NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Business & Community Discussion Forums > Community > Warnings & Alerts
Reload this Page Wordpress Sites Compromised?

Warnings & Alerts Report and discuss scams, stolen domains, and bad people or companies to deal with.

Advanced Search
9 members in live chat ~  


Reply
 
LinkBack Thread Tools
Old 05-19-2011, 12:47 PM THREAD STARTER               #1 (permalink)
NamePros Expert
 
RogueWriter's Avatar
Join Date: Jan 2005
Location: Smalltown USA
Posts: 5,036
RogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond reputeRogueWriter has a reputation beyond repute
 



Wordpress Sites Compromised?


I was reading a post from ipower.com's facebook page, thought it might be of interest:

- - - - - - - - - -
To all customers whose Wordpress site has recently been compromised:



Through our research we have found that we were one of many hosting solutions whose customer's Wordpress sites may have been compromised. That research shows that someone is using a script or application that allows them to read your wp-config.php file and compromise the database with the information from that file. This allows them to inject information into your Wordpress database including, but not limited to, links to malware sites and other malicious scripts.



There are several options that would allow you and the other compromised sites to protect yourself. One would be to write some additional code into the .htaccess file protecting the wp-config.php file. (Advanced users only.) Another would be to change the wp-config.php file's permissions to something like 640 as a protection measure. (Advanced users only.)



The best solution we can recommend, however, would be to add a firewall plugin to your Wordpress. The one recommended to us it the WordPress Firewall 2 plugin available at http://wordpress.org/extend/plugins/...ss-firewall-2/. This should block that application from seeing your configuration. We've tested it on a few sites our agent use and it has not had any ill-effect on their site's visibility or accessibility.



If you still have the malicious links on your site at this time, please submit a ticket in the Support area of your Control Panel. Please use the Subject line: "Compromised Wordpress Installation" to allow us to identify and address these tickets as quickly as possible.



Additionally, it is our recommendation that you update your Control Panel and FTP passwords to new, different, and secure passwords. You should also update both the database user and the password connected to that user to something new, different, and secure.
????: NamePros.com http://www.namepros.com/warnings-and-alerts/715475-wordpress-sites-compromised.html



If you have any additional questions or concerns, please leave a comment here, contact our support at (888) 511-4678, or submit a ticket through the Support area of your Control Panel.



Thank you,

IPower

- - - - - - - - - -
__________________
"I'm so mean I make MEDICINE sick." -Muhammad Ali
RogueWriter is offline   Reply With Quote
Old 05-19-2011, 12:56 PM   #2 (permalink)
TelShowcase.com
 
steveteva's Avatar
Join Date: Nov 2004
Location: hawaii
Posts: 1,323
steveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud ofsteveteva has much to be proud of
 


Protect Our Planet
great post I'm not hosted there but worth having firewall plugin in case of.
steveteva is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
www.ImageHut.org + Sister Sites!!! Flubber ccTLD Domains For Sale 0 06-12-2005 06:34 AM
[Turnkey]Super Sites (Some with PR) + 50% donating to Tsunami Relief Effort lfhost Turnkey Websites For Sale 11 01-24-2005 07:46 AM
Link exchange offer – 5 sites. Netsah For Sale / Advertising Board 0 09-05-2004 04:52 AM

 
All times are GMT -7. The time now is 07:06 PM.

Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger