• Resolved lamadame

    (@lamadame)


    hello everybody

    Since 2 weeks ago, something very unusual happened to my 2 WP accounts, and I need to explain this in order to get to know if anyother person has been passing the same, or maybe it’s something new on WP…

    I used to have my “usernames” as “admin”… but suddenly on the login page they now appear as sec-w.com do you know why or what does this means?

    It doesn’t seems to be hacked, all the content and pages are working perfectly …

    La Madame

Viewing 6 replies - 1 through 6 (of 6 total)
  • Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Shouldn’t you probe further into methods that check whether you’ve been hacked? Disregarding the possibility of a hack seems risky.

    http://sitecheck.sucuri.net/scanner/
    http://www.unmaskparasites.com/
    http://blog.sucuri.net/2012/03/wordpress-understanding-its-true-vulnerability.html

    You have been hacked. Soon they will load their own index.phph file and your site is no longer available.

    They gained access to your admin files and set their own username and email in your DB files. Use PHP_Myadmin and check the ‘users’ there you’ll find they have invaded into your dbase.

    It is essential to have ‘strong’ passwords and a WordPress security plugin running, also essential to change some file permissions – See BPS security Plugin.

    A similar hack happened to a new site I had created last year, it required a total re-build (as I had not backed it up!!). Although you can find where they infiltrate via username & perhaps all looks OK, you do not know if they have hidden a file somewhere???

    Hope this helps

    Thread Starter lamadame

    (@lamadame)

    Ok guys… I need precise directions to follow and block them…
    When you say:

    Use PHP_Myadmin and check the ‘users’ there you’ll find they have invaded into your dbase.

    Does this means that I can erase their action there and fix this issue?
    I’ve activated the “Better WP Security” and it seems to be working great, but I still can erase the sec-w username…

    What should I do?

    You access your ISP host and the Cpanel for your site.

    There you will find the admin options for the ‘Database’
    – Use the phpMyAdmin option
    – Once open, usually on the left hand side, select your dbase ‘ ……_wrdp_1’
    – All the dbase folders now show
    – Select ‘wp_users’, once open it will show the records, edit the hacked user then save.

    Best I can offer, it is a fairly self intuitive operation. Just found this search result :http://support.godaddy.com/help/article/5942/using-phpmyadmin-to-manage-mysql-databases

    Thread Starter lamadame

    (@lamadame)

    GREAT!!! Thank you!!!
    I just did it… it worked at least for erasing the sec-w username… let’s hope this and the previous action to protect my website will be enough…

    Thread Starter lamadame

    (@lamadame)

    I guess I can say for now that is a solved issue…

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Sec-W??!!’ is closed to new replies.