|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
|
Free Wordpress EXPLOIT remove utility here
Well my wordpress blogs were infected by some sort of exploit that allows hacker write files to my server and redirect traffic. It's really recommend to check your server for this shit+ upgrade to WP 2.51 asp! Here is handy tool I made to detect infected files + mysql database rows and remove this shit.
1) download tool here: http://64.15.156.39/remove_exploit.zip 2) download remove_exploit.zip -> unzip -> upload to your server 3) edit remove_exploit.php configuration part 4) login to your server via ssh 5) chdir to location where remove_exploit.php is located 5) run the tool: php remove_exploit.php notice: you must be logged as user who has rights to the files ('root' will work for sure) WARNING: USE THIS TOOL ON YOUR OWN RISK ![]() |
|
|
|
|
|
#2 |
|
i have man boobies
Join Date: Jul 2003
Location: van down by the river
Posts: 13,082
|
Liar!!!!!!!!!!!!!
__________________
333-765-551 |
|
|
|
|
|
#3 |
|
Confirmed User
Industry Role:
Join Date: Nov 2001
Location: NYC
Posts: 3,927
|
Rrrrrrrrrrrrrrrrriiiiiiight........
|
|
|
|
|
|
#4 | |
|
So Fucking Banned
Join Date: May 2008
Posts: 224
|
Quote:
|
|
|
|
|
|
|
#5 |
|
i have man boobies
Join Date: Jul 2003
Location: van down by the river
Posts: 13,082
|
that link is broken, try this one instead
correct link
__________________
333-765-551 |
|
|
|
|
|
#6 |
|
Confirmed User
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
|
|
|
|
|
|
|
#7 | |
|
So Fucking Banned
Join Date: May 2008
Posts: 224
|
Quote:
![]() |
|
|
|
|
|
|
#8 | |
|
Confirmed User
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
|
for 110% paranoids is tool here:
Quote:
|
|
|
|
|
|
|
#9 |
|
Confirmed User
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
|
Exploit described here: http://wordpress.org/support/topic/169246
|
|
|
|
|
|
#10 |
|
Confirmed User
Join Date: Feb 2008
Posts: 137
|
Great tool, running it now, thanks ilbb
|
|
|
|
|
|
#11 |
|
Confirmed User
Industry Role:
Join Date: May 2005
Location: EU - Czech republic
Posts: 3,025
|
If you are not sure about the script, you can remove 'unlink' commands to be 100% safe. Tool will then report if infected files were found.
|
|
|
|
|
|
#12 |
|
there's no $$$ in porn
Industry Role:
Join Date: Jul 2005
Location: icq: 195./568.-230 (btw: not getting offline msgs)
Posts: 33,063
|
well intended but pretty useless. If your box has been compromised there's only 1 thing to do: wipe and reinstall.
|
|
|
|
|
|
#13 |
|
Confirmed User
Industry Role:
Join Date: Dec 2004
Location: Denver
Posts: 6,559
|
hackers suck
__________________
![]() |
|
|
|
|
|
#14 |
|
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
anyone have a better solution?
|
|
|
|
|
|
#15 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
Nice catch.
Do you have any idea how you caught it ? |
|
|
|
|
|
#16 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
And by caught it I mean, how you came to be infected.
|
|
|
|
|
|
#17 |
|
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
trying to find out. was using the latest version of wp - when outdated versions were thought to be the culprit.
|
|
|
|
|
|
#18 |
|
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
it's only on one of my smaller virtual hosts - so that may be the problem.
|
|
|
|
|
|
#19 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
The big concern is if wp is inherently vulnerable, through some mysql injection or xss issue maybe.
|
|
|
|
|
|
#20 |
|
best designer on GFY
Join Date: Mar 2003
Location: IALIEN.COM - High Definition Video and Photographic Productions -ICQ 78943384
Posts: 30,307
|
Yeah...
Upgrade your current version with the newest one.
__________________
![]() ![]() NAKED HOSTING FTW!11 I'm On The INSANE PLAN $9.95/mo! | The Alien Blog Adult News Worth Reading Updated Daily | Content For Sale! 641 PICS 216 MINUTES OF VIDEO $350.00 |ICQ: 78943384 | |
|
|
|
|
|
#21 |
|
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
|
|
|
|
|
|
#22 |
|
Registered User
Industry Role:
Join Date: Feb 2006
Posts: 22,511
|
disabling plugins seems to work ... on some of my blogs anyway.
|
|
|
|
|
|
#23 | |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
Quote:
__________________
Obey the Cowgod |
|
|
|
|
|
|
#24 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
I've spent hours poring over this matter, and I have to my satisfaction resolved that
1. The point of infection is template/widget installation. 2. The version number has no bearing. You can get it just as well on 251. 3. It's not an inherent flaw in the wp php/mysql code. |
|
|
|
|
|
#25 |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
Did you find out how exactly they are using this vulnerability? It's very important to know in order to make an universal protection algorithm.
__________________
Obey the Cowgod |
|
|
|
|
|
#26 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
It's not really a vulnerability per se.
Upon installing a new template, you grant code in there same rights as the wp package. An infected template then alters the p_footer() hook, wp_head() hook or both, ads some entries in a bogus wp_options entrace in the options table, and voila. You're infected. Moral is, never install code you haven't read. Don't be shy to crack "protected" stuff, especially if it's widgets, templates and the like. |
|
|
|
|
|
#27 | |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
Quote:
__________________
Obey the Cowgod |
|
|
|
|
|
|
#28 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
Actually, what I say is, encrypted code should never be run. Decrypt, read, consider, install. DRCI.
If you don't know how to crack your wp template, I've just explained it in my blog. |
|
|
|
|
|
#29 | |
|
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
Quote:
![]()
__________________
Obey the Cowgod |
|
|
|
|
|
|
#30 |
|
So Fucking Banned
Join Date: May 2006
Posts: 2,187
|
Which reasoning explains why blackhat seo or nigerian scams don't exist.
|
|
|
|
|
|
#31 |
|
Confirmed User
Join Date: Jan 2006
Location: Gringo in Puerto Rico
Posts: 4,204
|
im 100% against any themes that contain encrypted elements.
|
|
|
|
|
|
#32 |
|
ICQ: 197-556-237
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
|
__________________
I'm just a newbie. |
|
|
|