My site was hacked several times.

Posted in: Newspaper
Post count: 11

Hi, anyone suffers like me attacks to his site?!
I’ve Newspaper 8.1 and WordPress 4.8.2 –> http://novedadesdeloeste.com

– I installed and configure iThemes Security
– I protected the folders wp-admin and wp-includes with password (via Cpanel)
– I banned all the IPS from USA via .htaccess
Any suggestion?!

The following files are modified by this malware/virus
wp-includes/script-loader.php
wp-includes/version.php
wp-includes/wp-db.php
wp-includes/class-wp-customize-manager.php
wp-includes/widgets/class-wp-widget-text.php
wp-includes/embed.php
wp-includes/formatting.php
wp-includes/js/twemoji.min.js
wp-includes/js/wp-emoji-loader.min.js
wp-includes/js/wplink.min.js
wp-includes/js/wplink.js
wp-includes/js/wp-emoji-loader.js
wp-includes/js/tinymce/plugins/wplink/plugin.min.js
wp-includes/js/tinymce/plugins/wplink/plugin.js
wp-includes/js/tinymce/wp-tinymce.js.gz
wp-includes/js/mce-view.min.js
wp-includes/js/mce-view.js
wp-includes/js/wp-emoji-release.min.js
wp-includes/js/twemoji.js
readme.html
error_log
wp-admin/edit-tag-form.php
wp-admin/install.php
wp-admin/plugin-editor.php
wp-admin/setup-config.php
wp-admin/user-edit.php
wp-admin/plugins.php
wp-admin/about.php
wp-admin/js/widgets/text-widgets.min.js
wp-admin/js/widgets/text-widgets.js
wp-admin/error_log
wp-admin/theme-editor.php
wp-admin/includes/class-wp-plugins-list-table.php
wp-admin/includes/update-core.php
wp-admin/includes/file.php
wp-admin/includes/template.php
license.txt

PD: And there is a problem between Newspaper and IP Geo Block?! (for the 500 error)

Post count: 23312

Hello,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Post count: 11

Hi! Thanks men!

I did a lot of things, and the attack stops.

But i have a problem, if a try to share in fb any article i have the “403 forbidden: please be advised that LiteSpeed…”

The folders permissions looks good, i desactive all the plugins, but the problem still there

Post count: 20688

Hi,

The error seems to mention something about litespeed, maybe it is related to the configuration of that. The 403 forbidden is in most cases caused by the configuration of security plugins
http://www.wpbeginner.com/wp-tutorials/how-to-fix-the-403-forbidden-error-in-wordpress/
Please double check all the settings of your security plugins.

Thanks

Post count: 11

Hi!
I think i solved the problem, but i still have the problem with sharing the articles in fb via the ‘Share Module’. The images doesn’t show up in fb.

Look –> http://novedadesdeloeste.com/pre-cosquin/

Any suggestion?!
Thanks

Post count: 9544

Check your open graph tags setup properly.

Post count: 20688

Hi,

At the moment there are no issues with the featured image when sharing the post
https://www.screencast.com/t/iQicG0A1
Use the Facebook debugger to identify potential problems if the issue persists
https://kb.yoast.com/kb/why-doesnt-facebook-display-an-image/

Thanks

Post count: 11

Thanks guys!

I solved everything with Yoast, except one article that did not work i didn’t know why. I just wrote the article again, and then the article starts to work correctly.

Thanks again!

Viewing 8 posts - 1 through 8 (of 8 total)
The forum ‘Newspaper’ is closed to new topics and replies.