I have a question about website security and dodgy file
-
HI
We have a site, which has been affected by someone changing the index.php file with malicious code and adding 3 dodgy files simple.php and chosen.php and baindex.php
ALL plugins are updated and WordPress is fully up to date.
Has anyone else had this issue and HOW you got on top of it to stop it?
We haven’t had issues for 2 weeks after restoring the website, updating ALL plugins, updating WordPress and no issues since then.
Until today. 3 new files in root directory and index changed
And I’ve installed Wordfence security also so I can monitor what files are accessed and can BLOCK them through Wordfence. But obviously I want to have preventative measures in place BEFORE it occurs, not having to try and fix it AFTER the issue.
So firstly my question is –
- What security plugin do you find best to use for these types of issues?
- I am looking at 2 types – Wordfence and Ithemes
- How can I stop the index.php being edited ?
- And the login.php file how to stop them getting access to this
- I heard that the wp_uploads directory is vulnerable to attackers is that correct ?
- Someone suggested to install a wordpress hardening plugin. But the one I found is OLD AND NOT SUPPORTED. This plugin hides sensitive files such as wp-contents, wp-uploads, etc. with just a toggle of a button. – Is there another plugin someone can suggest for this that is current and has support?
- Could a customer login password be a very poor password and causing this vulnerability?
- My other question is about plugins. As I notice when you have had plugins installed and then remove them (as in totally uninstall them), they still seem to sit in the backend in File Manager under the Plugins directory area but not actually removed. But you cannot see them in the WordPress admin Plugins list activated or deactivated as they have been removed. But they still sit when I look under File Manager on the hosting they are there under Plugins. Therefore can these old plugins that have already been removed, but sitting in here, can they cause a vulnerability? Does that make sense?
As all our plugins and wordpress is completely up to date it is hard to figure it out where the vulnerability is on the site.
Very frustrating. I’m at a loss at this stage.
I’ve fixed it again now until next time.
Thanks
- The topic ‘I have a question about website security and dodgy file’ is closed to new replies.