• Resolved stathis_k91

    (@stathis_k91)


    Hi,

    ninjafirewall send me the

    >>Alert: File Guard detection
    >>Someone accessed a script that was modified or created less than 2 hour(s) ago

    I have problem in this site and i discovered with ninjafirewall (thanks for that),

    in this alert i found a script in a file called “headers” in wp-admin and modified the index.php to access the “headers”,

    How the ninjafirewall can block the hacker to modified my site, not only alert me?

    Thanks,
    Stathis

    https://ww.wp.xz.cn/plugins/ninjafirewall/

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Author nintechnet

    (@nintechnet)

    Hi,

    The File Guard alert displays the date and time.
    Can you check in the firewall log if something happened at that time?
    Then, you will need to check the HTTP server log too. It will definitely show the attacker action at that time.
    If it does not show anything, check your FTP log as the hacker could upload from FTP as well.

    Thread Starter stathis_k91

    (@stathis_k91)

    Hi,

    strange things happened in the log file but i can’t understand,
    i started a scan in my account and i found a malicious file that goes quarantined,
    i also change the ftp password with a stronger,

    Thanks,
    Stathis

    Plugin Author nintechnet

    (@nintechnet)

    Hi,

    Ensure you enabled “File Check” to run hourly too, so that it will detect any changes to your files.
    You may have a backdoor on your site.

    Thread Starter stathis_k91

    (@stathis_k91)

    Hi,

    maybe the backdoor is the file i found: wp-xmlrpc.php

    i will make some scans,

    Thanks,
    Stathis

    Plugin Author nintechnet

    (@nintechnet)

    Hi,

    Probably, but if you are unsure, you can post the file to http://pastebin.com/ and give us the link.

    Thread Starter stathis_k91

    (@stathis_k91)

    Hi,

    i have the file but it can’t open because blocked of my antivirus,

    notepad can’t opened too, not even ziped,

    any suggestions to give you the file?

    Thanks,
    Stathis

    Plugin Author nintechnet

    (@nintechnet)

    Hi,

    Maybe you can try to rename it to wp-xmlrpc.txt, but I don’t know if that will work.

    Thread Starter stathis_k91

    (@stathis_k91)

    Hi,

    i think must open to rename, my notepad can’t open the file,

    it is for sure a malicious file, i found it in the wp-includes directory,

    i googled for backdoor and returned that the wp-includes directory is an often place for backdoors and the files often named similar to wordpress files,

    Thanks
    Stathis

    Plugin Author nintechnet

    (@nintechnet)

    Hi,

    There is an option in NinjaFirewall to block access to PHP files in the /wp-includes/ folder (“Firewall Policies > Block direct access to any PHP file located in one of these directories”).

    Thread Starter stathis_k91

    (@stathis_k91)

    Hi,

    yes, it is already checked, i feel that with ninjafirewall my site is safe,

    you have great support,

    Thanks,
    Stathis

Viewing 10 replies - 1 through 10 (of 10 total)

The topic ‘File Guard alert’ is closed to new replies.