WordPress 3.3.1 hacked
-
Hello, a few days ago that I started to have problems with a hacker who hack one of my blogs. Began to enter through the images folder and now I’ve seen in the logs that have accessed through the wp-user.php file.
I think the hacker is from Saudi Arabia because it changes my page with a page with text in Arabic and Muslim music.This is what I see in the log:
[00:10:09] root@MyServer [~]# grep myusername report.txt
/home/myusername/public_html/wp-user.php:2:eval (gzinflate(base64_decode[00:18:34] root@MyServer [~]# stat /home/myusername/public_html/wp-user.php
File: `/home/myusername/public_html/wp-user.php’
Size: 23169 Blocks: 48 IO Block: 4096 fichier régulier
Device: 801h/2049d Inode: 26510383 Links: 1
Access: (0644/-rw-r–r–) Uid: ( 658/myusername) Gid: ( 609/myusername)
Access: 2012-02-28 00:17:43.000000000 +0100
Modify: 2012-02-23 21:05:01.000000000 +0100
Change: 2012-02-23 21:05:01.000000000 +0100Please help me to improve the security of my blog.
In the last week has hacked me 4 times.
The other time has enter through a file called al.php who uploadit to the images folder and in the log I found it this:/home/myusername/public_html/images/al.php
[14:37:11] root@MyServer [/home/myusername/public_html/images]# stat /home/myusername/public_html/images/al.php
File: `/home/myusername/public_html/images/al.php’
Size: 23169 Blocks: 48 IO Block: 4096 fichier régulier
Device: 801h/2049d Inode: 26543734 Links: 1
Access: (0644/-rw-r–r–) Uid: ( 658/myusername) Gid: ( 609/myusername)
Access: 2012-02-22 14:35:14.000000000 +0100
Modify: 2012-02-22 00:48:16.000000000 +0100
Change: 2012-02-22 00:48:16.000000000 +0100[22/Feb/2012:00:41:44 +0100] “GET /shakira-pura-energia/ HTTP/1.1” 200 12900 … etc..
Thanks in advance!!
- The topic ‘WordPress 3.3.1 hacked’ is closed to new replies.