Forums

[resolved] possible hack; need help upgrading (11 posts)

  1. zwave
    Member
    Posted 1 month ago #

    Hi,

    First of all - i use version 2.3.3. I know, i should have upgraded million years ago, i'm a bad person and i should be ashamed.
    Beside that, after i read this article that talks about a warm that registers a user, than makes itself an admin - I checked my blog and saw that on "write post" tab, on the "post author" dropdown, that a user called KentWeiss72 was available, besides me. This was odd and I checked the "users" tab to see if I can delete it from there but i couldn't find it. So I assumed that I got hacked, just the way the article said.

    now my question is: what can I do to clean my site ?
    I have a main site that acts as an online shop and a wordpress blog associated with it. I don't know if the hacker messed up with my online shop or only with the blog.. i don't really know what's the extent of the damage because I don't know what to check... I'm kinda' lost even if I'm "administrator". Usually, I go by intuition, more than solid knowledge. Let me tell you what I've done so far:

    1. I opened phpmyadmin from cpanel and deleted suspect users, including KentWeiss72 which had admin rights from the database : wp_users and wp_usermeta tables
    2. i started updating to 2.8.4. I followed the steps from this article and got to step 7.
    I stopped to ask somebody on these forums if I'm doing it right.

    Thank you !
    p.s. i remember a few months ago I had a problem with some alien code that got into all my index files and contained an <iframe> which made I don't know what, but avira restricted access to my site. Back then I deleted the foreign code from all index files and it worked, but I didn't knew what else to check..

  2. zwave
    Member
    Posted 1 month ago #

    and it's not warm it's worm sorry! :d maybe a warm worm :)

  3. jonimueller
    Member
    Posted 1 month ago #

    That's just the procedure for upgrading WordPress. You have to proceed a bit differently if you've been hacked, especially with that latest added admin user hack. You'll need to clean your database. Read about that here:
    http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/

  4. zwave
    Member
    Posted 1 month ago #

    my .htaccess file looks like this:

    # BEGIN WordPress

    # END WordPress

    is it normal ?

  5. zwave
    Member
    Posted 1 month ago #

    after i studied several articles, i decided to go through with steps from here , as they seem more just..

  6. zwave
    Member
    Posted 1 month ago #

    if i delete .htaccess, it will create itself ?

  7. iridiax
    Member
    Posted 1 month ago #

    if i delete .htaccess, it will create itself ?

    Yes, it should when you set your pretty permalinks, but if it doesn't, see: http://codex.wordpress.org/Using_Permalinks#Creating_and_editing_.28.htaccess.29

  8. zwave
    Member
    Posted 1 month ago #

    and how exactly will you set the pretty permalinks ? sorry but i'm to tired to read through the hole article. i already staid up all night learning about this update and being careful not to mess something up ..

  9. zwave
    Member
    Posted 1 month ago #

    i uploaded new version and database. I deleted everything, then modified wp-config.php introducing the 4 keys and copied uploads folder into wp-content. I also deleted the .htaccess file but that one wasn't present in the new files of 2.8.4 version

    now i have one more question and i hit the sack !
    if i don't set my pretty permalinks, do i need .htaccess ? if yes, can i use the old one - which as i stated above has only 2 lines.. or make a new one ? ... please respond so i can finally sleep..

  10. iridiax
    Member
    Posted 1 month ago #

    if i don't set my pretty permalinks, do i need .htaccess ?

    No, you don't need one then.

  11. zwave
    Member
    Posted 1 month ago #

    thanks

Reply

You must log in to post.

About this Topic