Virus posting articles

Posted in: Newsmag
Post count: 207

Hello,

A virus is posting articles on my site http://pavlikeni.com?

How is that possible? Why is your script allowing that?

Peter

Post count: 9544

The theme doesn’t allow viruses to post on your site.

You should make sure you have proper security setup for your WP install per the WordPress.org docs on “hardening WordPress,” you should remove any pirate software or plugins being used; remove any plugins “found on the web,” change your main username/password, install https/SSL on your site, scan your site with the free SECURI site scanner, perhaps consider doing clean install of WordPress; remove all plugins and old themes you’re not using, as they are security risks.

https://sitecheck.sucuri.net/results/pavlikeni.com/

If you install a “Demo with content,” that loads example content for those making site from scratch and without any existing content. Read the friendly instructions.

Post count: 207

Hello,

Thanks for your response, BUT, that site shows no problems with my site. What is happening is that the virus is posting articles on behalf of one of my “author” accounts. For each article it creates a “uncategorized” category and posts it. I found a “public_html_hacked” directory on my server with a single content “pavliken_wpsite.sql” with permissions 0644.

I am not running any old themes, only yours, which I update as oon as you provide updates, nor have I any random plugins.

Please advise.

Thanks,
Peter

  • This reply was modified 9 years by Afterglow.
Post count: 9544

So, perhaps your author password got hacked and then that hacker uploaded files to your server?

Theme cannot upload or post — your WordPress install does that.

Hopefully you have cleaned your site, and changed all your account passwords to “strong” required passwords.

Not my theme, just 20 year webdev expert and 11 years on WordPress.

So, make sure you do clean install of WordPress, thenes, and plugins, as I suggested — this means REMOVE current WP folders, plugins, themes, and upload CLEAN copies; reset ALL passwords; check htaccess and wp-config.php and root for any suspect php files.

Only you can fix your compromised website, not fault of the theme.

Post count: 207

Hello,

After 24 hours of hell I think I managed to clean and protect my sites running your theme.

It is my strong belief that you absolutely should include or suggest security tool(s) to the theme. Not doing so is not right, it actually is wrong and exposes users like me to serious trouble. It is like selling a car or a house without door locks. And when I refer to “users” above, I do not mean your programmers and the Bill Gates and the Steve Jobs of the world, but users who are not professional and basic in their knowledge to say the least.

The company I found is http://ithemes.com with amazing and easy to customize tools for protection, scanning, etc. On top of that their prices are more than affordable.

Please consider my constructive criticism to further enhance your great product, saving your clients countless hours of frustration, money, etc.

We live in a nasty predatory world and including or suggesting protection to non-professionals like me (and I am sure many of your clients) is imperative. At least I demand it having bought 8 copies of your theme.

Thanks,
Peter

Post count: 9544

RTFM: https://codex.wordpress.org/Hardening_WordPress

Again, “theme” does not allow hacking; your WordPress setup and user access levels, allow hacking. For example you should have the ability to edit core theme and WP files “off” for all users except super user. You should not have your superuser named “admin.” Etc.

Helps to read the WordPress docs on how to use, secure, manage WordPress.

WordPress is the “car” in your analogy, and the theme is only the paint color and stereo. It doesn’t drive your site, it only changes how it looks and what kind of speakers you have inside. The main WordPress files allow publishing pages; the theme only offers “styles” to change that.

Theme is not responsible for “locking down” WordPress.

Hope you take that as constructive criticism.

Post count: 207

Again, I know – I am a stupid user, as I have already come to realize. Regardless, I do not have to be a programmer to mindlessly post my articles. Your theme is what a low grade user like me sees – its admin panel, its front end, etc. If that is the case, which it is, I suggested that you suggest to users like me, which are also paying customers of yours, options for meaningful protection beyond the colours, the bells and the whistles. It will also save you time dealing with people like me on issues as the discussed one.

Viewing 7 posts - 1 through 7 (of 7 total)
The forum ‘Newsmag’ is closed to new topics and replies.