• Early last week we upgraded my WordPress site to the latest version. Before there were no particular problems, but as soon as we upgraded, I began to receive about triple the amount of spam comments, and for the first time, I was receiving numerous pingbacks from other WordPress sites clearly set up by spammers.

    Yesterday I logged in to my dashboard and went to delete the spam comments. As soon as I click an action (ie mark as spam), all the links on the whole WordPress dashboard turn green, and the action will not go through.

    Furthermore when I try to post a blog, it will allow me to begin composing, but then if I try to Save Draft or after a certain period, it will take me to what looks like a PHP editing screen that is titled “Magic Include Shell 3.3.3”. Also if I try to log out, it takes me to the same screen.

    Per this thread…

    http://wordpress.org/support/topic/cant-postedit-requesting-authentication-magic

    …I downloaded brand new root files from WordPress, and replaced ALL of them in my root file except the wp-config file, meaning the whole wp-admin and wp-includes files, as well as all the other individual files in the root folder. It had no effect.

    Help. Please.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Moderator James Huff

    (@macmanx)

    Try decativating all plugins. If that resolves the issue, reactivate each one individually until you find the cause.

    If that does not resolve the issue, try switching to the Default theme (WordPress 2.9) or the Twenty Ten theme (WordPress 3.0) to rule-out a theme-specific issue (theme functions can interfere with the admin panel).

    Thread Starter kylecor42

    (@kylecor42)

    Thank you for the help.

    Already tried that per another Magic Include Shell solution I found, but any time I click to change a plugin, it takes me to the “Magic Include Shell 3.3.3” PHP-editor-looking screen. I tried changing them individually, as a bulk action, using a different browser, and nothing worked.

    Pretty much any time I get to the point of being able to change content on the site in any way, it takes me to the Magic Include Shell screen.

    Thread Starter kylecor42

    (@kylecor42)

    Oh, and I don’t think this is theme-compatibility related. Though I did just upgrade, I didn’t experince this problem until about a week later. I suggested to the guy that helps me with the back end that we do a downgrade. He’s not too excited about that idea. The reason we upgraded was supposed to be to defend us better from hacks.

    Try resetting the plugins folder by FTP or phpMyAdmin.

    And your web guy is right – upgrading to the latest version is the best security against future hacks.

    Thread Starter kylecor42

    (@kylecor42)

    Thanks Esmi,

    Ok, I followed the instructions to manually disable the plugins. After making a plugins.hold folder thru FTP, I went into the administration dashboard, and under “Plugins” it said they were all disabled. Then I renamed the plugin file through FTP.

    Still did not solve the problem. Nothing’s changed.

    And your web guy is right – upgrading to the latest version is the best security against future hacks.

    Ironically in 2 1/2 years I never had one problem. A week after upgrading my spam triples and I get hacked.

    moongoose

    (@moongoose)

    Another security tip: Do NOT download WordPress themes found via an Internet search (ie some site other than wordpress.org). I did that and one of them had the Magic Include Shell hack in the comments.php file. So, if you are having issues with Magic Include Shell, you may have it in your theme files, so be sure to search on those files for those words. No one seems to mention this has a potential source of the attack. You may have uploaded your theme two years ago, then the hacker finally discovers that you have left the backdoor open for them and starts to exploit it.

Viewing 7 replies - 1 through 7 (of 7 total)

The topic ‘Hacked By Magic Include Shell 3.3.3’ is closed to new replies.