Home User profile
tagDiv Member
This user did not write anything. So we are just showing here some random text to make the profile page look nice :)
loslunes
tagDiv Member

Working fine here also. Maybe you´re using some kind of plugin in your browser that make a bug when sharing (but it’s strange).

loslunes
tagDiv Member

So then, is there any chance to increase this default landscape pixel size to mobile view? I just wanted to test if it is possible.

Many thanks

loslunes
tagDiv Member

Same here, this ips from Russia, Romania and Netherlands are trying to inject malware. They had the same problems months ago. Many of us were injected with a redirection code that you can see in theme options> custom code> javascript (or something similar). At least it’s seems they solved the problem blocking these petitions.

But yes, since a month ago we have had a continuous and non-stop traffic from this ips. Look at my server visit log https://ibb.co/Y7TWgxy

loslunes
tagDiv Member

Its a vulnerabilty of the theme. Someone is constantly trying to inject malware. Take a look to your server visit log and maybe you´ll find ips asking without stop to “/wp-json/tdw/save_css” or something similar.

My version of the theme gives them a 403, I was injected a few months ago and it’s seem the new version they built “solved the problem”. But hackers knows this vulnerability and they are trying and trying and trying. Look at the attached image, where you can find my server log from this morning. I haven’t seen them since a couple of weeks but they have come back again… Ips from Romania, Russia and Netherlands.

https://ibb.co/Y7TWgxy (attached image)

  • This reply was modified 2 years by loslunes.
loslunes
tagDiv Member

I’m just saying some ips are asking without stop for a tagdiv resource trying to inject a redirection. You have just to look at my server…

loslunes
tagDiv Member

I have noticed this in the server, we have continuous visits from ips from rumania and netherlands asking for “/wp-json/tdw/save_css”. Fortunately this petitions are resolve with 403 instead this ips are not blocked. Look the screenshot: https://ibb.co/SnpVDsL

This happened months ago too. A code was inserted in template css and javascripts options boxes when you look there. Then you update the theme, and it seems that petition to be solved with a 403. It seemed they (I mean the hackers) disappears but since a couple of weeks I have noticed they are asking for CSS again because they know you have a vulnerability there. Today they are asking without stops, sometimes more than 50 times per minute…

Someone is attacking your theme without stop. You should take a look to this issue. Right now, fortunately, I have not been injected but they could find a new way again. This is a long-standing problem.

  • This reply was modified 2 years by loslunes.
loslunes
tagDiv Member

Google uses the date from the sitemap, not from the theme, when publishing your article in his search engine.

  • This reply was modified 2 years by loslunes.
loslunes
tagDiv Member

This is not the problem, It’s the first thing I made. I have also deactivated adblock plugin and tracking protection but the problem persists. Last thing I tested is cleaning web caches from WP panel. Not working either.
I have downgraded Firefox for android to version minor than 107.X (The ones with the problem, new ones from the mobile browser version) and all is working perfect. So it seems Firefox has made something that makes the web to be open without a correct font css or overwriting it to a default one. This is something you can change in pc version (where the web load fine with correct fonts) but it’s not an option in mobile one, so I don’t really know what makes fonts not to load correctly.
I know it’s a strange thing but maybe you could know something. Many thanks.

loslunes
tagDiv Member

Solved, a WP support forum user has sent me a code to change the vertical aligment code for widefat

loslunes
tagDiv Member

Same problem here with YouTube with no legend. With photos I had to add a custom css code because we had the same problem. I have not updated to last newspaper version, so I can’t say if it’s solved there. Could u give us a custom css for YouTube embed which change the down margin?

loslunes
tagDiv Member

I have NOT being infected again, but I can see the same IPS (that I blocked, you can see here and in the other post related with this issue) are trying to repeatedly. My advise is to block them. Both are from OVH SAS hosting, famous for a lot of spam and hacking (I thought to block the entire ip range from this hosting, but finally I didn’t. Anyway I have to say that I have blocked dozens of them).

So, I will ask your developers to find a “more secure” solution to this malware than not to allow writing an “eval string” in theme panel. Think about it, cause it’s a real problem…

Also, If i were you (I mean newspaper support) I will ask to OVH SAS abuse department to look into this ips ranges. If they receive a mail or a call from an important theme developer like you, they will look into the problem with more emphasis than if they receive a mail from a “normal web admin”. Think about it too.

loslunes
tagDiv Member

He wanted to say that before updating to new version, you have to delete the code if is in the custom JavaScript and custom HTML fields in theme panel > custom codes. I updated yesterday, will see if it works (hoping to work or we will drive crazy).

loslunes
tagDiv Member

Thanks Calin, I will update asap to new version. I have answered you in the other post saying that the code only works when injected manually, as we show you, and caches were cleaned after the injection. If caches not cleaned or code is not here in custom fields the site works fine (so it couldn’t be an infected file in the server because the malware should then ALWAYS work, I hope I’m explaining well).

