• Resolved joeblow

    (@avenuebeads)


    First if this isn’t the correct area to post this I apologize.

    So I got hacked this weekend and I’m having an issue figuring out where to locate the changed files. Or how they got in.

    Using latest wordpress/woocommerce. all plugins up to date. Very strong password. So it had to be brute force.

    Quttera internal scan shows the only two suspicious files are in my error logs. Threat name: Heur.AlienFile.gen
    False postive?

    Looked in my themes files. htaccess and all the usual suspects and see no odd code. I’m using the udraft plugin and it has a bunch of stuff in my htaccess file. so maybe something was snuck in there that im not noticing?

    Not hugely familiar with databases but I combed through that but didn’t see anything either.

    Help?

    The page I need help with: [log in to see the link]

Viewing 6 replies - 1 through 6 (of 6 total)
  • Moderator t-p

    (@t-p)

    Carefully follow this guide.

    When you’re done, you may want to implement some (if not all) of the recommended security measures and start backing up your site.

    Thread Starter joeblow

    (@avenuebeads)

    All internal malware scans return zero results.

    I’ve compared fresh files with current ones using the usual culprit injecting files (head,footer,index. wp-config, theme files, etc) all are clean.

    htaccess looks normal to me.

    modified dates on files don’t show anything being changed in the last month.

    Admin page(s) don’t redirect, all public facing pages do.

    I didn’t have a recent files back up (I should know better) but I did refresh my database with a back up that should have been several days/week before the hack happened.

    Is it possible this is a host hack? The page will fully load and then it gets redirected.

    • This reply was modified 7 years, 1 month ago by joeblow.
    Moderator t-p

    (@t-p)

    Is it possible this is a host hack?

    Please ask at your hosting provider’s support.

    Thread Starter joeblow

    (@avenuebeads)

    Found the culprit! whew! It was the Blog Designer plugin I was using that got hacked. All fixed.

    Moderator t-p

    (@t-p)

    Glad its sorted 🙂

    Moderator t-p

    (@t-p)

    wanted to improve plugin detection capabilities thus others victims of such infection won’t spend days to find it.

    Appreciate your concerned.

    But, as @jdembowski indicated above, posting of infection samples is not allowed in these forums.

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘Hacked redirect issue’ is closed to new replies.