achadwick454
Forum Replies Created
-
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?Over two weeks and still no reply over at the WordFence forum. Disappointing.
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade,
Someone guessed one of my administrative user names and exploited a vulnerability in WordPress. It was “andy” which I guess they figured out from looking at my site. I’m not using any obvious user names anymore so that should help in the future.
By the way, WordFence has been VERY informative. The live traffic monitor is very useful and the alerts are great. It seems like about every 3.5 hours I get 15 (I counted them( attempts to log in using the “admin” username. These attacks come from all different IPs, but they all come in with 1-2 minutes of each other.
Thank you very much for your help, wslade. I really appreciate it. I think that I’l take up my hosting service’s offer to move to a new server.
I still have not been able to complete a WordFence scan yet.
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?My website has been hacked again. I guess I need a lot of help.
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade,
I’d like to continue this conversation. Just sent an inquiry into your website.
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade, I posted over on the WordFence forums but no reply after more than a day. π
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade,
Our monthly traffic is way low. Our website is the basis of a very small hobby business that frankly takes more time than it’s worth. We get ~$2k revenue a year and keep it going only because it’s fun. But hackers make it a PIA.
I’ve not posted on Wordfence yet since I’m so busy with my day job. I’m a chemical engineer serving the oil & gas industry working for a Fortune 100 company and we’re swamped right now. I’ll try to get back to this tonight. Thanks for your patience!
kmessinger, I’ll check out their offer to move to a new server. I’ve not read the directions in the link you provided but it is an easy process to do?
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?kmessinger,
I asked my hosting service about the Sucuri scan and got the reply posted below. They want more money. Is this typical?
================================
We could see that the Sucuri Scan of your domain “jdcproducts.net” hosted in our shared server “xxx.xxxxxxxxxx.com” shows both the cPanel and Web Server Apache as outdated one.Please note that your account “jdcproducts.net” is currently hosted on a shared server and there are many legacy packages installed on our shared servers. Any update may break such installations. This may in-turn cause service disruption. We can only update any dependency packages after rigorous testing from our end. We do not normally upgrade packages on shared server.
Please note that, it is not possible to make server wide changes/updates in a shared server because any changes/update made will affect the other accounts hosted on the server.
There are two options for you to get rid of the vulnerabilities mentioned in Sucuri.
====
1. You can move your account to our new cPanel server “xxxx.xxxx.com” which is patched with latest updated softwares and applications. If you wish to move the website contents to the new server, we will create a new account in the server and will provide you the login details and you have to migrate the contents to the new server.OR
2. You can move to a VPS plan. VPS Hosting allows for custom configurations and installations, because it gives you full root access to the virtual server. This is feasible because you are the sole owner of the VPS. Also, it has better security to count on because of its self-dependency. That is because every virtual server uses its own resources and OS, it can be rebooted and configured absolutely independently from the other virtual machines and itβs not affected by other usersβ actions. Self-dependency makes VPS Hosting more secure than shared web hosting. Please refer the following URL for more details on the VPS plans available.
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?Again, I don’t know how to tell how many files are in a folder using cPanel file manager. How can I tell that? (Thanks for your patience with a newby!)
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade, I did read your post and followed your instructions last night but got the same error message when I set the max time to 240 seconds except fewer files were scanned. I then tried different times and got the following:
10 seconds scanned 123,800 files
15 seconds scanned 164,300 files
default seconds scanned 104,800 files
60 seconds scanned 47,800 files
240 seconds scanned 49,600 files.I have not yet been able to complete a scan. Everytime I scanned I got pthe same thing in the New Issues area called “Bulk Operation” I then clicked on the “select all repairable files” and nothing happened. After clicking on the “select all repairable files” button I then clicked on “Bulk Repair Selected Files” but got the following error message:
No files were selected
You need to select files to perform a bulk operation. There is a checkbox in each issue that lets you select that file. You can then select a bulk operation and hit the button to perform that bulk operation.
I got exactly the same result by clicking on the “select all deletable files” and the “bulk delete selected files” buttons. Nothing happened except I got the error message in the pop-up box.
What else should I try to complete a scan and be able to fix the problems?
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?I tried to run a Webfence scan again and got the same error message:
Maximum execution time of 30 seconds exceeded in…There are two folders in my directory that contain the folders named wp-admin, wp-includes & wp-content. One is named “public_html” and the other is named “www”. Which one should I be looking at?
Also, I don’t know how to tell how many files are in a folder using cPanel file manager. How can I tell that? (Thanks for your patience with a newby!)
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?No cache plugin running. I don’t even use the blog functionality since I use my website only for product sales. I’ll get back to this issue this evening. I’ve got to attend to my day job now. Thanks for your help!
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?The scan had a fatal error “Maximum execution time of 30 seconds exceeded” after analyzing 170,300 files. I have no idea why so many files are in there. The scan did find one issue called Bulk Operation. Should I clean or delete the infected files?
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?I just installed Wordfence and it’s scanning for the first time. Do I need a p[aid version of Wordfence or will the free version suffice?
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?wslade,
I did find a very large number of lines in the wp_usermeta table that were neither of the two valid user ID so I deleted them. It worked! The user count is now correct. π
juggledad,
This is the first time I’ve heard about hardening my website. Thanks for the tip! I did a google search and found very many hits. Could you direct me toward where I should start?
Forum: Fixing WordPress
In reply to: Invisible Administrator Users?There are only two users in the wp_users table, the same ones that are listed in my users list in wordpress, but there are is bunch of stuff in the wp_usermeta table that I don’t recognize.