I upgraded to 2.9.2. My admin page keeps reverting to this, with all kinds of problems...
I've reloaded wordpress now more than I can count to fix this, thought I had it fixed opnly to wake up today ans see the same thing in my admin.
HELP!
I upgraded to 2.9.2. My admin page keeps reverting to this, with all kinds of problems...
I've reloaded wordpress now more than I can count to fix this, thought I had it fixed opnly to wake up today ans see the same thing in my admin.
HELP!
Usual suspects: Did you dump your browser cache?
I did that, and now I get a blank page where my admin used to be.
Check on the server. Are the files there in wp-admin?
yes. Like I said, I have reloaded wordpress several times now.
I have the same problem as poprunna, I am also getting a code of eval(base64_decode("aWYo.. in all my php files, I am so upset right now
poprunna, just because you've reloaded doesn't mean all the files are there :) By the way, the term you're looking for is 'reinstalled' -- reloaded implies you hit refresh on the webpage to reload it in your browser. Yes, semantics, but it matters sometimes :) Now. HOW are you reloading?
jamking, you've been hacked. See http://blog.sucuri.net/2010/05/new-attack-today-against-wordpress.html for help.
method a) via godaddy, uninstalling wordpress the REINSTALLING via the godaddy WP application widget. or...
b) by downloading a fresh version of 2.9.2 from wordpress, then doing a manual install/overwrite via ftp
I have discovered I have also been hacked. I am downgrading from 2.9.2 back to the previous version that I had no problems with.
poprunna - Downgrading won't help. The hack isn't that WordPress is vulnerable.
See http://blog.sucuri.net/2010/05/new-attack-today-against-wordpress.html for help. You're going to need to change all your passwords, too.
Also reinstalling via Go-Daddy's installer generally isn't the best way to go about it. Download a fresh copy of WordPress from this server.
You know... I'm starting to wonder if GoDaddy's WP installation is what's hacked...
well, if it helps Ipstenu (to return the favor, you've been a big help, thx), that's what started this whole ordeal for me. I got an email from godaddy about a WP security issue, urging me to upgrade to 2.9.2, and that's where all my trouble started.
You were probably hacked before, I'm afraid to say :(
My personal opinions about the issues with GoDaddy hosting aside, don't bother downgrading. Read the sucuri blog post, follow their directions, CHANGE ALL YOUR PASSWORDS and never use FTP again.
Ipstenu You know... I'm starting to wonder if GoDaddy's WP installation is what's hacked...
Ipstenu I most certainly agree with you on that one I was on the phone with them for 2 hours this morning and the tech tried to put it on wordpress saying that they had a Security problem last night, so they are now running a scan on my files and I will know the results in 24 to 48hrs but after that I will have to fix the problem! I ran the wp-fix for the web version at http://blog.sucuri.net/2010/05/new-attack-today-against-wordpress.html still no luck. getting back on the phone with go-daddy now. stay tune
P.s Ipstenu I did install a new wordpress at go daddy yesterday!! go figure huh?
An important point here.
If you just reinstall WordPress and don't change your passwords, you will be hacked again.
So please, even if you run the sucuri fix, remember to go change passwords. :)
got cha!!! thanks....
GoDaddy says they are aware http://community.godaddy.com/godaddy/wordpress-compromised-how-to-fix-it/?isc=smtwsup
Godaddy is getting hit hard over at twitter about this attack. for those hosting with them stay updated (sample) @GoDaddy get your crappy server config straight. Stop blaming WordPress. http://wordpress.org/development/2010/04/file-permissions/
Someone else mentioned to me that ALL your files may be infected. From your WP core files to plugins to themes.
Good news? It's NOT the database!
Bad News? You basically need to rip out your files and reupload everything fresh PLUS change your passwords.
I am up and running per go daddy I still have just a little glitch i.e photos will not upload. dashboard takes longer than usual to load. but everything else seems to be working well, change pw as advised, here is GD response
Thank you for contacting the Hosting Security Team.
We have checked and confirmed that your hosting account xxxxx had php files which contained a javascript malware injection. We have since removed the contaminated code as a (courtesy). Please note, that this is not a permanent solution because it does not remove the vulnerability that allowed the malicious code to be inserted.
To address the specific vulnerability, please ensure that you fully upgrade all installations of web based software such as WordPress or Joomla to the most recent version.
Out of curiosity, how do you generally update files?
I mean, I use SSH nearly exclusively, but when I use SFTP it's either Transmit or Cyberduck. Which FTP apps are you using, and are they secure FTP?
If its Ftp your talking about Ipstenu I use filezilla. good or bad?
As long as you're connecting with secure FTP (sFTP), rather than standard FTP, you'll be fine. Standard FTP is one of the least secure protocols around today. Most hosting providers offer sFTP access, but you may have to ask them to enable it first.
Thanks mac, and I am going over to Blue Host just got off the phone with them I have had it with GoDaddy my site is sill down after they so called cleaned it. Now my dashboard is all screwed up and my editor Upload/Insert doesn't work. it's one big mess
This topic has been closed to new replies.