to wordpress at all.

Do you know of any that have been hit by any chance?

Brujah 05-10-2010 12:31 PM

On wordpress.org forums there's a list of people who claim their sites were hacked.
http://wordpress.org/support/topic/396524?replies=1

Add BlueHost to the list of shared hosts. Also, this doesn't seem to be exclusive to wordpress, but sometimes other .php files on the servers.

Dirty Lord 05-10-2010 12:38 PM

Quote:

Originally Posted by SGS (Post 17124875)
Wordpress = fucking nightmare.

dont say that:Oh crap

icymelon 05-10-2010 12:41 PM

cant you set wordpress to only let your ip login?

harvey 05-10-2010 12:48 PM

the attacks are on Apache, not WordPress, that's why it only works on shared hosting. They attacked WP, ZenCart, Drupal and almost any PHP file at sight. Thing is WP has millions of users, hence you'll see "WP is under attack". Or do you expect to see "some custom php script is under attack"? geez, some people :Oh crap

Quite curiously, you'll rarely see "some idiots at shared hosting have no clue about what they're doing", and in 99% of cases that is the issue.

harvey 05-10-2010 12:50 PM

Quote:

Originally Posted by icymelon (Post 17126340)
cant you set wordpress to only let your ip login?

yes you can with some easy custom mod. However, the attacks were from inside the server, so how do you stop that? Last time, when the NetSol fiasco shown up (1 month ago or so) it was proven they had a rogue admin that changed permissions to allow access to account. Same with GoDaddy hosting. How do you plan to stop that?

Davy 05-10-2010 01:18 PM

I have no problems with my php sites on Dreamhost.

Argos88 05-10-2010 02:57 PM

This is a sever config problem.. NOT Wordpress....

TheDA 05-10-2010 03:14 PM

I checked all my WP stuff on shared earlier and it was OK!


All times are GMT -7. The time now is 06:07 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123