Got hacked..
-
Hi folks,
my wp 1.5.1 setup got hacked yesterday. I dont think its a problem with wp, but maybe my setup was bad. (its back to normal now)
I was analyzing the log, and found that the hackers had used this…at the start of the hack. Any idea what it does..?
[Moderated – string removed.]
(it was in hex format, which i decoded).
and then a POST call to /wp-admin/wp-users.php!
and then the person is in..my admin panel!Here is the detail….
—————-
GET /blog/ HTTP/1.0
GET
[Moderated – line removed]
HTTP/1.1
POST /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/wp-admin/users.php?action=promote&id=4&prom=up HTTP/1.1
GET /blog/wp-admin/users.php HTTP/1.1
GET /blog/admin.php HTTP/1.0
GET /blog/ HTTP/1.0
GET /blog/wp-login.php HTTP/1.0
GET /blog/wp-admin/wp-admin.css HTTP/1.0
GET /blog/wp-images/wp-small.png HTTP/1.0
GET /blog/wp-images/fade-butt.png HTTP/1.0
POST /blog/wp-login.php HTTP/1.0
GET /blog/wp-admin/wp-admin.css?version=1.5.1.1 HTTP/1.0
GET /blog/wp-images/header-shadow.png HTTP/1.0
GET /blog/wp-admin/ HTTP/1.0
—————-
after this, they enabled file upload, and loaded some files on the server……..
—————-hope this is useful….in case its a security issue.
btw, the only mistake (big mistake……yieeeeks) i had done was, given 777 on /blog folder so that the sitemap.xml file could be created by the sitemap plugin. (and then i forgot to remove the 777.
the hackers luckly did not make any harm, but only left the following message..
<———————>
Hacked By Status XAdmin, please change this blog, man…you don’t want to get hacked again:))) Ok, nothing is destroyed, I just changed the index, all the database and blog is fine…. Greetz to soooo secure WordPress :)))))
Specail Greetz to: 1dt.w0lf and RST team. and also to https://xtools.org team, and https://antichat.ru Russian Hack always rulez :))
PS: to view the blog just go to /blog/index.php ??
<———————>
- The topic ‘Got hacked..’ is closed to new replies.