Hack affecting WordPress login
-
For the past week, I’ve been fighting some kind of hack of a WP site. The symptoms include:
– Site appears to run normally for visitors
– A file named “whois.dat” is in the root directory where WP is installed. This file consists of JS and HTML that includes a lot of links to e-commerce site for medical related products.
– Any administrative page past the login page comes up blank. When trying to view-source of the blank page, there’s zero HTML or PHP code displayed.
– I’ve been unable to find any evidence that any of the files in the WP site have been compromised.To restore the site, I’ve been forced to complete remove all the files and re-install WP from scratch. Once I’ve done that, I can get to the admin page and reinstall plugins, theme, etc. But after doing that the first time, it was only a couple of days before I found the site compromised again with the same symptoms.
Any suggestions on what might be going on here and how to better lock down the site to keep this from happening again?
- The topic ‘Hack affecting WordPress login’ is closed to new replies.