Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter langknow

    (@langknow)

    No, but for some reason I received an email from namecheap after trying to clone the website:

    From: [email protected] [mailto:[email protected]]
    Sent: 20 March 2013 01:01
    To: [email protected]
    Cc: [email protected]
    Subject: Attention: Malicious Attempt to Access Your Hosting Account
    “mywebsite” is Detected

    Dear Hosting Account ‘mywebsite’ Owner,

    This is an automated alert to inform you that we have detected a malicious
    attempt to access your account via http or ftp on our server
    ‘host16.registrar-servers.com’.
    Our security systems have blocked the upload of malicious file to the server
    and put it to the quarantine. Your website is safe now, but it is important
    you undertake the following precautions.

    1. Immediately scan your PC for viruses and malware. We recommend the
    anti-virus programs which free editions are available
    for most operating systems for this purpose.

    2. Make sure that you use strong, hard-to-guess passwords on your account
    and applications. Do not use the same password for
    different applications. To remember more difficult passwords, we
    recommend you use the password managers such as LastPass or RoboForm.

    3. Update all third party scripts to the latest versions (e.g. Joomla,
    WordPress, Magentoo or any other CMS). Remove every script, gadget,
    feature, function, and code snippet which has poor security
    vulnerability report.

    4. Enable CloudFlare in cPanel. It is designed to provide protection from
    many forms of malicious activity.

    5. Use .htaccess or cPanel > Deny IP to block the hacker’s HTTP access to
    your site. If you identified the hacker’s IP address, one site where you
    can look it up to get more information about this IP is
    http://whois.domaintools.com/ .

    6. Change your cPanel/ftp passwords.

    We have put the following content into quarantine as we believe it contains
    viruses or other malicious code. If you feel this has been in error and your
    file is false-positive (innocent), please submit a ticket to us at
    https://support.namecheap.com/index.php?/Tickets/Submit or contact the Live
    Help at http://www.namecheap.com/support/livesupport.aspx and we will be
    happy to assist:

    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/2013-03-20-00-14-22_why-take-fish-oil-su/wp-conte
    nt/plugins/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/2013-03-20-00-14-22_why-take-fish-oil-su/wp-conte
    nt/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/themes/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /plugins/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/page.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/footer.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/thesis_18/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/footer.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/page.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /plugins/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/page.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/thesis_18/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/footer.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/panorama/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/footer.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/index.php
    ‘[PHP Exploited Script [P0193]]’:
    /home/mywebsite/public_html/wp-content/wpclone-temp/wpclone_backup/wp-content
    /themes/twentyten/page.php

    Thread Starter langknow

    (@langknow)

    Hey, no it shouldn’t be. The new wordpress site is a new installation..

Viewing 2 replies - 1 through 2 (of 2 total)