Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 30 guests and 3 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow General Certificationarrow from hacking
EH-Net
May 24, 2013, 01:12:46 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: from hacking  (Read 2056 times)
0 Members and 1 Guest are viewing this topic.
grady07
Newbie
*
Offline Offline

Posts: 1


View Profile WWW
« on: August 03, 2012, 11:38:57 AM »


My website http://weddingsvermont.com  was attacked yesterday morning and i have cleaned everythign off the FTP and reinstalled fresh copy of mybackup however they have done it again. is therea way of blocking ? Undecided
they leave few files in the website which is base64 decoded. also a txt file 150be24c26f4aa277a96fd68c91f3b48AuthCode: 306426
Logged
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #1 on: August 03, 2012, 11:57:05 AM »

You're running a Wordpress blog. Wordpress plugins are fairly commonly found to have vulnerabilities that could allow an attacker to gain unauthorized access.

Instead of deleting and restoring from backup, you need to find the way they're coming in and fix that. It would be like demolishing your house after someone stole the keys but leaving the locks the same when you rebuild.

You're best bet at finding how they got in is to look through your webserver logs. Any entries that look "odd" should be investigated. (usually Google is your friend for this)

If you have any specific questions about log entries, feel free to post them here.
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #2 on: August 03, 2012, 01:30:02 PM »

i agree with ziggy wordpress has some bugs u must find and patch them and it was better to show us a port scanning result of ur website i thing maybe the ftp server program has some vulnerabilities too .
Logged

ICS Academy Network Security Certified
shadowzero
Full Member
***
Offline Offline

Posts: 120


It's a UNIX system, I know this!


View Profile
« Reply #3 on: August 03, 2012, 02:34:30 PM »

If the problem is with WordPress, you should probably upgrade it, and all the plugins to the latest release. Make sure you have strong passwords as well. Depending on the what was vulnerable, your entire system could be compromised and you may need to format and reinstall to wipe out any backdoors. Some WordPress vulnerabilities allow attackers to execute remote code on your server which eventually leads to remote access.

Logged
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #4 on: August 04, 2012, 07:02:38 AM »

Yep, upgrade WordPress and pay extra attention to the plugins.  I've heard people go ahead and upgrade WP only to be compromised again through a plugin they didn't upgrade.  Good luck!
Logged

Certs: GCWN
(@)Dewser
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #5 on: August 06, 2012, 10:48:43 AM »

Have you tried WP-scan that may put some light on any plugin that are outdated or have issue. There are also lots blogs that give some tips on secuing wordpress.
Logged

OSWP | Hackingdojo Nidan | eCPPT
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.081 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.