  • This reply was modified 3 years by loslunes.
loslunes
tagDiv Member

Ok thats the answer I wanted. I would update asap.

If any file infected in all the server files then the malware will run ALWAYS. The problem is that the malware only works when the hacker use tdcomposer / tdpanel option (as my partner and I said) to put into the custom javascript and custom html.

When you delete the code from there (I made 2 days ago and, fortunately, it doesn’t appears again) and clean caches, all works fine. When the code is injected and caches are not cleaned, the code doesn’t works because it has been not applied. I mean, it only happens when someone use td panel vulnerability to inject it. I don´t know if only in old version, I have 11.5.1.

Thanks for the help

loslunes
tagDiv Member

I repeat the one thing I have said you in the other post, THEY ARE USING A VULNERABILITY OF TAG DIV to put it there.

loslunes
tagDiv Member

Calin, you’re not giving us a solution since a couple of days that we have report the problem. Stop telling us it’s a viral campaign, people injected virus and malware… We know this happens because they use code vulnerabilities like the one you have here. I understand you don’t want to say it’s a theme problem, but I have talked with many developers with other themes, and they did not have the problem.

Someone is accessing tag div panel without a logged ip and then putting there malicious code. So then, your development team has to try to solve it asap. We have given you clear info about the process they use to do it, now it’s time for you to solve it.

loslunes
tagDiv Member

https://imgur.com/lpfhW3Z

  • This reply was modified 3 years by loslunes.
loslunes
tagDiv Member

Same problem here since I have update to WP 6.1. The margin down an image (without a legend) has dissapeared

  • This reply was modified 3 years by loslunes.
loslunes
tagDiv Member

+1 here, using newspapper 11.5.1

Would like to know if anyone with most recent version has the same issue.

loslunes
tagDiv Member

I’m looking the custom codes option every 30 min xD. This is insane. Anyway, I’m waiting the server to make a backup and a relaxing moment in my website (It’s happening when our visit has increased 300% from 5 months ago… so it’s a big problem having malware injected that random way) to update to last version and see if the problem persists.

Anyway, they should make a deep investigation about the issue and stop telling us its “our problem”

  • This reply was modified 3 years by loslunes.
loslunes
tagDiv Member

Look at the log from yesterday:

91.134.227.26 – – [15/Nov/2022:22:04:51 +0100] “GET / HTTP/1.1” 200 170375 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36”
91.134.227.26 – – [15/Nov/2022:22:04:53 +0100] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 77 “https://www.mysite.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”
91.134.227.26 – – [15/Nov/2022:22:04:55 +0100] “GET /wp-admin/admin.php?page=td_theme_panel HTTP/1.1” 200 118509 “https://www.mysite.com/wp-admin/admin.php?page=td_theme_panel” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”
91.134.227.26 – – [15/Nov/2022:22:05:00 +0100] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 21 “https://www.mysite.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”

The only one asking for https://www.mysite.com/wp-admin/admin.php?page=td_theme_panel is me and this ip. After this ip asked for this resources the code appears again

loslunes
tagDiv Member

Look at theme panel > custom codes > custom javascript and custom html and let us know if you have a code there with eval (char…. (lots of numbers)). It’s happening to a few of us and it seems someone is using some vulnerability.

loslunes
tagDiv Member

I deleted it on Monday when someone here talks about this code in your theme custom JavaScript and clean all the caches. The problem was solved.

Yesterday, I looked more than 10 times firing the day until its appears again in my last view at 11:40 pm. I look into the log and saw a strange behaviour in the ip I said calling to admin ajax two times after asking for home page and then this ip leave.

Its someone who called to and action related to the theme like our partner shows above. So it seems to be a vulnerability of the composer.

I have version 11.5.1 so maybe I have to update and see of coming back… I will let you know and if the problem persists we will talk again about you to look into our panel.

loslunes
tagDiv Member

Have you read the post attached on my first comment? Its a clear vulnerability of your theme. Im not the one with the problem mate.

loslunes
tagDiv Member

AND NOW ALSO IN CUSTOM HTML!!! See atached image: https://ibb.co/Qbs0Xjn

SOLVE IT!!!!

Viewing 25 posts - 1 through 25 (of 77 total)