Skip to main content

Compromised site files with incorrect date

Comments

4 comments

  • GOT
    The most important thing to do that you have not mentioned is updating all wordpress core, themes and plugins for every site. An outdated wordpress is trivial to exploit and do all the things you are seeing. In addition to the listed updates, a lot of themes come with commercial plugins, such as revolution slider, that will not list an update even if there is one without purchasing a license for the plugin. Once you've had a compromise like this, just updating the wordpress isn't enough. You could very easily be missing a malware script buried in a site somewhere that is like a php shell which gives the attacker way too much access to the all the sites on the server potentially, depending on how you have things set up. Since you are listed as a 'website owner' I presume that you do not have root level access, so you may have to engage the support of your host because if cross site attacks are possible, there are things they can do to prevent this. You might want to consider getting a service like Sucuri that will not only protect your sites from attack, but perform clean ups on them as well.
    0
  • belvinip
    Hi, Thanks so much for ur reply and useful suggestions. I did actually updated all themes and plugins even revolution sliderrs. And yes, i am using both Sucuri and Wordfence, they are helpful to identify the issue and help to delete it, but its not preventing the issue, so i really want to prevent this. When u mentioned "root level access", so i mean the c-panel access? I do hv full c-panel and ftp access, like setting permissions I hv couple of specific questions: With C-panel, can i not allow the the sites inject php files to other websites ditectory? Current i hv a few websites under my c-panel. And the malicious scripts are injected across different website. Not sure anything to do with the permission. My permission setting is 755 for directory and 644 for all files. And, is there any clue that, why the Last Modified Date is like what i said? And, is there any ways i can identify the malicious php files were created in relation to which plugin?
    0
  • GOT
    Since it sounds like all these domains are under the same account, they are therefore the same user and as such, once on areaa of your account gets compromised, they have access to the entire account. Since you are using Sucuri, have you submitted the site for cleanup? They should be able to identify and clean all infected files. As for file modification date, that is trivial for the hackers to modify to fake you out.
    0
  • cPanelLauren
    I cannot stress enough how important the advice @GOT provided here is:
    The most important thing to do that you have not mentioned is updating all wordpress core, themes and plugins for every site. An outdated wordpress is trivial to exploit and do all the things you are seeing. In addition to the listed updates, a lot of themes come with commercial plugins, such as revolution slider, that will not list an update even if there is one without purchasing a license for the plugin. Once you've had a compromise like this, just updating the wordpress isn't enough. You could very easily be missing a malware script buried in a site somewhere that is like a php shell which gives the attacker way too much access to the all the sites on the server potentially, depending on how you have things set up.

    This is also great advice:
    Since you are using Sucuri, have you submitted the site for cleanup? They should be able to identify and clean all infected files.

    But ultimately if you're still experiencing an issue after trying all of these I'd suggest enlisting the assistance of a qualified system administrator if you don't have one you might find one here: System Administration Services | cPanel Forums Thanks!
    0

Please sign in to leave a comment.