Error logs;
[Wed May 04 00:12:43 2011] [error] [client 82.6.164.219] File does not exist: /home/logicalx/public_html/wordpress/wp-content/plugins/simple-ajax-shoutbox, referer: http://logicalx.org/wordpress/?p=261
Goes on for 15 mins, traced the ip to a virgin media client in glasgow. (removed shoutbox plugin case of any SQL Injection scripts, also removed any other plugs that i thought might cause an issue)
After talking to my Hosting Company they said this;
Luke Williams 22:21:36
Hey, your account is causing issues on server
| 71 | exetersw_ecsc | localhost | exetersw_ecsc | Query | 0 | Opening tables | SELECT data, created, headers, expire, serialized FROM cache WHERE cid = 'theme_registry:acquia_mari |
| 94 | exetersw_ecsc | localhost | exetersw_ecsc | Query | 0 | Opening tables | SELECT data, created, headers, expire, serialized FROM cache WHERE cid = 'theme_registry:acquia_mari |
| 123 | exetersw_ecsc | localhost | exetersw_ecsc | Query | 0 | Opening tables | SELECT data, created, headers, expire, serialized FROM cache WHERE cid = 'theme_registry:acquia_mari |
| 159 | exetersw_ecsc | localhost | exetersw_ecsc | Query | 0 | Opening tables | SELECT data, created, headers, expire, serialized FROM cache WHERE cid = 'theme_registry:acquia_mari |
| 171 | exetersw_ecsc | localhost | exetersw_ecsc | Query | 0 | Opening tables | SELECT data, created, headers, expire, serialized FROM cache WHERE cid = 'theme_registry:acquia_mari |
root@lexus [/tmp]# mysqladmin pr | grep logicalx_wordpress
| 285 | logicalx_user1 | localhost | logicalx_wordpress | Query | 4 | Opening tables | SELECT wp_posts.* FROM wp_posts WHERE 1=1 AND wp_posts.post_type = 'post' AND (wp_posts.post_sta |
| 293 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 38 | | |
| 303 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 53 | | |
| 307 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 4 | | |
| 371 | logicalx_user1 | localhost | logicalx_wordpress | Query | 4 | closing tables | show tables |
| 372 | logicalx_user1 | localhost | logicalx_wordpress | Query | 4 | closing tables | show tables |
| 375 | logicalx_user1 | localhost | logicalx_wordpress | Query | 6 | Opening tables | SELECT option_value FROM wp_options WHERE option_name = 'aiosp_post_title_format' LIMIT 1 |
| 377 | logicalx_user1 | localhost | logicalx_wordpress | Query | 4 | closing tables | show tables |
| 389 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 4 | | |
| 390 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 4 | | |
| 391 | logicalx_user1 | localhost | logicalx_wordpress | Sleep | 4 | | |
| 394 | logicalx_user1 | localhost | logicalx_wordpress | Query | 0 | Opening tables | SELECT option_name, option_value FROM wp_options WHERE autoload = 'yes' |
root@lexus [/tmp]# w
22:20:44 up 41 days, 10:03, 2 users, load average: 17.84, 14.36, 10.46
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
root pts/0 213.229.66.119 22:02 0.00s 0.07s 0.07s -bash
root pts/2 213.229.66.119 22:04 1:36 2.92s 0.03s -bash
Dont think there's any private info there but now im worried as they said if this continues they will suspend my account.
Any suggestions people :(, worried i might be getting hacked.
Thanks, Logi.