• Resolved mistral7-wporg

    (@mistral7-wporg)


    I had to restore my site in total following a persistent hacking, uploaded files from my computer and included a carefully checked short list of plugins and themes(2) from the downloaded/renamed wp-content.

    I seem to have lost my super-admin user listing. As a consequence I cannot apply or add to plugins or make other global changes.

    Reading the hacking notes on the forum, I really need to get that access up and running.

    I checked the .htaccess file and it contained:

    # BEGIN WordPress
    <IfModule mod_rewrite.c>

    RewriteEngine On
    RewriteBase /
    RewriteCond %{REQUEST_URI} !^/[0-9]+\..+\.cpaneldcv$
    RewriteCond %{REQUEST_URI} !^/[A-F0-9]{32}\.txt(?:\ Comodo\ DCV)?$
    RewriteRule ^index\.php$ – [L]

    # uploaded files
    RewriteCond %{REQUEST_URI} !^/[0-9]+\..+\.cpaneldcv$
    RewriteCond %{REQUEST_URI} !^/[A-F0-9]{32}\.txt(?:\ Comodo\ DCV)?$
    RewriteRule ^files/(.+) wp-includes/ms-files.php?file=$1 [L]

    RewriteCond %{REQUEST_FILENAME} -f [OR]
    RewriteCond %{REQUEST_FILENAME} -d
    RewriteCond %{REQUEST_URI} !^/[0-9]+\..+\.cpaneldcv$
    RewriteCond %{REQUEST_URI} !^/[A-F0-9]{32}\.txt(?:\ Comodo\ DCV)?$
    RewriteRule ^ – [L]
    RewriteCond %{REQUEST_URI} !^/[0-9]+\..+\.cpaneldcv$
    RewriteCond %{REQUEST_URI} !^/[A-F0-9]{32}\.txt(?:\ Comodo\ DCV)?$
    RewriteRule . index.php [L]
    </IfModule>

    # END WordPress

    I changed that to the list provided in codex –

    # BEGIN WordPress
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ – [L]

    # uploaded files
    RewriteRule ^([_0-9a-zA-Z-]+/)?files/(.+) wp-includes/ms-files.php?file=$2 [L]

    # add a trailing slash to /wp-admin
    RewriteRule ^([_0-9a-zA-Z-]+/)?wp-admin$ $1wp-admin/ [R=301,L]

    RewriteCond %{REQUEST_FILENAME} -f [OR]
    RewriteCond %{REQUEST_FILENAME} -d
    RewriteRule ^ – [L]
    RewriteRule ^[_0-9a-zA-Z-]+/(wp-(content|admin|includes).*) $1 [L]
    RewriteRule ^[_0-9a-zA-Z-]+/(.*\.php)$ $1 [L]
    RewriteRule . index.php [L]
    # END WordPress

    Not sure if that is correct bu the previous .htaccess info included references to cpanel which makes me nervous.

    Shall continue to read and try to find a solution, but if there is someone who can help me restore super-admin I would be very grateful.

Viewing 2 replies - 1 through 2 (of 2 total)
  • Well, did you restore the database from a backup? Users are stored in the database.

    Thread Starter mistral7-wporg

    (@mistral7-wporg)

    Hi nnikolov, resolved the problem when I removed a well-disguised “foreign” file. Our hacker excuses for human beings had been busy.
    Site now stable, thank you.

    Regards
    Ken

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘super admin lost’ is closed to new replies.