Username/pw are being changed, not brute forced
-
I’ve been using Wordfence for about a month after multiple takeovers of my website. Over the course of troubleshooting I’ve deleted plugins, old themes, hardened WordPress with .htaccess, scanned all my website files with anti-virus, disabled FTP access, reset WP salt in wp-config, and more.
Every time attackers somehow manage to change the username to “admin” and a password to one of their choosing. There’s no notification from Wordfence, meaning they are managing to change the username and password without logging in to the WP site. I usually catch them before they login to WP, and I reset the password from phpMyAdmin. After I restore access, I scan the site with WF and come up clean.
Today I received a WF notification because an attacker actually used the admin login. They deleted the WF plugin and installed a malicious plugin called “File Manager.” They also used a malicious php file called “resetcp.php” to reset the password, but I’ve never found a file like that before.
The site is currently running WP 5.1.1, WF 7.2.4, Imsanity 2.4.2, Annual Archive 1.5.3 and Akismet 4.1.1. The only theme is Twenty Nineteen.
I’m in the process of backing up my posts so that I can completely erase public_html and start with a new WP install. Other than that, is there anything else I can try to protect my site?
- The topic ‘Username/pw are being changed, not brute forced’ is closed to new replies.