• Resolved b2kaibecker

    (@b2kaibecker)


    We have attacks from hackers from time to time and Wordfence was a good solution here. Especially because it recognized modifications to files.

    For some time now, there have been attacks on systems that use the Hello theme. This attack is apparently also possible in the current version. The wp-config.php is extended by this area:

    This is clearly recognizable and Wordfence does NOT report any changes to the file. From my point of view, this is very bad and I am considering whether Wordfence is still a solution!

Viewing 1 replies (of 1 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @b2kaibecker,

    Assuming you’ve not disabled any firewall rules, the rules themselves are updating successfully and there aren’t any communication issues between your site and our servers, I would suggest sending a copy of the suspicious code (or files containing it) to samples @ wordfence . com. Just make sure to?remove any database credentials or keys/salts?in any files you send over.

    Issues can sometimes be packaged in a different way to cases seen before by our scans as threats often evolve over time. If you’re able to find and clean files yourself but the issue returns later, it may be recreated by another file somewhere. If there’s another issue our Threat Intelligence team may be able to identify that and recommend the next steps from there.

    Many thanks,
    Peter.

Viewing 1 replies (of 1 total)
  • You must be logged in to reply to this topic.