Forum Replies Created

Viewing 15 replies - 1 through 15 (of 29 total)
  • Thread Starter ANTi-CAP

    (@anti-cap)

    I do understand what you are saying. I will look further into the server security but it seems a bit odd that it happened after this install and only that domain and sub domains of it were affected, why not take the whole server?? Why is nobody else reporting defacements or hacks from the other accounts that did not have WP installed??

    There is no doubt WP has been an easy target for hackers/skiddies for years… you seem to miss the point of even your official code containing dubious comments etc…

    I do want to use WP for one site but not when it causes this, which I truly believe it did as we have had no problems on the server for a very very long time. If I get the time I will work out how they done it and come back to prove you wrong.

    I don’t blame WP for anything but think sec is low on your priority list and use many other scripts that are patched much faster.

    Either way as I said at the start this is just a heads up. It happened and I honestly beg to differ that it was a server sec issue.

    You seem to try and deny it but hoards of WP sites get pwned simultaneously. I have been around and seen it happen. I can drag up the articles and zone-h records if you like??

    Either way I’m going leave now as I’m getting slightly angry with you.

    If I find the exploit I will post it publicly to prove the point.

    I take security seriously hence my post and if it had not been the festive season this would of just cost me a very profitable money site to be down for 10-12 hours.

    Peace <3

    Thread Starter ANTi-CAP

    (@anti-cap)

    Sorry but I feel like you are twisting my words. Or possibly I’m not wording things correctly. It happened within a 12 hour period of installing it while I was sleeping. If it was already in the script you guys had better check your download of it as I got it directly from here.

    After reading this though it wouldn’t surprise me: http://www.eweek.com/enterprise-apps/wordpress-with-release-4.1-aims-to-be-distraction-free.html
    ‘One of the most interesting minor fixes in WordPress 4.1 corrects what is labeled by WordPress developers as a “suspicious comment” in a piece of WordPress’ php code. The class.smtp.php file had a comment in it that stated “hacked by Lance Rushing.”‘

    I do however fully disagree with your comment of “It was not WP” when it clearly was.

    I feel I am coming across as slightly aggressive and if I am I apologise. I am just annoyed as I had some good plans for the site and there is no other blogging software that has what I need to build the website I planned. Luckily it was a fun site not a money site.

    The server is secure. It does have other accounts and scripts on it BUT as I keep saying the shell script came about via my WP install that had no plugins or themes installed at the time.

    And no I fully understand. I also have a similar time frame of knowledge, probably in slightly different fields but am pretty fluent in PHP/JS/HTML/CSS/MySQL, a bit of ethical hacking and started building mobile chat sites before I even had a decent internet connection (some of which are still up on hotscripts I believe).

    Maybe I should go through the logs and work out what exactly the exploit was and on what file but I don’t feel it’s my job in all honesty and have many other paid jobs to be getting on with.

    I would love to use WP for the site I had planned, but I can’t compromise the other sites on the server again without getting to the bottom of this :-/

    Thread Starter ANTi-CAP

    (@anti-cap)

    It happened directly after installing WP 4.1. Deny this as much as you like but that is how they got the shell script into the account. Yes some other domains that were sub/addon domains on the same WHM account were affected but none under different accounts on the server.

    The domain in question had been empty for some time with a few active addon domains on the account while I made plans for the WP site (that was not yet installed) I was planning to build there.

    Sorry but there is no doubt that if I had not installed WP this would not of happened IMO. My server provider is fine as is the general security on it.

    Sorry root kit was the wrong term. Shell script.

    http://s17.postimg.org/cl0g9phov/PHP_Webshell_H.png <– PHP/Webshell.H

    They got that shell script up via the WP install, nothing else.

    Thread Starter ANTi-CAP

    (@anti-cap)

    I was referring to soaksoak, not to mention the hundreds of WP sites I have seen defaced over the years.. third party plugins or not you should have some type of vetting process for the code you allow to be hosted on your website, especially when your target audience are in general not tech savvy and can install plugins from the back end of their websites.

