changed files in BPS 51.7
-
5/3/15 11:30 I just did a scan of my files against the respository and found many bps files changed from the respository files. I have put them back to the repository version.
I am also having problems with the File Manager on my cPanel showing file permissions on a lot of files in my root install at 755 instead of 644 on core wordpress files and some plugins on my root WP install. As far as I know there is no reason for most WP files of any kind to need 755. The same files on other of my WP installs are at 644.
I suspect a cPanel hack but can’t prove it. And I suspect there is some injection into a transient on my main site because I am getting phantom folders showing up in webmaster tools. The first time it was fdx-index folder. So I 410 it and now there is another folder named fdx-contact showing 404 in Webmaster tools. These folders are linked from the same one page and 3 urls + main ip. I have checked the pages with unmask parasites and it shows no errors. I have also checked with their pharma links and none of them show up in Google.
Sucuri shows no issues with the site. Unmask parasites shows no issues.
I doubt using BPS trouble shooting will show any thing hidden in a transient. But since two different phantom folders show up linked to the same page and 4 urls, it makes me think there is a buried hack in there somewhere.
Here is what a Google search reveals
FedEx Ground? Services – fedex.com?
Adwww.fedex.com/?Reliable and Economical Delivery. Get Rates and Transit Times Online.
Search Results
*WP Mobile Edition (Contact) | Fly Fishing Colorado
https://www.fly-fishing-colorado.com/fdx-contact/*WP Mobile Edition (Contact). This page is required for plugin WP Mobile Edition. Search. Shopping Cart. There are no items in your cart. Browse Products ? …
WP mobile edition was a mobile plugin I tried.
Here is what a vulnerability database has
7898 2015-04-14 WP Mobile Edition <= 2.7 – Remote File DisclosureCurrent version I found in the repository is 2.3 if this is the same plugin as the vulnerability database.
I have think I tried a PHPmyAdmin scan for wp mobile edition and nothing showed up. But will try again.
- The topic ‘changed files in BPS 51.7’ is closed to new replies.