Forum Replies Created
-
AuthorPosts
-
September 20, 2018 at 10:24 am in reply to: Malicious code found in wp files but website still redirect to unknown website. #2158
Have you run a second scan to make sure that there are no remaining threats, and that none of the original threats have come back?
Just follow the same steps that you did the first time you installed the plugin: Get the free key (which should match the key you paid for) and that key should already be registered and show your donation. If not then just register that key under the same email address and it will then show your donation. If you have any trouble following these directions please send me a screenshot so that I can see where you’re at.
You have already unlocked the core file definition and the automatic update feature with your donation so now you just need to click the automatic fix button and my plug-in will automatically restore those core files that have been changed.
If it’s not a session issue on your server then maybe you have another plugin or firewall that is blocking rewrite scripts from loading in within the wp-content directory?
As I mentioned in my first replay, it would help if you sent me a screenshot of the firewall settings page in your wp-admin.
In general this message indicates that your server was either unable to start a persistent session or that the rewrite rules in the .htaccess files are not affective. There could be many causes for this that you should bring up with your hosting provider. Maybe you have restricted access on some directories or there is a permission problem on certain folder. If your hosting provider is not helpful in this and you can send me a screenshot of the Firewall settings page then I can try to help you troubleshoot further.
You can unregister a site or transfer your registrations from the members page. Or you can simply re-register a site by ckicking on the green checkbox in the upper-right side of the Anti-Malware Setting page in the wp-admin on that site.
The scan will also automatically skip empty files and whitelisted files and this is ok, it does this to speed up the scan process. If you hover over the file listed it will pop-up and tell you why it was skipped.
If the scan finds a file that is marked as a Known Threat then you can click on the red linked file to examine the contents. There you will have the option to whitelist that file, however, this is a passive action that does not really solve anything and ignores the bigger issue. Either you are whitelisting an infected file that contains malicious code which should not be whitelisted or my plugin is incorrectly flagging this code as a Known Threat when it should not be. Can you please send me the file or files that you are wanting to whitelist so that I can check them and make adjustments to my definition updates if needed?
My plugin should find this threat. Can you send me a screenshot of the scan results or send me your wp-admin login so that I can take a look?
That error means that there is no response from your server when testing the session feature. I am not sure why your site will not start a session but it is usually due to a server configuration issue, like php.ini settings or the permissions on the /tmp/ directory (or wherever the session files are kept on your server). Check your server’s error_log files and ask your host to verify that session files can be stored on your server.
So You cannot change the file permissions in FileZilla. I’m sorry that your host was not more helpful. You may be able to fix the permissions on these files using your hosting control panel, there is usually some kind of file manager that can change the permissions for you. Otherwise you would have to convince your hosting provider to step up and help you or else move your sites to another host.
How many sites do you have on this host?
It would seem that there is a permission issue on those files that prevents them from being fixed by any PHP process on your webservers. You could try to change the permissions on those files so that they can be automatically fixed by my plugin.
If you need more specific guidance then I would need more detailed information about the specific situation on your server. Please feel free to send me screenshots or any other specific info that might help if you need further assistance.
By default the Firewall Option to block User Enumeration is Automatically Enabled. This means that any attempt to pass a numeric value for the Author property in the URL that is not in the wp-admin path is automatically redirected. You can choose to disable this protection in the in the Firewall Option under the Anti-malware Setting if you want to allow these link to enumeration pathes that are not under /wp-admin/.
You would need to fix whatever is wrong with that server that prevents it from creating a persistent session. Maybe it is the wrong permissions on the /tmp/ directory or that partition is full, or maybe the session path is set to a directory that does not exist. You would need to refer to your error_log files to find the answer that pertains to your particular situation.
Try editing that teenage-cancer-trust page in your wp-admin and just remove the viagra link that was injecting into your DB content.
-
AuthorPosts