• Earlier today, it appeared as though only the main page was working. Everything else I attempted to access from the main page returned a 404.
    Okay, no problem. Just restored from a backup. Boom. Done.

    Then, my site kept going down.

    Then, even trying to log in through the host wasn’t working.

    Now I’ve regained access through the host.
    A scan is currently running on my comp.
    The site appears to be up and running a-okay again.

    Now, I noticed the following in the logs…

    Host: [REMOVED]

    *

    /wp-includes/js/jquery/ui.core.js?ver=1.7.3
    Http Code: 200 Date: Jul 09 22:08:17 Http Version: HTTP/1.1 Size in Bytes: 8558
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /wp-includes/js/jquery/ui.tabs.js?ver=1.7.3
    Http Code: 200 Date: Jul 09 22:08:18 Http Version: HTTP/1.1 Size in Bytes: 11625
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /wp-content/themes/pressplay/library/tabs.js?ver=5279
    Http Code: 200 Date: Jul 09 22:08:18 Http Version: HTTP/1.1 Size in Bytes: 495
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /Imgs/favicon.ico
    Http Code: 200 Date: Jul 09 22:08:18 Http Version: HTTP/1.1 Size in Bytes: 1521
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /
    Http Code: 200 Date: Jul 09 22:08:14 Http Version: HTTP/1.1 Size in Bytes: 9554
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /wp-content/themes/pressplay/style.css
    Http Code: 200 Date: Jul 09 22:08:16 Http Version: HTTP/1.1 Size in Bytes: 17015
    Referer: –
    Agent: Opera/8.54 (Windows NT 5.1; U; de)

    *

    /wp-includes/js/jquery/jquery.js?ver=1.4.2
    Http Code: 200 Date: Jul 09 22:08:21 Http Version: HTTP/1.1 Size in Bytes: 72578
    Referer: [MAIN SITE]
    Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20070321 Netscape/8.1.3

    That isn’t the only IP that accessed strange things. I’ve IP banned many IP’s.

    Any ideas of what’s going on / what to do next?

Viewing 4 replies - 1 through 4 (of 4 total)
  • Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Then, even trying to log in through the host wasn’t working.

    Sounds like you need to secure your host. Those log entries you’ve posted don’t really indicate what the problem was. Banning IPs won’t solve the problem and will just make work for you.

    Also can you provide a link to your site? This might be just another case of wORDpRESS not being secured on you blog.

    Thread Starter user220

    (@user220)

    Actually, what if I were to simply rip everything out, put up a new install, and then put the posts back into the new one.

    How would I go about doing that?

    (I’ve made it unavailable to the public by throwing up a password protection)

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Export the existing blog into WXR and save that file.

    http://YOUR-BLOG-URL/wp-admin/export.php

    Backup all your files and database. Get ready to restore them from scratch.

    http://codex.wordpress.org/WordPress_Backups
    http://codex.wordpress.org/Backing_Up_Your_Database
    http://codex.wordpress.org/Restoring_Your_Database_From_Backup

    Once you are completely sure and confident that your backups are complete and good, and you are sure that you can restore them to their current state, then delete your WordPress files.

    When you create the new wp-config.php, use the same database. But make sure you use a different table prefix. This way your valuable database stays intact and you start with a set of empty tables.

    At that point, install WordPress, and import that WXR file back into the new empty installation. This should get your posts and comments back in fresh and new.

    MAKE SURE YOU HAVE THAT BACKUP! Sorry to shout, but a good backup and restore plan can save you hours of grief.

    Judging from the post, it would seem that these hits bring only paranoia–and no factual proof of anything. Reinstalling an entire WordPress setup because of it seems a bit overboard to me…

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Possible hacker? Strange IP's accessing jquery’ is closed to new replies.