Anti-Malware Admin

Forum Replies Created

Viewing 15 posts - 406 through 420 (of 698 total)
  • Author
    Posts
  • in reply to: Hacked minutes after #1709

    Anti-Malware Admin
    Key Master

    It may not be related to your WordPress install directly, it could be coming from another user’s site on that server, typical shared hosting accounts are not very secure.

    The best thing to do for the security of your site would be to move it to a more secure server. I do offer Super Secure Hosting for $12/month per site. If you just have this one site to worry about then you should just move the site to my server and be done with this. I have moved hundreds of infected sites to my servers and non of them have ever been reinfected again since.

    I got your other direct email so if you are interested in hosting with my you can send me your hosting details directly to my email and I can move the site for you.

    in reply to: Hacked minutes after #1705

    Anti-Malware Admin
    Key Master

    If you are getting reinfected with the same or similar threats repeatedly then the root vulnerability that let in the hack the first time is still there.

    If this hack is coming in through a server vulnerability or from another infected site on the same server then there is no plugin that you can put on this site that will stop it for good. You need to find the root cause, the source of the infection.

    Is this a shared hosting account?

    If so, how many sites do you have on your account?

    in reply to: MW:JS:GEN2?web.js.malware.fake_jquery.003 #1701

    Anti-Malware Admin
    Key Master

    Sucuri caches their results, so those threats were already fixed. I clicked the “Force a Re-scan” link at the bottom:

    *Cached results from more than 2 days ago. Force a Re-scan to clear the cache.

    and now all it shows is a link you a counter site witch might be a false positive but you can probably remove it anyway.

    in reply to: redirect when attempting to logon #1698

    Anti-Malware Admin
    Key Master

    This is the Brute-Force Protection, which you can disable on the Firewall Options page in your wp-admin, under Anti-Malware.

    in reply to: Can´t download new definitions #1696

    Anti-Malware Admin
    Key Master

    Sorry about that, I just fixed it, so It is working now, thanks ;-)

    in reply to: xm1rpc.php ? #1693

    Anti-Malware Admin
    Key Master

    It may be coming in from another account on the server. The best thing to do would be to move your site to a more secure hosting environment. I offer Super Secure Hosting if you are interested, it’s $12/month per site and you will not get reinfected on my server ;-)

    in reply to: xm1rpc.php ? #1691

    Anti-Malware Admin
    Key Master

    I see that your site in is a subdirectory on a HostGator shared hosting account. It would be most effective if you could scan the site_root or even the account root. There could be other infected sites on this server that are reinfecting your site. There may also be .htaccess files or cron jobs on your account that will affect all the sites in your account. How many sites do you have on HostGator?

    in reply to: Website crashed after fix #1675

    Anti-Malware Admin
    Key Master

    After the fix it loads the wp-admin in that framed window, if the wp-admin loads tht means the WordPress bootstrap was not broken. Theme files are often infected and con sometime be broken when they are hacked (if the hack was done poorly), or when the hack is removed (if the removal was not complete and thorough).

    Can you send me the threat that you had to remove yourself? If my plugin could have removed that whole threat when you ran the fix then this would not have happened.

    in reply to: No response from server #1668

    Anti-Malware Admin
    Key Master

    That would be one possible fix but your should ask your host to review permissions on that folder and make it right according to their security needs. Personally I would make it 770 so that “others” could not read or write in that directory, but then you would need to make sure that the apache user is the owner or group owner so that PHP can write (and read) session files.

    in reply to: Skipped Folders / Files #1666

    Anti-Malware Admin
    Key Master

    Yes, you should also run the Complete Scan if you want to make sure your site is completely clean. The Quick Scan only scan the main folders were malware is likely to be found.

    in reply to: No response from server #1663

    Anti-Malware Admin
    Key Master

    I have spent quite some time debugging multiple issues on this test site that you gave me access to. First, I found that some of the rules in your .htaccess files were preventing the rewrite rule in my plugin directory from working properly. After fining a workaround for that problem I found that your server was not able to save and retrieve a session file. The directory where session files are stored has the following permissions: drwx-wx-wt

    in reply to: Core File Scan? #1653

    Anti-Malware Admin
    Key Master

    The plugin will scan all the files in the directory your choose and you can run the Quick Scan on the core files as well, but it will not be as fast as it would if you download the Core Files Definitions, plus it will not find every file modification, only identifiable threats. The Core Files Definitions are available through the Automatic Update feater, which is what you get when you donate $29+, this will a speed up the scans and improve accuracy.

    in reply to: Site OFFLINE – Error 503 #1645

    Anti-Malware Admin
    Key Master

    If your sites are offline then the scan will not be working either. Check your server’s error_log files to get more info about those 503 errors or ask your hosting provider why your sites are all offline.

    in reply to: Brute-force Protection Not Installed #1641

    Anti-Malware Admin
    Key Master

    I’m glad your web hosting company responded with a solution and it is working now.

    I am posting their response here in case it might help others who have the same problem.

    In Plesk, in the WordPress security menu, you activated “wp-content folder security”, which prevents accessing it directly.

    I have disabled this.

    Aloha, Eli

    in reply to: Brute-force Protection Not Installed #1639

    Anti-Malware Admin
    Key Master

    Thanks for your donation, I’m glad my plugin was helpful in stopping that attack.

    I would like to help you resolve error on your server that is causing the “no response” message on the JS/Session test.

    If you are willing to send me your wp-admin login then I can debug this issue on your site, other wise please check your browser’s Error Console for JavaScript errors and the error_log files on your server for PHP Errors and let me know what you find.

Viewing 15 posts - 406 through 420 (of 698 total)