• lpelham

    (@lpelham)


    I was hacked by the Moroccan Agent Secret recently. Copying over my htdocs seemed to take care of the problem. I am using the latest version of wordfence.

    However, I still cannot log in to the wp-admin side of my site. I get a Fatal error: Call to undefined function curl_init() in /htdocs/www/wp-content/plugins/wordfence/lib/wordfenceClass.php on line 922 message.

    Looking at line 922 I see this: $curl = curl_init(‘http://noc3.wordfence.com:9050/hackAttempt/?k=’ . wfConfig::get(‘apiKey’) . ‘&IP=’ . wfUtils::inet_aton($IP) . ‘&t=’ . $type );

    I’m not sure what to do next.

    I tried renaming the wordfence folder in the plugins folder via FTP but then I get ‘unrecognized username’ when I try to log in to wp-admin

    https://wordpress.org/plugins/wordfence/

Viewing 15 replies - 1 through 15 (of 30 total)
  • wslade

    (@wslade)

    What’s the URL of your site?

    Thread Starter lpelham

    (@lpelham)

    Forgive me .. but why are you asking for the URL? Is there something I can look for in the page source?

    wslade

    (@wslade)

    I wanted to see if wp-login.php appeared normal and to see if any outward signs of the hack still exists.

    Did you notice the “Did you include a link to your site, so that others can see the problem?” at the bottom of the reply box? Where this isn’t a rule, it sure makes helping you easier.

    Thread Starter lpelham

    (@lpelham)

    I’m sorry.. I’m just so untrusting these days. Eickertrealty.com

    wslade

    (@wslade)

    No problem :), one can never be too safe.

    Would you try turning off all your plugins, not just Wordfence? Go to wp-content and rename the plugins directory to plugins-off.

    Do you remember if you have more than one theme in this site?

    When you replaced the directories and files in htdocs, did you delete the files before uploading new ones?

    Thread Starter lpelham

    (@lpelham)

    After renaming the plugin folder and I try to log in at wp-admin I get ‘invalid username’

    At the time of the hack I did have all the versions of twentyX but deleted them via FTP after the site was restored.

    After the hack I had my host delete my site entirely and I resinstalled WP fresh then applied the back up from the day previous to the attack. Then changed passwords. Then did a back up.

    Then got hacked again.

    I did not delete files before uploading my back up htdocs after the most recent restore, no.

    Thread Starter lpelham

    (@lpelham)

    Furthermore, when I try to retrieve a lost password – I enter my username and result is ERROR: There is no user registered with that email address.

    Thread Starter lpelham

    (@lpelham)

    Should I just install a fresh version of WordPress via FTP?

    Thread Starter lpelham

    (@lpelham)

    I mean a fresh version of Wordfence.. not WordPress

    wslade

    (@wslade)

    This is a good step – Wordfence can wait until you get access to the script.

    OK, how about resetting your password using phpmyadmin? Use this link as a go by: http://www.wpbeginner.com/beginners-guide/how-to-reset-a-wordpress-password-from-phpmyadmin/

    You will want the plugins off when you try this or you’ll get the error again.

    If you don’t find yourself in wp_users, just let me know.

    Thread Starter lpelham

    (@lpelham)

    Yes, I was in the db this morning and in the wp_users table.. unfortunately I don’t have see the table values..

    I’ll have to contact my provider for support, I guess.

    wslade

    (@wslade)

    I’m confused, you don’t see what you expect to see in the tables?

    Thread Starter lpelham

    (@lpelham)

    wslade

    (@wslade)

    OK, I think you may have missed a step in the instructions. No more caffeine for you! You want to select the wp-users table and Browse then Edit the row containing your data.

    This give me a chance to give you a short cut – there is a drop down with MD5 as an option now – you no longer have to go find a MD5 hash generator. Just put your password in plain text, choose MD5 from the dropdown and save.

    Then trying to log in.

    Thread Starter lpelham

    (@lpelham)

    Well, notice the Browse tab is not highlighted.. I can’t browse πŸ™

Viewing 15 replies - 1 through 15 (of 30 total)
  • The topic ‘Recovering after a hack’ is closed to new replies.