rossagrant
Forum Replies Created
-
Right now esmi, we’re still not 100% and I think right now it would be irresponsible to say 100% either way.
There was the UTF-7 hole in WP going back to vers 2.5. I’m not sure if this may have somehow been re-opened.
Could really do with a core developer being made aware so that they could give us the likelihood.
I think it’s lim that it’s WP, but because I can’t give steps to replicate, we just don’t know right now what has gone on.
We need raw access logs from someone’s host the day they see this happening.
Unfortunately my host only keeps 24 hours worth and the day this happened now has no logs which is a mare as I can pinpoint the exact minute the xploit took place.
If a core dev could tell us that in their opinion it is 100% NOT a WP issue then that’s great.
That does look like the kind of thing we are seeing here.
So does this point to WP or the server?
Forum: Fixing WordPress
In reply to: Got Hacked by BadiI think if the fix instructions in this thread dont work, then people need to create their own thread, if they DO work, then we need to collaborate to find out what this vulnerability is.
Please don’t close this thread as it is a means to keep each other updated about this.
It clearly isn’t isolated to just one host, one kind of setup, and is valuable for the entire community to be aware of.
Forum: Fixing WordPress
In reply to: Got Hacked by BadiJ87, is there any chance you can get your hosts to elaborate on the irregularities so that we can let our hosts know.
Let us know, but obviously don’t post info directly here as we don’t want to spread the vulnerability. If you can gather info, I’ll drop you my email address.
Thanks.
Still trying to work out how this is happening Alf, but will keep people posted.
No idea if it’s a WP script vulnerability that is being used to inject SQL or if it’s a host vulnerability.
If it is a server issue then it’s a very common vulnerability that needs to be discovered.
I wish the hackers would just come out and tell someone what it is.
Yep, it’s still there then.
Get in touch with your hosts and see if they have an idea. Affecting Cpanel is not good.
Klap if £ signs appear normally you are good to go.
That backup will have cleared out the hack I guess.
Keep a close eye on things though.
Not too sure exactly what has gone on there then. Is yous ite title still messed up? Change it back.
Are you showing weird characters on your site. Try typing a £ sign and see what it displays as. Are you definitely set to UTF-7?
The text widget won’t be in one of your sidebar areas, it will be in a long panel under the list of widgets on the LEFT.
It will be in an unregistered sidebar.
If it’s not, I’m not too sure, that’s just what I experienced.
Klap, the UTF option should be in your WP dashboard, not in CPanel.
Do you still see the text widget in the backend of WP in the Appearance—>Widgets section.
It will be under a heading down the page that says unregistered sidebar?
Don’t delete it just yet, but see if it’s there.
Forum: Fixing WordPress
In reply to: Got Hacked by BadiVery strange that this has happened to sites that aren’t even on WP.
The plot thickens.
Let’s keep each other posted people!
I’m working with my hosts and Securi to try to work this out.
No UTF-8 is the charset you need to set your database to in order for it to display some characters correctly.
UTF-7, which the hack sets it too allows for code to be passed through the DB and isn’t good from a security aspect.
From what i found with my sites, if you go into the Settings—>Reading screen in the WP dashboard BEFORE you delete Badi’s text widget with his script in, then you will see an option to set the charset back to UTF-8.
If you delete the script then that option disappears and I guess you will have to set it through PhpMyAdmin.
The option was taken out of the dashboard in WP 3.5.
This hack seems to reinstate it until you delete the script found in the text widget that is also created upon the hack getting into your site.
Not sure Dev,
I though the protocol on this kind of stuff was to let the core team know at WP with a ‘we’ll put this out in the wild in x days’ kind of thing.
I still don’t know for sure if it’s a server side thing(very widespread across loads of different hosts) or a core WP thing.
I have spoken to a few site owners and can’t see a plugin correlation, so it’s either WP or servers.
Devin, firstly go into settings—> Reading and change the UTF-7 to UTF-8.
Then go into your widgets area. You’ll see an unregistered sidebar witha text widget in it.
Delete it AFTER you set the UTF-8.
This MUST be done first or you will lose access to that option (it is hidden by standard in WP 3.5, this hack must bring it back).
Then change your site title back.
So far, i think that is all you need to do.
No malware or file changes will have taken place, but this is happening more and more.
Badi was on here today and said it was done through server vulnerabilities.
I wish he could just work with us to let us know, so our hosts can fix it.
My livelihood is my WP site, it’s not a hobby for me, it’s my work. I need to know about vulnerabilities.
I hope his conscience brings him to let the WP community know what he is doing here.
Am talking to my hosts and we’re looking through things. Would be way more helpful if Badi could explain whether after the hack, if anything is actually remaining in the site’s files.
I can roll back, but do I really need to.
I wouldn’t expect a full explanation of the hack but people would be a grateful of a general overview of the flaw used to compromise the site.
Even a general pointer.