    Defaced as in they used a root kit to wipe files and upload a quite funky anti-gov message/image/swf (with music) that I actually agree with (I went to speak with them afterwards briefly but their English is not so great).

    http://s16.postimg.org/qelvmcskl/Screenshot_38.png <– IMAGE

    No the sever is pretty solid, no past hacks or defaced sites (until a matter of hours after putting the first ever vanilla WP install on it). I’m guessing they recently found the exploit and just dorked WP sites as I had no time to remove the mass amount of footprints in the install. They have done at least 4/5 WP4.1 sites I know of today, you can check on hacking archives such as zone-h.

    I would expect more “I’ve been hacked” threads shortly TBH.

    No I didn’t even bother trying to identify the exploit as it clearly came from the WP install (with no plugins/themes) but could check it out I guess, though I feel it a waste of my time as I don’t plan on using WP again unfortunately, despite it’s good points.

    Sorry to be a bit of a grump but WP is just an easy target. I have been building websites for well over ten years and never seen any free/paid open source script get owned as much. Apologies for my lack of quoting also I’m not used to this forum software.

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    Removed…. thanks for the heads up.

    Regards,
    ANTi-CAP

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    Ah ha!!! It’s Awsome screenshot. It just done it again.. sly…

    Regards,
    ANTi-CAP

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    Issue resolved. Please see edit above. Sorry for wasting your time.

    Regards,
    ANTi-CAP

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    Mmmm. It seems so, I just tried with chrome (with adblock turned off) and don’t see the adverts.

    I use FF but have adblock disabled for my site.

    EDIT: Issue resolved. Somehow a sneaky addon called ffShopper was added to my FF… strange. Sorry for the time waste, but those are the same adverts shown via WordAds on WP.COM hostsed sites.

    Regards,
    ANTi-CAP

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    Yes home page, and many other pages.

    I’m not sure how you can’t see the adverts from the screen shots though they are clear as day?

    http://s27.postimg.org/3tay9uf37/homepage.png

    Regards,
    ANTi-CAP

    Forum: Everything else WordPress
    In reply to: WordAds??
    Thread Starter ANTi-CAP

    (@anti-cap)

    They are adverts applied to wordpress.com hosted websites with high traffic and an application as far as I can gather.. here are some screen shots. I’m running an alpha version of 4.1, self hosted and they appeared on my site just today:

    http://s3.postimg.org/nntl17veb/WA1.png

    http://s11.postimg.org/9uim82wdv/WA2.png

    Regards,
    ANTi-CAP

    I sadly had the same issue. I will try this later thanks 🙂

    Thread Starter ANTi-CAP

    (@anti-cap)

    Okay,

    Just I run quite a few websites (non WP) seems you guys are the easiest target. It’s a bit odd to happen on a week old test site Most of the IP’s were Chinese. WP sites are to easy to find (dork) hence all the attacks on high ranking sites IMO.

    I’m preferring v4.1 though but think you guys should implement security measures as standard rather than leaving it to plugin DEV’s.

    I resolved the issues myself anyway. Fire with Fire.

    Regards,
    ANTi-CAP

    Thread Starter ANTi-CAP

    (@anti-cap)

    Hi Tim,

    No thank you for such a great plugin. I have done what you suggested and all seems good now. There was already a scan in progress but from the code below all seems good.

    [Sep 08 15:50:33] Blocking fake Googlebot at IP 200.137.2.254
    [Sep 08 20:55:23] Scheduled Wordfence scan starting at Monday 8th of September 2014 08:55:23 PM
    [Sep 08 21:10:09] Blocking fake Googlebot at IP 79.6.131.204
    [Sep 08 21:15:24] Scanning comment with Source IP: 216.107.145.9
    [Sep 08 21:15:24] Checking 2 host keys against Wordfence scanning servers.
    [Sep 08 21:15:24] Done host key check.
    [Sep 08 21:15:24] Scanned comment with Source IP: 216.107.145.9

    I was actually so impressed with your plugin after trying another that caused major problems I done you a mini review and link back here.

    Regards,
    ANTi-CAP

    Hi Tim,

    I’m flat out working right now. I will do this later if I get time and the issue has not resolved it’s self, as I’m sure the issue is your end.

    Regards,
    ANTi-CAP

    Sorry,

    On a google search of the error this looked like the best out of three places to post.

    Regards,
    ANTi-CAP

Viewing 15 replies - 1 through 15 (of 29 total)