Forum Replies Created

Viewing 15 replies - 1 through 15 (of 22 total)
  • Thread Starter gobigk

    (@gobigk)

    Just wanted to follow up on this thread. For most of the last week two of my websites were targeted by a brute force password attack. Traffic to my websites increased by 2000%, almost entirely originating from a single province in Russia. Here’s what I learned and what helped me:

    – Even though I didn’t use “admin” as my administrative account’s username, the hackers were able to quickly find my admin username by looking at posts in my website and looking at their creator’s username. I’ve rectified this by using a new username and in the WP settings all articles are now posted by “admin”. The actual username is not displayed anywhere on the website and there’s no way for a hacker to find the actual username anymore (except by guessing).

    – The Sucuri plugin was instrumental in helping me add additional levels of security to my websites, starting with passwords that are at least 20 characters long. It’s a very complex plug in to set up (at least I thought it was) but well worth the effort.

    – I think the only reason the hackers weren’t able to gain access to my website was because my original passwords were 12 random characters composed of letters, numerals and special characters. Had I used anything that included words of any kind, they would have easily gained control of my website.

    Thanks everyone, especially Steve, for your help!

    Thread Starter gobigk

    (@gobigk)

    I used different databases for each of the websites.

    Figured out how to fix it. Went to Settings then the Permalinks page and just saved the settings. That fixed it. Not sure why I had to do it, but I’m happy it’s fixed. 🙂

    Thread Starter gobigk

    (@gobigk)

    But I didn’t change anything (yet) in this website except add 2 plugins. I can change the first website back to it’s original database prefix, but I don’t understand why changes in one website would effect another?

    Thread Starter gobigk

    (@gobigk)

    OOPS! Making the above changes seems to have broken another of my sites. 🙁

    After finishing the above changes and testing everything, I set about to do the same thing with another of my websites. Both sites are hosted on the same server, but are located in different folders and use different databases.

    The home page seems to work fine. The admin pages work fine. But if I browse to any of the linked pages I get a 404 error. Did I break something when I changed the first website’s database prefixes?

    Thread Starter gobigk

    (@gobigk)

    Thanks Steve. I installed the sucuri plugin and no malware, etc was found. Made some of the changes recommended and installed the geo blocking plugin. Looks like I may have nipped this one in time (fingers crossed).

    Went back to Google Analytics and looked at the search engine name that was the source of all the hits. Looks like someone in Russia was making a political statement?

    http://i66.tinypic.com/2mriako.jpgGoogle Analytics

    • This reply was modified 9 years, 8 months ago by gobigk.
    • This reply was modified 9 years, 8 months ago by gobigk.
    • This reply was modified 9 years, 8 months ago by gobigk.
    Thread Starter gobigk

    (@gobigk)

    @jose – Yes, that’s what I’m seeing. Don’t remember seeing it before 4.3.1.

    Thread Starter gobigk

    (@gobigk)

    BUMP*

    Thread Starter gobigk

    (@gobigk)

    I’ve decided to start from scratch following that “Smackdown” thread. Deleted everything WP from my server. My site didn’t have that many pages so it’s not a big deal. Hope this is the last time I have to do it though.

    Thread Starter gobigk

    (@gobigk)

    I’m having a hard time understanding how I was hacked twice in 2 months. All my folders permissions were set to 755. I use very secure passwords (10+ characters) and change them frequently. My site was using Joomla before and for 6 years was never hacked. I looked at the Smackdown post above and it looks like I did everything right.

    Thread Starter gobigk

    (@gobigk)

    It won’t help for long because your filesystem is compromised and I don’t think you’ve necessarily closed that door.

    Do you have a link to directions that tell me how to fix this?

    Thread Starter gobigk

    (@gobigk)

    I’m not with GoDaddy and I’ve not had a hack in 8+ years with the same host, but I will look into it anyways.

    Quick question: Can I do a new, clean WP install into a new folder on my server and a new, empty database while leaving the old WP folder and db intact? It would just make things much easier to duplicate how I did things on the old site. Then when I’m done, I’ll delete the entire old WP folder and db. Or do I have to wipe the server clean and start all new? I won’t be using my back up at all, I don’t want to risk there being any malware there that I didn’t catch the last time. I’ll be starting with a fresh download of WP 3.2.1, my template and my 1 plugin.

    Thread Starter gobigk

    (@gobigk)

    Yup, I changed the passwords a few weeks ago after the first hack and today again after the second. I’ve backed up the site to my HD and am debating what to do next. I may re-install everything from scratch or I may dump WP entirely. In 10+ years this is the first time I’ve ever had my website hacked and now twice in just 2 months since switching to WP. I really like how easy to use WP is but if this is a sign of the future I’m better off with plain old HTML.

    Thread Starter gobigk

    (@gobigk)

    I’ve pulled the site off line until I get this fixed. Took a couple tries but I saw the IFRAME you referred to. I may just start all over from scratch, the “how to” pages you listed are pretty confusing and probably why I didn’t fix it properly the first time. Considering all the time I’ve spent on this, I might have been better off just writing the whole thing in HTML from the start. 😛

    Thread Starter gobigk

    (@gobigk)

    Jan, could you contact me privately (contact info is on my website)?

    Thread Starter gobigk

    (@gobigk)

    Nope, nothing in .htaccess that would cause it and the virus scan of my Mac came up clean. Here’s the web address: marinesimulation dot com if you wouldn’t mind giving it a quick look.

Viewing 15 replies - 1 through 15 (of 22 total)