• I had a couple of subscribers show up from @mail.ru domain and I noticed that one of them all of a sudden had a couple posts (my old ones) attributed to them… I’ve deleted them (the subscribers) and I looked around and didn’t see any other damage but…..

    I went to make a post but my editing window for creating a post has no toolbar. So I guess they may have been able to do something. Does anyone know which file from the install file of WP would control the display of the create post window?

    I’ve uploaded new files but it doesn’t seem to have helped…
    Ideas?
    http://www.vistaphotos.net/vista

Viewing 3 replies - 1 through 3 (of 3 total)
  • Thread Starter folgerj

    (@folgerj)

    I guess I’ll bump this once since I still can’t figure out what happened to my blog.. I’ve reloaded twice now except for the themes and galleries… I’m guessing that whatever the problem is would be in the content area… Anybody have any suggestions?

    Make sure that your currently editing in the Visual Editor and not the HTML editor. If you wanted to be safe, I would upload a new version of WordPress (Download Version 2.5.1) create a new database with a new password and also change the password for your actual WordPress user account. This may be a bit extreme considering we don’t actually know if your site has been compromised or not but it would take care of any possible security problems.

    I’m guessing that when you say “I’ve reloaded twice” you mean you’ve already re-installed your WordPress install. If this is the case I would clear private data from your browser. The WYSIWYG editor can be tricky to get working in some cases. I believe that the files for the WYSIWYG editor are .js files in the /wp-includes/ directory of your install.

    (If you do decided to upload a new version of WordPress and create a new site with new login / access data be sure to Backup your WordPress SQL database before modifying any files in your WordPress install.)
    (Note: Users in the Subscriber role are not usually authorised to access the Edit / Write interface within WordPress.)

    Thread Starter folgerj

    (@folgerj)

    I understand that from my readings but would a subscriber all of a sudden be able to have one or more of my old posts attributed to them? I don’t see anything in the wiki or the volumes of helpful faqs out there on this aspect of subscribers roles…

    This is the only reason that I have to go and suspect a “compromize”. I checked the chmod settings to see if they were preventing things from working but they seem ok…

    I have reloaded most all the non customized files and folders from a clean download of 2-5-1 and swapped out all admin files except for content and galleries.

    I’ve looked through the different php files but nothing jumps out at me as being alien…

    It’s just the editing funtions for the most part aren’t there the two words for html and visual are there but clicking on either one produces no reaction from the page.
    The cursor turns to a hand indicating a link but right or left clicking on the links produce the expected results. A right click gives you the contextual menue as you would expect but it doesn’t give you the option to open in a new tab as all the other links on the page do…

    Thanks for the reminder on the DB and I will back it up and put into place the new “secret” phrase just in case this is a hack and not my imagination…

    Also I just switched over to vista… this couldn’t be something in vista that I’m not aware of…?

    Thanks…

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘possible hack but not sure’ is closed to new replies.