Viewing 3 replies - 1 through 3 (of 3 total)
  • When you uploaded a fresh copy of core, did you delete all of the old files & folders before uploading the fresh copies? I’ve known old copies of files to remain even after an apparent fresh upload.

    Did you check the database for hacker scripts etc?

    I’d also recommend taking the site right back to a vanilla install by activating the default theme and resetting the plugins folder by phpMyAdmin, if possible. The odd vampiric script will still run even after a plugin folder rename. Resetting via Phpmyadmin seems to stop all of that in its tracks.

    Since this is a post hack issue, it might be worth reviewing http://ottopress.com/2009/hacked-wordpress-backdoors/ if you haven’t already. You may still have some rogue code lying around.

    Thread Starter Ricky55

    (@ricky55)

    Thanks for replying man.

    Well I didn’t delete them I just moved them to a folder called zzz

    No I’ve not checked the db for hacker scripts. Do you have any more info on these? how they look, which tables they typically appear in etc?

    Yeah I might have to take back to a vanilla install.

    Once again thanks.

    I just moved them to a folder called zzz

    That should be OK although, personally, I wouldn’t keep them hanging around.

    Do you have any more info on these? how they look, which tables they typically appear in etc?

    Oh gosh – that’s a real “how long is a piece of strong” question! In terms of specifics, I have no idea as every hack is different. The link I posted above gives some general information on what you should be looking for but I think that’s about as helpful as it gets. 🙁

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Login to admin takes me to home page’ is closed to new replies.