Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter Martin.Harper

    (@martinharper)

    Thanks Chip, I can confirm that:

    — WP version is latest and updated on all hacked blogs.
    — It is not FTP as it is restricted have also checked logs.
    — It cannot be my hosting because all the software are regularly updated and I, myself ensure that the permissions are correct.
    — My local machine has professional Anti Virus and is regularly updated. I also doubt that it is my machine because I have firewalls / IDS in my network and as I said only few blogs were affected, rest were OK. I expect even other blogs to get compromised if it was my local machine.

    Regarding plugins, I have “All In One SEO Pack”, “Artiss Social Bookmarks”, “WordPress SEO” and “WP Social Bookmarking Light” installed & up to date but I have only “WordPress SEO” active.

    On recommendation of one of my friends I have removed all Themes and have switched to Default WP Theme (New One) and have also restricted admin directory to certain IPs. Lets hope that this works.

    Regards,
    Martin

    Thread Starter Martin.Harper

    (@martinharper)

    Thank you for your quick response poeple, this is highly appreciated.

    yes, I have read most of those but the sites get defaced event after I restore the entire installation from good backups. I suspect the themes that I am using are vulnerable (different every time).

    I want to know if there is a list of recommended themes or if not I am ready to switch all my blogs to default WP themes. Can you guys ensure that they are safe.

    I am also taking to one of my friends and he has suggest to restrict the admin directory with .htaccess so that only certain IPs are able to access the admin area. Do you guys recommend this..?

    Thanks,
    Martin

Viewing 2 replies - 1 through 2 (of 2 total)