Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Developer)
  3. Hacked

Hacked

Scheduled Pinned Locked Moved WordPress (Developer)
18 Posts 9 Posters 2.3k Views 8 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      J Offline
      jquintana
      wrote on last edited by
      #1

      Hi

      1 - i did a migration with AIOWP Migration
      2 - i have a backdoor, for example they edit index.php
      /7b1a5/

      @include ("/app/data/public/wp-includes/assets/.1d254507.mo");

      /7b1a5/
      3 - they can create folders and edit certain files like index.php or settings or config

      i dont know what to do, support derives me here
      every 4 / 7 days im hacked.......

      Thank you very much

      the site is hotelmardeplata.com

      marcusquinnM 1 Reply Last reply
      0
      • J jquintana

        Hi

        1 - i did a migration with AIOWP Migration
        2 - i have a backdoor, for example they edit index.php
        /7b1a5/

        @include ("/app/data/public/wp-includes/assets/.1d254507.mo");

        /7b1a5/
        3 - they can create folders and edit certain files like index.php or settings or config

        i dont know what to do, support derives me here
        every 4 / 7 days im hacked.......

        Thank you very much

        the site is hotelmardeplata.com

        marcusquinnM Offline
        marcusquinnM Offline
        marcusquinn
        wrote on last edited by
        #2

        @jquintana Try this plugin to scan all files for vulnerabilities:

        • https://wordpress.org/plugins/gotmls/

        Also worth a look, if you don't have already:

        • https://wordpress.org/plugins/really-simple-ssl/
        • https://wordpress.org/plugins/hide-my-wp/
        • https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/

        Web Design https://www.evergreen.je
        Development https://brandlight.org
        Life https://marcusquinn.com

        1 Reply Last reply
        1
        • J Offline
          J Offline
          jquintana
          wrote on last edited by
          #3

          @marcusquinn i already have it....., gotmls/
          wordfence....,
          etc.....,

          but i want get the roots of this problem........, it's only this site

          1 Reply Last reply
          0
          • BrutalBirdieB Offline
            BrutalBirdieB Offline
            BrutalBirdie
            Partner
            wrote on last edited by
            #4

            Sorry to be a bit harsh but, do I understand it correctly that you have a compromised Wordpress which gets compromised over and over again and yet you still keep it running?

            If it gets breached multiple times what have you done to prevent this?
            Did you pay someone to have a look and secure it?

            Like my work? Consider donating a drink. Cheers!

            1 Reply Last reply
            1
            • marcusquinnM Offline
              marcusquinnM Offline
              marcusquinn
              wrote on last edited by
              #5

              We'll all be guessing here, but if you already knew of and used the mentioned plugins, and nothing is obvious, the other main thing I would do is change the passwords for all Administrator users, that would be my next guess.

              Web Design https://www.evergreen.je
              Development https://brandlight.org
              Life https://marcusquinn.com

              1 Reply Last reply
              1
              • timconsidineT Offline
                timconsidineT Offline
                timconsidine
                App Dev
                wrote on last edited by
                #6

                I'm not a wordpress expert at all.
                But given that the site design and content is not that complex, my instinct would be to create a new Wordpress app in Cloudron on a dummy sub-domain and recreate the site from scratch (i.e. do not import it) with the security plugins and new passwords. Then delete the old one once you are happy, and change the sub-domain of the new site back to the original one.

                1 Reply Last reply
                1
                • girishG Offline
                  girishG Offline
                  girish
                  Staff
                  wrote on last edited by
                  #7

                  @jquintana I recommend setting up a fresh installation on the side and importing the "content" from your existing site. Is this possible in your situation ?

                  1 Reply Last reply
                  1
                  • P Offline
                    P Offline
                    p44
                    translator
                    wrote on last edited by
                    #8

                    Hi @jquintana, you tried Wordfence, the free version or the premium one? What they did, what they replied? I think you should provide more detailed report to have a discussion based on facts...

