You mentioned WordPress and the plugins – what about your theme?
Also, check if you have any “must-use” plugins. If any look unfamiliar, delete them.
Examine the wp-config.php file to see if it contains anything that looks suspicious.
Check the entire uploads directory to see if there are any PHP files inside. Some plugins write files there, but if you don’t recognize them, delete them.
Also, go ahead and delete all language files in wp-content/languages/. Hackers often hide code inside their PHP files. Once deleted, WordPress will download fresh copies.
If you have a wp-content/cache directory, delete that as well; the plugins that need it will recreate it.
In general, keep an eye out for any files that don’t seem to belong to anything.
Delete the wp-admin and wp-includes directories and re-upload their contents from a fresh download (matching your specific WordPress version) obtained from https://wordpress.org/download/releases/.
If you’d rather avoid that effort, check if you have a clean backup and restore it.
Afterward, you should take a look at this resource: https://developer.wordpress.org/advanced-administration/security/hardening/
Thread Starter
mvvvmd
(@mvvvmd)
I have not seen any indication of the attack being successful, my AV software is stopping the attempts. I also have done various checks to see if anything is out of order, this is not the case.
I would like to know if there is a way to block these uploads to /tmp. Idealy I would like to figure out what they are exactly doing to get the files written /tmp.
If you want to know how to stop this, you need to figure out the path the request takes. You can send all sorts of things to the AJAX endpoint, but only a function that exists in your project could cause data to be stored in the /tmp directory. That function, in turn, could come from any part of your project. You need to find it. My list above can be a helpful tool for that. WordPress itself doesn’t do this.