Hi,
Three days ago i’ve purchased and installed Newsmag. Today i received the following mail from dreamhost:
We have recently scanned one or more users on your DreamHost account for
potential security threats. Unfortunately, we found some potential
indications that your website(s) *may* be compromised.We understand that this may not be the best news you can get. This
notification is intended to help you through the process and serve as
a starting point to assist you in getting your account cleaned and
secured. While we won’t be able to complete these processes for you, if
you have any questions about the items that follow please don’t hesitate
to reply to this email and we will be happy to clarify any points or
offer any further guidance to help you through getting your account back to normal.The following files/directories had insecure permissions (777), which
have been remediated.…/doyouknowturkey.com/wp-content/uploads/js_composer
Additionally, the following steps should be taken to ensure password
security.Change your users password(s) by clicking under the Action Column for
that user in our Web Panel: https://panel.dreamhost.com/index.cgi?tree=users.users
Change your database password(s) by clicking the database username in
our Web Panel: https://panel.dreamhost.com/index.cgi?tree=goodies.mysql
IMPORTANT: You may need to modify your site’s configuration file to
reflect the new password.Use a complex (8-31 characters) password or passphrase that contains
mixed case letters, numbers, and symbols. You should avoid using
dictionary words (in any language), names, dates, addresses, phone
numbers, etc. as these can potentially be guessed or acquired through
other sources. The username that the password is being used for, or the
domain name/site name the user is attached to should never be included
in any part of the password. Also note that it is a good idea to
periodically change your passwords.
If you have any questions, please reply to this email and we will be
more than happy to assist you with securing your sites.Please also see https://help.dreamhost.com/hc/en-us/articles/214916918_keeping_your_website_secure
If you have any questions or concerns, you can submit a ticket, open
a LiveChat, or request for phone support here!
I had 4.12.1 version installed.
Now i’ve deleted the plugin but i am not sure what to do with this…?
Well, ask them WHY they think it “may” be compromised.
Some plugins need a directory to have 777 permissions to be writable by WordPress, most can just do 775.
Check with them. Visual Composer is a popular WordPress plugin, so likely ‘false positive’ on their end.
