Title: sapper6fd's Replies | WordPress.org

---

# sapper6fd

  [  ](https://wordpress.org/support/users/sapper6fd/)

 *   [Profile](https://wordpress.org/support/users/sapper6fd/)
 *   [Topics Started](https://wordpress.org/support/users/sapper6fd/topics/)
 *   [Replies Created](https://wordpress.org/support/users/sapper6fd/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/sapper6fd/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/sapper6fd/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/sapper6fd/engagements/)
 *   [Favorites](https://wordpress.org/support/users/sapper6fd/favorites/)

 Search replies:

## Forum Replies Created

Viewing 6 replies - 1 through 6 (of 6 total)

 *   Forum: [Reviews](https://wordpress.org/support/forum/reviews/)
    In reply to:
   [[WP Mail SMTP by WPForms - The Most Popular SMTP and Email Log Plugin] Horrible Security](https://wordpress.org/support/topic/horrible-security/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [9 years, 1 month ago](https://wordpress.org/support/topic/horrible-security/#post-9059519)
 * Thanks for the tip Vinayy. I’m going to check out Mail Bank right now.
 *   Forum: [Reviews](https://wordpress.org/support/forum/reviews/)
    In reply to:
   [[WP Mail SMTP by WPForms - The Most Popular SMTP and Email Log Plugin] Horrible Security](https://wordpress.org/support/topic/horrible-security/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [9 years, 1 month ago](https://wordpress.org/support/topic/horrible-security/#post-9057911)
 * Oh great! Even better! Why not just put the password on the front page of your
   wordpress site for everyone to see. You might as well.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress cOmpromised](https://wordpress.org/support/topic/wordpress-compromised/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [10 years, 11 months ago](https://wordpress.org/support/topic/wordpress-compromised/#post-6298081)
 * I was able to figure out how they got access to the account.
 * A plugin by the name of **N-Media Contact Form with File Upload** seems to have
   been the entry point. It was locked down so only PDF and ZIP files can be submitted(
   or so I thought). It turns out the plugin is ignoring the settings that determine
   which file types can be uploaded. I was able to upload a phpinfo script and execute
   it without any resistance at all.
 * Two .php scripts were found in the folder where uploaded files are stored. Those
   files then allowed access and the ability for an attacker to upload a backdoor
   giving them root access and full control over the hosting account.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress cOmpromised](https://wordpress.org/support/topic/wordpress-compromised/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [10 years, 11 months ago](https://wordpress.org/support/topic/wordpress-compromised/#post-6298016)
 * I’ve found the malware. Its: spam-seo-suspicious15?web.html.spam-seo.hidden-style.
   001
 * Now to find out how to remove it
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress cOmpromised](https://wordpress.org/support/topic/wordpress-compromised/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [10 years, 11 months ago](https://wordpress.org/support/topic/wordpress-compromised/#post-6297980)
 * The reason I think its the theme is because it comes with a number of plugins–
   quite a few of them. One of which is the Revolution Slider. There have a updates
   for each of the plugins it comes with over the past year, except for the revolution
   slider. When I mentioned above that had found files that had been edited, each
   one of them was in relation to the revolution slider.
 * If it walks like a duck, quacks like a duck, looks like a duck, I tend to call
   it a duck until I can prove otherwise. While it may not be the point of entry,
   disabling that theme (removing it entirely) and replacing it with something else
   will be a good starting point. There are only two other plugins that I use on
   this site. One of which is Wordfence and the other is Google Analytic’s by YOAST.
   Chances are the site was compromised via a plugin. I have a suspicion it wasn’t
   Wordfence or Google Analytic’s by YOAST unless this is a zero day attack.
 * I did quite a bit of wordpress hardening when the site was first setup. Deleting
   unused themes and plug-ins, removing version references, hardening the directories
   via htaccess, changing the name of the /wp-admin folder and so on…. I guess I’ll
   have to look into a number of additional hardening techniques as well.
 *   Forum: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
   
   In reply to: [WordPress cOmpromised](https://wordpress.org/support/topic/wordpress-compromised/)
 *  Thread Starter [sapper6fd](https://wordpress.org/support/users/sapper6fd/)
 * (@sapper6fd)
 * [10 years, 11 months ago](https://wordpress.org/support/topic/wordpress-compromised/#post-6297963)
 * Well I’ve found a backdoor install within my themes folder, and a few php scripts
   within the themes folder which have been edited (although I’m not sure which 
   ones, but the java code that’s found within the site is appearing within certain
   sections of the sites code that’s associated with the theme….
 * Fantastic……
 * I guess i’m off to find a new theme as this one is up to date and it looks like
   that’s how the site was compromised.

Viewing 6 replies - 1 through 6 (of 6 total)