• My site went down today, although I could still log into the admin panel. I had a look on my server and the index.php had been changed to a file that was 240k . I chnaged the index.php back with a backup file and everything worked.

    Does this mean my site has been hacked? and if so how do I stop it from happening again. The only plugin I have used is the autoupdate one.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Does this mean my site has been hacked?

    the site in your profile? the one running a version of wordpress that is over a year old and can be exploited by anyone able to copy and paste from milw0rm.com?

    <meta name="generator" content="WordPress 2.2.1" /> <!-- leave this for stats -->

    probably, and it may also be that that isnt the only incursion.

    As for the next question:

    you scour your site for anything malicious
    you scour your database.
    and you upgrade
    you change ALL of your passwords, including your mysql password
    you contact your host and let them know.

    Theres more than enough info out there that goes through the details on all of that.

    http://wordpress.org/search/hacked?forums=1
    http://ocaoimh.ie/2008/06/08/did-your-wordpress-site-get-hacked/

    Thread Starter bigcol

    (@bigcol)

    Thanks for the info, but the site that was hacked was not the one in my profile, and was version 2.51
    I will do as you suggest, as a beginner in the wordpress stakes I come back to the forum for help, the websites you have given me will help me prepare better.

    It’s nice to be important, but more important to be nice.

    2.51,

    thats another story, and one I cannot speak to. Do, however upgrade that site in your profile, asap if its yours to do, though.

    Donncha’s link ( the second ) might help you more than the first since he goes into some good detail.

    bigcol – is this site on the same server as your old WordPress site?
    Is this hacked site an upgraded site, or a brand new install?

    Thread Starter bigcol

    (@bigcol)

    The site is on another server, and it is an upgraded site using the auto-upgrade plugin.

    Unfortunately your site was probably hacked before you upgraded, even if you upgraded on the day 2.5.1 came out. My post above has some useful info you should follow!

    Thread Starter bigcol

    (@bigcol)

    Thanks for the info I will chack things out

    Caveat emptor or something like that

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘rogue index.php’ is closed to new replies.