                    1 Reply Last reply
                    0
                    • martinkbsM Offline
                      martinkbsM Offline
                      martinkbs
                      wrote on last edited by
                      #9

                      Hi @jquintana

                      Do all plugins and themes come from "trusted" developers or sites?

                      • Remove and reinstall all plugins and themes from the installation (including all inactive ones).
                      • Remove all files that have been added and do not belong to the original development.
                      • Check the DB to rule out any SQL injection of malicious code that will cause it to re-hack the site.
                      • Change all admin user passwords.
                      • Disable login by username and force login by email and password only.

                      With that, the installation should be secured.

                      1 Reply Last reply
                      0
                      • J Offline
                        J Offline
                        jquintana
                        wrote on last edited by jquintana
                        #10

                        Hi @martinkbs

                        9 may 00:27mins
                        index.php
                        /7b1a5/

                        @include ("/app/data/public/wp-includes/blocks/post-featured-image/.8ae050b9.mo");

                        /7b1a5/

                        wp-config
                        /1ce2a/

                        @include ("/app/data/public/wp-includes/blocks/post-featured-image/.8ae050b9.mo");

                        /1ce2a/

                        Do all plugins and themes come from "trusted" developers or sites? Yes, the problem here can be the 1st step: cloning site from AIOWPM, here possibly there are altered permission files and folders.....?....
                        Remove and reinstall all plugins and themes from the installation (including all inactive ones). Done....
                        Remove all files that have been added and do not belong to the original development. Done....
                        Check the DB to rule out any SQL injection of malicious code that will cause it to re-hack the site. How?
                        Change all admin user passwords. Done
                        Disable login by username and force login by email and password only. How?

                        timconsidineT 1 Reply Last reply
                        0
                        • J jquintana

                          Hi @martinkbs

                          9 may 00:27mins
                          index.php
                          /7b1a5/

                          @include ("/app/data/public/wp-includes/blocks/post-featured-image/.8ae050b9.mo");

                          /7b1a5/

                          wp-config
                          /1ce2a/

                          @include ("/app/data/public/wp-includes/blocks/post-featured-image/.8ae050b9.mo");

                          /1ce2a/

                          Do all plugins and themes come from "trusted" developers or sites? Yes, the problem here can be the 1st step: cloning site from AIOWPM, here possibly there are altered permission files and folders.....?....
                          Remove and reinstall all plugins and themes from the installation (including all inactive ones). Done....
                          Remove all files that have been added and do not belong to the original development. Done....
                          Check the DB to rule out any SQL injection of malicious code that will cause it to re-hack the site. How?
                          Change all admin user passwords. Done
                          Disable login by username and force login by email and password only. How?

                          timconsidineT Offline
                          timconsidineT Offline
                          timconsidine
                          App Dev
                          wrote on last edited by
                          #11

                          @jquintana said in Hacked:

                          the problem here can be the 1st step: cloning site from AIOWPM

                          absolutely : in this scenario, don't clone or import.
                          start with fresh clean WP site, add plugins, then manually create new pages and copy/paste content from old pages to new pages
                          if the site has some low-level deep infection, "burn it" and start again clean, with all the other recommended protections.
                          Well, that's what I would do

                          ei8fdbE 1 Reply Last reply
                          2
                          • timconsidineT timconsidine

                            @jquintana said in Hacked:

                            the problem here can be the 1st step: cloning site from AIOWPM

                            absolutely : in this scenario, don't clone or import.
                            start with fresh clean WP site, add plugins, then manually create new pages and copy/paste content from old pages to new pages
                            if the site has some low-level deep infection, "burn it" and start again clean, with all the other recommended protections.
                            Well, that's what I would do

                            ei8fdbE Offline
                            ei8fdbE Offline
                            ei8fdb
                            wrote on last edited by
                            #12

                            @timconsidine said in Hacked:

                            absolutely : in this scenario, don't clone or import.

                            This is the most pragmatic solution.

