Hi, anyone suffers like me attacks to his site?!
I’ve Newspaper 8.1 and WordPress 4.8.2 –> http://novedadesdeloeste.com
– I installed and configure iThemes Security
– I protected the folders wp-admin and wp-includes with password (via Cpanel)
– I banned all the IPS from USA via .htaccess
Any suggestion?!
The following files are modified by this malware/virus
wp-includes/script-loader.php
wp-includes/version.php
wp-includes/wp-db.php
wp-includes/class-wp-customize-manager.php
wp-includes/widgets/class-wp-widget-text.php
wp-includes/embed.php
wp-includes/formatting.php
wp-includes/js/twemoji.min.js
wp-includes/js/wp-emoji-loader.min.js
wp-includes/js/wplink.min.js
wp-includes/js/wplink.js
wp-includes/js/wp-emoji-loader.js
wp-includes/js/tinymce/plugins/wplink/plugin.min.js
wp-includes/js/tinymce/plugins/wplink/plugin.js
wp-includes/js/tinymce/wp-tinymce.js.gz
wp-includes/js/mce-view.min.js
wp-includes/js/mce-view.js
wp-includes/js/wp-emoji-release.min.js
wp-includes/js/twemoji.js
readme.html
error_log
wp-admin/edit-tag-form.php
wp-admin/install.php
wp-admin/plugin-editor.php
wp-admin/setup-config.php
wp-admin/user-edit.php
wp-admin/plugins.php
wp-admin/about.php
wp-admin/js/widgets/text-widgets.min.js
wp-admin/js/widgets/text-widgets.js
wp-admin/error_log
wp-admin/theme-editor.php
wp-admin/includes/class-wp-plugins-list-table.php
wp-admin/includes/update-core.php
wp-admin/includes/file.php
wp-admin/includes/template.php
license.txt
PD: And there is a problem between Newspaper and IP Geo Block?! (for the 500 error)
-
This topic was modified 8 years by
ReyLagarto.
-
This topic was modified 8 years by
ReyLagarto.
Hello,
Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.
The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.
Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a link for best WordPress security practices created by Chris S:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!
Hi! Thanks men!
I did a lot of things, and the attack stops.
But i have a problem, if a try to share in fb any article i have the “403 forbidden: please be advised that LiteSpeed…”
The folders permissions looks good, i desactive all the plugins, but the problem still there
Hi,
The error seems to mention something about litespeed, maybe it is related to the configuration of that. The 403 forbidden is in most cases caused by the configuration of security plugins
– http://www.wpbeginner.com/wp-tutorials/how-to-fix-the-403-forbidden-error-in-wordpress/
Please double check all the settings of your security plugins.
Thanks
Hi!
I think i solved the problem, but i still have the problem with sharing the articles in fb via the ‘Share Module’. The images doesn’t show up in fb.
Look –> http://novedadesdeloeste.com/pre-cosquin/
Any suggestion?!
Thanks
Hi,
At the moment there are no issues with the featured image when sharing the post
– https://www.screencast.com/t/iQicG0A1
Use the Facebook debugger to identify potential problems if the issue persists
– https://kb.yoast.com/kb/why-doesnt-facebook-display-an-image/
Thanks
Thanks guys!
I solved everything with Yoast, except one article that did not work i didn’t know why. I just wrote the article again, and then the article starts to work correctly.
Thanks again!