StudioPress Community Forums
  StudioPress Community Forums > Forums > General Discussion
For help and support, access to your downloads, or to manage your account please log into My StudioPress.

These forums have been set to read-only so you can browse the existing topics for any questions you may have -- and this forum will be removed on July 1st, 2013.

For general discussion on WordPress, CSS and design (NOT for support) visit the new Community Forums.
 
 
Thread Tools Display Modes
  #1  
Old 08-16-2010, 04:00 PM
adi adi is offline
Registered User
Pro Plus Member
 
Join Date: Jul 2010
Posts: 29
Default WP Security Problem: MySQL Injection Schema, Dataext, and fuzzer

Hi,

I noticed a s.py file in the website ftp.

Some kind of script called MySQL Injection Schema, Dataext, and fuzzer.

I also found a picture of some dumbass from Asia.

It's very frustrating being hacked.

Do you know what I should do about that? Anyone experienced that before?

Thanks
Adri
  #2  
Old 08-16-2010, 04:03 PM
violet's Avatar
violet violet is offline
Community Leader
 
Join Date: Oct 2008
Posts: 2,247
Default

You have been the victim of an injection attack unfortunately.

You need to go thru your site, every directory, and look for suspect files. There are usually several rogue files that they install. They will usually have a php extension. They especially like to hide files in your uploads directory.

You should also reinstall WordPress being careful to follow directions on wordpress.org so you don't delete files you don't want to delete.

Make sure you keep your WordPress install up to date and your plugins as well.
__________________
wpfab.com
WordPress Specialist •Genesis Developer • StudioPress Theme Customizer

Please don't PM or email me with support questions.
  #3  
Old 08-16-2010, 04:09 PM
adi adi is offline
Registered User
Pro Plus Member
 
Join Date: Jul 2010
Posts: 29
Default

Hi Violet,

Thank you for a very fast response.

The attack was done on a add-on domain. Should I verify every directory including other add-on domains and the main one?

Also, can you direct me to trusted sources on how to reinforce security on wordpress.

I actually deleted the whole wordpress installation, database, the domain, everything.

This was a dormant domain with a old wordpress running another framework (NOT genesis).

Adi

Genesis Rocks
  #4  
Old 08-17-2010, 08:05 AM
violet's Avatar
violet violet is offline
Community Leader
 
Join Date: Oct 2008
Posts: 2,247
Default

Check every directory.

Google "secure wordpress" and you'll find several resources. There are lots of steps you can take.

Good luck!
__________________
wpfab.com
WordPress Specialist •Genesis Developer • StudioPress Theme Customizer

Please don't PM or email me with support questions.
  #5  
Old 08-17-2010, 04:29 PM
adi adi is offline
Registered User
Pro Plus Member
 
Join Date: Jul 2010
Posts: 29
Default

Thank you

I'll work on it.

Adi
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Allure theme security problem- help needed DCE2007 General Discussion 1 10-25-2010 05:27 PM
WordPress Injection Attack Prevention Tips jaffery12 General Discussion 9 03-15-2010 10:42 PM
MySQL database name problem netup General Discussion 5 12-16-2008 06:31 AM
Mysql 4 or 5 ? javajoba General Discussion 2 12-10-2008 03:41 PM


All times are GMT -5. The time now is 03:31 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.