Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 44

Thread: Help find hole

  1. #21
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    Quote Originally Posted by Rarst View Post
    What is second URL? Not either of my hosts.
    Thats your host isnt it ? The WP stuff is a marketing front.
    John Myrstad

  2. #22
    Kim's Avatar
    Kim
    Kim is offline Hello World
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    61

    Default

    @Rarst: You need to install the Post Logger plugin: http://www.village-idiot.org/archive...for-wordpress/

    It records every usage of the $POST variable, from comments to admin logins to creating/editing posts and pages, and will give you more info on who they are and how they're getting in than simple Apache logs.

    I've got it running on every WP install I have to help track down issues if I'm ever hacked.

  3. #23
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    @JohnM

    Nope, their parent company is http://exabytes.com/

    @Kim

    Thank you! Wish I had it in place for second attempt.

    At moment I am waiting for reply from support/security... So I have no blog to install it on. :) Maybe they will roll back database delete, or I'll just restore from backup (might lose some comments and such made in last day).
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  4. #24
    Len's Avatar
    Len
    Len is offline Big Tipper
    Join Date
    Jan 2009
    Location
    Winnipeg, MB Canada
    Posts
    376

    Default

    Rarst,

    You may also want to contact Whoo, the owner of the site linked to by Kim. When it comes to security issues there are few better than Whoo.

  5. #25
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    Quote Originally Posted by Rarst View Post
    @JohnM

    Nope, their parent company is http://exabytes.com/
    http://www.google.com/safebrowsing/d...site=rarst.net

    The fax number used to register the hosting domain does not have a good reputation.
    John Myrstad

  6. #26
    Kim's Avatar
    Kim
    Kim is offline Hello World
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    61

    Default

    @Rarst: When you do install it, set up the logs folder outside of the public_html folder, i.e. at the same level as public_html:

    Account root/
    wp-logs/
    public_html/

    I usually check the logs weekly, back up a copy locally, then empty the logfile.txt file to record the next week's events.

    You can exclude certain IP numbers from being recorded (like your's) but I'd recommend not doing that right now until you get these problems cleared up.

    Question: How were they able to delete your database? Are you using a database manager plugin inside WordPress? If not, then it sounds like they've got access to your hosting control panel as well.

  7. #27
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    @Len

    Thanks for suggestion, had mailed him. Also sent mail to dd of sucuri.net on suggestion of Daniel Scocco.

    Only issue - I won't be able to properly hire either if they ask for it - retarded country issues that lock me out of PayPal and such. :( Make payments online close to impossible.

    @JohnM

    You mean their domain or my domain? Mine is registered with biggest local company, as legit as it get around here.

    As for them I try to keep my opinion balanced. It might as well turn out to be completely my issue. So until proven guilty... Even if very suspicious. :)
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  8. #28
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Quote Originally Posted by Kim View Post
    @Rarst: When you do install it, set up the logs folder outside of the public_html folder, i.e. at the same level as public_html:

    Account root/
    wp-logs/
    public_html/

    I usually check the logs weekly, back up a copy locally, then empty the logfile.txt file to record the next week's events.

    You can exclude certain IP numbers from being recorded (like your's) but I'd recommend not doing that right now until you get these problems cleared up.

    Question: How were they able to delete your database? Are you using a database manager plugin inside WordPress? If not, then it sounds like they've got access to your hosting control panel as well.
    I have no idea on database. I logged new attempt to get WP admin access blocked... And some time later database is gone, absolutely nothing related in HTTP log.

    I see no reason to go after WP with cpanel access, you have cpanel you own site.

    And you don't just get into cpanel, just like you don't just get into WP. :(

    [Update] As far as I remember I logged in into cpanel before hack today and it shows my IP as "Last login from", so I think it wasn't accessed.
    Last edited by Rarst; 09-01-2009 at 03:06 PM.
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

  9. #29
    JohnM's Avatar
    JohnM is offline Big Tipper
    Join Date
    Feb 2009
    Location
    Norway
    Posts
    346

    Default

    If you checked the link you would see that your domain is hosted on wehostesitescom.
    The wehostsitescom domain is registered using a fax number that is associated with fishy stuff, so I guess its not the best of hosts.
    John Myrstad

  10. #30
    Rarst's Avatar
    Rarst is offline Big Tipper
    Join Date
    Jul 2009
    Posts
    322

    Default

    Quote Originally Posted by JohnM View Post
    If you checked the link you would see that your domain is hosted on wehostesitescom.
    The wehostsitescom domain is registered using a fax number that is associated with fishy stuff, so I guess its not the best of hosts.
    Sorry, I missed where you made jump from zone name to that site. Now I see it.

    As I understand that company is not exactly hosting company? I am not good with this stuff and don't know what exactly "network operator" means, as they call themselves.

    Still no reply from support/security. Getting late here.
    Rarst.net - cynical thoughts on software and web (and sometimes WP) | @Rarst | I seem to be non-GPL-compliant person. Beware my poisonous thoughts.

Page 3 of 5 FirstFirst 12345 LastLast

LinkBacks (?)

  1. 08-29-2009, 01:03 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •