Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

All my Wordpress sites got HACKED

General questions about VestaCP
Locked
  • Print view
Advanced search
14 posts
  • 1
  • 2
  • Next
cagatay
Posts: 119
Joined: Wed May 28, 2014 6:40 am

All my Wordpress sites got HACKED

Post by cagatay » Fri Feb 06, 2015 10:25 pm

Anyone experiencing mass wordpress hack?
Top

Rodrigo
Posts: 11
Joined: Sat Sep 20, 2014 12:30 pm

Re: All my Wordpress sites got HACKED

Post by Rodrigo » Sat Feb 07, 2015 12:06 am

What Wordpress version do you use?
Top

cagatay
Posts: 119
Joined: Wed May 28, 2014 6:40 am

Re: All my Wordpress sites got HACKED

Post by cagatay » Sat Feb 07, 2015 12:30 am

I always use the latest version. I am not sure if it is vesta or wordpress related. I just wanted to keep you guys informed. Be careful these days.


viewtopic.php?f=10&t=6980 makes me think, if I received a shell script or something...
Top

ZipperZapper
Posts: 13
Joined: Fri Feb 06, 2015 11:37 am

Re: All my Wordpress sites got HACKED

Post by ZipperZapper » Sat Feb 07, 2015 11:19 am

I had this once. Wordpress is under heavy attack all the time.

I would strongly reccomend to follow all these steps: http://codex.wordpress.org/Hardening_WordPress . But keep in mind: putting wp-config one folder higher as they say, doesn't work anymore if you use apache basedir and nginx hosting as reccomended in the other topic you name.

Next to that, I can advise to install Clef-login and BruteProtect for Wordpress. They reduce the danger.

Last, I can recommend CloudFlare. Not only does it provide a speed boost for your websites, but it also keeps DDos attacks and known threaths from your websites.
Top

cagatay
Posts: 119
Joined: Wed May 28, 2014 6:40 am

Re: All my Wordpress sites got HACKED

Post by cagatay » Sat Feb 07, 2015 11:40 am

ZipperZapper wrote:I had this once. Wordpress is under heavy attack all the time.

I would strongly reccomend to follow all these steps: http://codex.wordpress.org/Hardening_WordPress . But keep in mind: putting wp-config one folder higher as they say, doesn't work anymore if you use apache basedir and nginx hosting as reccomended in the other topic you name.

Next to that, I can advise to install Clef-login and BruteProtect for Wordpress. They reduce the danger.

Last, I can recommend CloudFlare. Not only does it provide a speed boost for your websites, but it also keeps DDos attacks and known threaths from your websites.
thank you but all sites were using cloudflare. i will keep this topic informed.
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: All my Wordpress sites got HACKED

Post by mehargags » Sat Feb 07, 2015 3:24 pm

cagatay wrote: thank you but all sites were using cloudflare. i will keep this topic informed.
how does that protect your base server ? how do you ensure someone is not breaching your server, through SSH/MySQL/HTTP or any other vulnerabilities. Security is a process...not a product!
Top

cagatay
Posts: 119
Joined: Wed May 28, 2014 6:40 am

Re: All my Wordpress sites got HACKED

Post by cagatay » Sat Feb 07, 2015 4:42 pm

mehargags wrote:
cagatay wrote: thank you but all sites were using cloudflare. i will keep this topic informed.
how does that protect your base server ? how do you ensure someone is not breaching your server, through SSH/MySQL/HTTP or any other vulnerabilities. Security is a process...not a product!
hey idiot, did I ever say I am protected by cloudflare? he asked me if I use cloudflare, I said yes I do.
Top

joem
Posts: 378
Joined: Thu Nov 13, 2014 8:33 am

Os: CentOS 6x
Web: nginx + php-fpm
Re: All my Wordpress sites got HACKED

Post by joem » Sat Feb 07, 2015 6:13 pm

Do all your wordpress use the same database or a different one?
Top

cagatay
Posts: 119
Joined: Wed May 28, 2014 6:40 am

Re: All my Wordpress sites got HACKED

Post by cagatay » Sat Feb 07, 2015 6:31 pm

joem wrote:Do all your wordpress use the same database or a different one?
All use different database and some sites has their own vesta username. I assume he got himself a shell access.

I am considering a safer paid panel solution. Using unmature panel for business is too risky for me.
Top

sin
Posts: 1
Joined: Sat Feb 07, 2015 11:30 pm

Re: All my Wordpress sites got HACKED

Post by sin » Sat Feb 07, 2015 11:34 pm

cagatay wrote:
joem wrote:Do all your wordpress use the same database or a different one?
All use different database and some sites has their own vesta username. I assume he got himself a shell access.

I am considering a safer paid panel solution. Using unmature panel for business is too risky for me.
What does using VestaCP have anything to do with it? You don't even know how your Wordpress sites were hacked, you assumed they got shell access well what do your logs says?
Top


Locked
  • Print view

14 posts
  • 1
  • 2
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password