EH-Net
May 26, 2013, 01:44:40 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
General Certification
(Moderator:
don
) >
from hacking
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: from hacking (Read 2063 times)
0 Members and 1 Guest are viewing this topic.
grady07
Newbie
Offline
Posts: 1
from hacking
«
on:
August 03, 2012, 11:38:57 AM »
My website
http://weddingsvermont.com
was attacked yesterday morning and i have cleaned everythign off the FTP and reinstalled fresh copy of mybackup however they have done it again. is therea way of blocking ?
they leave few files in the website which is base64 decoded. also a txt file 150be24c26f4aa277a96fd68c91f3b48AuthCode: 306426
Logged
ziggy_567
Sr. Member
Offline
Posts: 361
Re: from hacking
«
Reply #1 on:
August 03, 2012, 11:57:05 AM »
You're running a Wordpress blog. Wordpress plugins are fairly commonly found to have vulnerabilities that could allow an attacker to gain unauthorized access.
Instead of deleting and restoring from backup, you need to find the way they're coming in and fix that. It would be like demolishing your house after someone stole the keys but leaving the locks the same when you rebuild.
You're best bet at finding how they got in is to look through your webserver logs. Any entries that look "odd" should be investigated. (usually Google is your friend for this)
If you have any specific questions about log entries, feel free to post them here.
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
fred
Sr. Member
Offline
Posts: 351
The World is sick, Save your mind...
Re: from hacking
«
Reply #2 on:
August 03, 2012, 01:30:02 PM »
i agree with ziggy wordpress has some bugs u must find and patch them and it was better to show us a port scanning result of ur website i thing maybe the ftp server program has some vulnerabilities too .
Logged
ICS Academy Network Security Certified
shadowzero
Full Member
Offline
Posts: 120
It's a UNIX system, I know this!
Re: from hacking
«
Reply #3 on:
August 03, 2012, 02:34:30 PM »
If the problem is with WordPress, you should probably upgrade it, and all the plugins to the latest release. Make sure you have strong passwords as well. Depending on the what was vulnerable, your entire system could be compromised and you may need to format and reinstall to wipe out any backdoors. Some WordPress vulnerabilities allow attackers to execute remote code on your server which eventually leads to remote access.
Logged
3xban
Hero Member
Offline
Posts: 608
Re: from hacking
«
Reply #4 on:
August 04, 2012, 07:02:38 AM »
Yep, upgrade WordPress and pay extra attention to the plugins. I've heard people go ahead and upgrade WP only to be compromised again through a plugin they didn't upgrade. Good luck!
Logged
Certs: GCWN
(@)Dewser
Jamie.R
Sr. Member
Offline
Posts: 429
Re: from hacking
«
Reply #5 on:
August 06, 2012, 10:48:43 AM »
Have you tried WP-scan that may put some light on any plugin that are outdated or have issue. There are also lots blogs that give some tips on secuing wordpress.
Logged
OSWP | Hackingdojo Nidan | eCPPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...