1

I have a wordpress site which is acting strange lately. It seems like the database is spontaneously rolling back a few hours from time to time. I have noticed it happen at least four times.

  • When I updated to wordpress 3.5, after a short time, maybe 30-60 minutes I noticed the nag to upgrade was back. I ran the upgrade a second time, even though I was certain that I had already upgraded.
  • I added a new category and changed a widget on one of my sidebars, only to find that my changes were gone the next day and I had to redo them.
  • I added a post yesterday, linked to it in various places and then returned several hours later to find the post missing. I rewrote the post from memory and put it back on the site.
  • This morning when I went to the site, the original post was back and the one that I had recreated from memory was gone. The post's id number was the same as the previous day. I think there was also a draft post that disappeared and reappeared as well.

One last clue which may or may not be related is that when I go to a page on the blog that should generate a 404 message I get a single piece of text which says: "defaced by t3ll0" I noticed this recently, within the last few weeks. I'm not sure how long it has been like that.

I ran Sucuri Scanner, and it found no evidence of malware. Any suggestions of how to troubleshoot this? Could this be a problem with my database rather than wordpress?

UPDATE: It appears that the primary problem I was noticing was because of two versions of the site being up simultaneously. The DNS settings had not been updated to the new site. I'm still investigating if the site was hacked.

4

2 回答 2

1

你被黑了。“被t3ll0污损”是线索。有人控制了您的网站和您的托管帐户。

使用这些资源并按照所有说明彻底清理您的网站,否则您可能会再次被黑客入侵。请参阅常见问题解答:我的网站被黑了 « WordPress Codex以及如何彻底清理您被黑的 wordpress 安装以及如何在被黑的 WordPress 中找到后门强化 WordPress « WordPress Codex。

更改所有密码。扫描您自己的 PC 以查找可能窃取了您的登录名和密码的间谍软件。

http://sitecheck.sucuri.net/是一个很好的资源,但它会扫描恶意软件,而不是被黑客入侵且未用于分发恶意软件或具有垃圾邮件链接的帐户。

告诉你的网络主机你被黑了;并考虑更改为更安全的主机:推荐的 WordPress 虚拟主机

于 2012-12-19T17:35:22.227 回答
0

您尚未应用安全性可能在多个地方。1.文件权限,文件夹权限。2.上传文件夹权限。3. 执行权限。

现在,如果您不是开发人员,您将如何检查这些漏洞?

我建议您备份您的数据库(导出它)。摆脱现有的 WP 核心并重新安装它。

删除所有插件并从新来源安装它们。

如果您使用了自定义主题,请获取它的备份版本并删除当前主题,因为它有污点。

您可以使用这样的插件检查很多漏洞:http ://wordpress.org/extend/plugins/better-wp-security/

重命名您的管理员帐户。强化您的密码。从 .htaccess 和 wp-config.php 文件中删除写权限。

于 2012-12-19T17:30:25.243 回答