• Hello,

    my website has been attacked by a hacker. My host has suspended my account because they say that my website sends spams. They made a scan and i have these lines concerning s2member :

    # Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-notify-in-subscr-or-rp-eots-w-level.inc.php’
    # (decoded file [depth: 0]) Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-notify-in-subscr-or-rp-eots-w-level.inc.php’
    # Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-notify-in-web-accept-sp.inc.php’
    # (decoded file [depth: 0]) Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-notify-in-web-accept-sp.inc.php’
    # Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-return-in-web-accept-sp.inc.php’
    # (decoded file [depth: 0]) Regular expression match = [decode regex: 8]:
    ‘/my-site/wp-content/plugins/s2member/includes/classes/paypal-return-in-web-accept-sp.inc.php’

    * Does someone can tell me what it means ?
    * Is it necessary to delete my plugin for cleaning my website ?

    Thanks for your help in advance,
    Igor

    https://wordpress.org/plugins/s2member/

Viewing 6 replies - 1 through 6 (of 6 total)
  • I think s2M can not be a problem, but WP or some plugin and theme too. I see lot of attacks to sliders, crackers use them to download sensitive info like wp-config.php file (I build a plugin “KC Admin area Monitor” to track that, will be released soon).

    Also s2M in known to create lot of PHP notifications, I think this is what you see.

    Thread Starter igorlaszlo

    (@igorlaszlo)

    Thanks for your reply, it is really kind !

    I will change the wp-config after the cleaning, it is for sure.
    So, do you think that above scanned files are not infected and i can keep s2member without reinstalling ?

    First, not need to change wp-config.php, it is a system file, WP can not work without it. If you change (even I don’t know what you mean as “change” of a config file), you may crash the site better that a cracker can do… You just must protect it, because there stay your settings, include DB access info. Actually, nothing to do if WP and themes and plugins are clean and updated.

    Best way to check if a file is infected (altered) is to compare to the original. You have a local copy of your site, right? Or at least you have old backups? To be really sure that you have a clean plugin, not s2M only, download it again and replace all the files by FTP.

    Thread Starter igorlaszlo

    (@igorlaszlo)

    I meant under “change a file” that i will send it again via FTP …
    If i delete for example s2member and than i send the new files to the server, will it loose the connection between the website front end and the database ? Or i just have to “change” the files directly (in sending via ftp and the system changes it) ? Or it does not make difference ?

    I do not know anything about database and the relation to my whole website, i do not know how the plugins changes will affect all data…

    Better don’t delete old files. You must just replace them by original ones. Plugin what you replace must be same version as plugin on the site. Updating will do just the same, so it’s enough to replace these, which can not update.

    Sorry about wp-config.php – misunderstood you…

    Thread Starter igorlaszlo

    (@igorlaszlo)

    Thanks a lot Krumch !

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Attack of a hacker, my site and my s2member plugin is concerned’ is closed to new replies.