ningishzidda
Forum Replies Created
-
A new error started happening. This time it was Ecwid shopping cart. After the update applied to the plugin the visual editor wouldn’t load, it just looked like the HTML editor. I came here and found your request and I noticed the errors for java with Ecwid, so I disabled the plugin and that fixed that.
But the problem with the update button is still there. I will type a couple of letters, and the update button wills suddenly go inactive.
Then it comes back for a few seconds. Then it goes inactive again and stays that way until I use the Google Chrome debug trick and delete the word disabled.
I did the steps for checking for java errors, there seem to be none. Sorry for the slow reply, I have too much to do.
Just an update, it is still doing this. Gets stuck in autosave apparently forever.
Yeah…it’s a bizarre issue that makes no sense. I disabled all plugins and am already on 2015. I tried different themes, like 2014.
Thanks for the advice on the Chrome though, and the autosave process…so I actually had to open Chrome to get it to update. That fixed the menu. Oddly enough the Update function started behaving properly again, for the first few minutes before going into the autosave process. Before it would immediately be disabled.
Since it is a VERY long post (book size ish) with lots of edits I suspected something with that perhaps. Who knows how long it will last like this, but I will keep the thread updated if I notice the issue returning – it is currently in autosave mode and im going out, when i return it should have returned from that state. If not I will think it is something “stuck” in the code that is unknown, similar to how plugins sometimes get stuck? Im not even a coding amateur so I have no idea.
I am currently editing in google docs as my master copy now to be safe.
More mysteries emerge.
It appears the work was saved, but to a revision, I was able to retrieve my lost work by going to a previous version. That means WordPress is somehow not calling up the most recent “Save” done by changing the code on the Update button in chrome, when I click on a post in the post list.
Just noticed, that when I use this method, even though it shows as saved it doesn’t really “Save” it lost all work for the past three days, rolling back to an autosave.
Also the WordPress menu apears “scrambled” buttons will stack on top of each other and jump around.
What is going on? This is a fresh install.
Forgot to add…I disabled all plugins and reinstalled WordPress, overwriting old files.
I think I figured it out, but I’m not sure. I think this came about because I have disabled and re-enabled comments.
in the posts list in the admin, under quick edit, the comments have to be re-enabled for every post manually.http://codex.wordpress.org/Comments_in_WordPress#Enabling_Comments_on_Your_Site
[Expletive] xst let me just log into the cp and haX0r infested darknet, WHERE I CAN ACTUALLY TALK ABOUT WORDPRESS AND THINGS RELATING TO WORDPRESS.
Here’s the code they were inserting in sidebar:
[removed]
That’s nice to hear photocrati, your plugin is very valuable to me and I will reinstall it when I stableize.
You can take a look at a partial error log leftover from earlier i have. Remember that this is not ONE person doing this. I watched the live feed and this was basically a team of people who targeted our site specifically over some grievance, using many different exploits. This just happens to be the most annoying, although not the most damaging portion of the attack. This is the tail end of what has been a really interesting Post-Superbowl weekend I do not know anything about the earlier attacks as I have not had a breathe to take a look.
But first I’ll tell you what was occuring while the errors were happening, and I can give you access to the full logs if you like, but I’d have to find them first as I am an amateur.
First the site would get broken into, permissions changed, adverts go up.
I take them down, change the permissions.
The error log THEN reports this:
[removed]
After this string, the process repeats itself. The permissions are changed, the popups go back up.
I delete the Yillix and Bidsweeper code out of sidebar and footer, and change the permissions back.
Repeat about 10-20 minutes later. (by the way my admin name is not really admin, do not worry)
Now where am I at now?
I switched themes to 2015, as it is the safest theme you can get. I deleted Gamepress, because it did not update with the latest upgrade. Our leader is really attached to the theme but it has java built into it for some damned reason. The exploits appeared to be targetting NextGen gallery java and the Gamepress theme java.
My ex-husband who was in IT used to say, “It’s always [removed] java!” Before screaming. He became a cop after ten years in IT and Security because he was so sick of this stuff. Don’t know how true that is but it does appear to be some java exploit they are using.
I have no idea what it is. My webhost got back to me and offered to harden the site for $45 which was nice, so I took the offer and I am going to see what they do. I hardened WHM as best I could and scanned my computer again but nothing dangerous was found.
SO far it’s holding, the 2015 theme has been up for an hour. I am stripped down to very few plugins right now.
Forum: Fixing WordPress
In reply to: Site was hacked again, same timeframe as last yearHere are my scan results for anyone else who might find them useful:
This file may contain malicious executable code: /home/m1thr0s5/public_html/mutationalalchemy.com/wp-includes/css/newshellwitpass.php
Filename: mutationalalchemy.com/wp-includes/css/newshellwitpass.php
File type: Not a core, theme or plugin file.
Issue first detected: 30 secs ago.
Severity: Critical
Status New
This file is a PHP executable file and contains an eval() function and base64() decoding function on the same line. This is a common technique used by hackers to hide and execute code. If you know about this file you can choose to ignore it to exclude it from future scans.I deleted it. It also detected changes to the original Gamepress theme but I am pretty sure I made them. I reviewed the two altered files and they looked okay.
Forum: Fixing WordPress
In reply to: Site was hacked again, same timeframe as last yearHere’s what I did:
Deleted Social Media Feather by Acurax because it was specifically targeted by somebody this morning. I cannot afford to lose Next gen gallery as i think most people will agree, so I installed Wordfence after finding it highly rated during a search for the outdated Sucuri (more below)
I reinstalled WordPress.
Global settings on the sidebar somehow got set to allow users to write, so I set them not to be able to write, which would have prevented the sidebar from getting hacked to show google ads.
I am tired of the footer constantly getting hacked by less malicious hackers to point to yontoo, (for some reason any new updates to wordpress like to set the value to allow users to write again, after ive disallowed it) so I’ve disabled user registrations and deleted our vast collection of members – they wernt really adding that much of value to the site anyways. I do not need them. This will prevent user uploads at least.
I think the culprit for the first hack may have been Next Gen Gallery as the majority of the attempted attacks this morning seem to have been directed at it. Looks like there was a WordPress update between then and now, too so I wonder if that was it.
I also uninstalled Wang guard since I don’t have any users anymore.
Sucuri was reccomended by those links, but it is outdated with current version of wordpress, so I disregarded it. I installed Wordfence instead which came highly reccomended.
By the way, that security company/webhost I called was a joke. The guy called me and couldn’t tell me anything useful about what their security company did, just a bunch of flashy sounding rhetoric in an email after the useless phonecall. He said “What really makes us the best is we learn every time we get hacked.” I was like “erm, yes that is the thing to do after making a mistake or getting attacked, you learn from it” The tour through the free plugin Wordfence is much more impressive with actual information. The math is easy free or 350 a month, or 200 a year for three site keys from the Wordfence plugin, or 350 a month. Looks like it’s all the same stuff.
I uninstalled my cache program because Wordfence includes one.
Forum: Fixing WordPress
In reply to: Site was hacked again, same timeframe as last yearThey appear to be attempting an alteration of Acurax and Next Gen gallery. I don’t need Acurax so ill uninstall it but I do need Next Gen gallery.
Forum: Fixing WordPress
In reply to: Site was hacked again, same timeframe as last yearThanks for all of those links. I’ve done the hardening one before.
The site is still getting hacked, although not as badly now and I am looking through the error log from the hacker activity today.
Forum: Fixing WordPress
In reply to: Site was hacked again, same timeframe as last yearShit I just realized we have a ton of Hebrew art on our site. Now Im pissed off. Going to go tell a Rabbi about it.