                            Any other will require you to expend much more time and energy to answer why you keep getting hacked.

                            You can understand why it keeps getting hacked by examining the original hacked files offline.

                            1 Reply Last reply
                            1
                            • marcusquinnM Offline
                              marcusquinnM Offline
                              marcusquinn
                              wrote on last edited by
                              #13

                              You could migrate to one of the Wordpress specialist hosts, like Siteground, Cloudways, etc. Then use their large pool of Wordpress experts to diagnose and fix, which is usually part of their service, then if you want to host with Cloudron still, and self-support with some community ideas here, migrate back again once you're confident it's locked-down again.

                              Web Design https://www.evergreen.je
                              Development https://brandlight.org
                              Life https://marcusquinn.com

                              1 Reply Last reply
                              1
                              • J Offline
                                J Offline
                                jquintana
                                wrote on last edited by
                                #14

                                yes, but that is precisely what I want to avoid....,
                                I want to find the solution, not only to learn how to close open doors, but also because of time and pride....,

                                I am checking the database, as the problem is very likely to come from there,

                                Can you think of anything else?

                                because it seems strange to me that there is no powerful software to analyse back doors.

                                marcusquinnM 1 Reply Last reply
                                0
                                • J jquintana

                                  yes, but that is precisely what I want to avoid....,
                                  I want to find the solution, not only to learn how to close open doors, but also because of time and pride....,

                                  I am checking the database, as the problem is very likely to come from there,

                                  Can you think of anything else?

                                  because it seems strange to me that there is no powerful software to analyse back doors.

                                  marcusquinnM Offline
                                  marcusquinnM Offline
                                  marcusquinn
                                  wrote on last edited by
                                  #15

                                  @jquintana If "no powerful software to analyse back doors" is finding anything in the most well-known platform on the planet, with the most understanding of vulnerabilities, maaayyyybbeee it is compromised credentials? No software could detect that. You certain you eliminated that possibility completely?

                                  Web Design https://www.evergreen.je
                                  Development https://brandlight.org
                                  Life https://marcusquinn.com

                                  1 Reply Last reply
                                  0
                                  • J Offline
                                    J Offline
                                    jquintana
                                    wrote on last edited by
                                    #16

                                    really, no

                                    marcusquinnM 1 Reply Last reply
                                    1
                                    • J jquintana

                                      really, no

                                      marcusquinnM Offline
                                      marcusquinnM Offline
                                      marcusquinn
                                      wrote on last edited by marcusquinn
                                      #17

                                      @jquintana In your Cloudron panel, you could try changing the permissions for the files that keep getting edited so they can't be updated, then just change them back temporarily if ever you did want to edit them.

                                      Another quick look at your website, and as nice as I'm sure it was when built, I think you could very quickly build a new version in perhaps a week. I highly recommend the KadenceWP theme, and the above plugins.

                                      Cloudron is rock-solid for us for many years now, and no security issues, so I'm confident you'll be happy with a clean install, modern flexible theme and those light and tight plugins mentions.

                                      That or you might be looking at Upwork of Fiverr for an expert to do an audit, which will be as unpredictable on cost as the guesses we've been able to make here so-far.

                                      Web Design https://www.evergreen.je
                                      Development https://brandlight.org
                                      Life https://marcusquinn.com

                                      1 Reply Last reply
                                      0
                                      • RazielKanosR Offline
                                        RazielKanosR Offline
                                        RazielKanos
                                        wrote on last edited by
                                        #18

                                        check out in the options table. I once had a hacked plugin that was writing executable code in the options table, and by that, it was able to reinstall itself again and again.

                                        Well securing the page should be a matter of less than an hour. Just export those pages, make a fresh install and import the pages back in 🙂

                                        1 Reply Last reply
                                        0
                                        Reply
                                        • Reply as topic
                                        Log in to reply
                                        • Oldest to Newest
                                        • Newest to Oldest
                                        • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search