Forum Replies Created
-
AuthorPosts
-
It looks like your server cannot sustain a persistent session.
You should not have been able to Enable the Brute-Force Protection without a working session, but maybe your session capability only broke after the protection has enabled.
In any case, you need to manually disable this login protection now so that you can get back into your WP Admin, and there are two ways to do this with FTP or File Manager access to your server. The simplest way to disable the Brute-Force Protection without disabling the plugin is to delete the safe-load folder inside the gotmls plugin folder. The second way is a little harder if you don’t know anything about PHP, but would be better in the long run, is if you can edit the wp-config.php file in the root directory or the site and rem out the require_once line at the top of the file by adding // right after the first
@programmers,
I have upgraded the scan depth on both the keys your sent me. Please download the new Definition Update and you should be able to scan the other sites in the www/public_html directory.Please note that the Complete Scan may take a very long time to finish if there are a lot of sites in the scan path.
I discovered that there was a malicious javascript redirect in the settings for the fancybox-for-wordpress plugin. So I installed my SQL Reports plugin and searched for the mfbfw value in the wp_options table and deleted it. Now your site does not redirect on my mobile device
I just got your login yesterday and ran a Complete Scan last night. My plugin didn’t find anything but Potential Threats and those look ok, but I do get redirected when I go to your site in a mobile browser, so this must be something new. I would like to find this new threat and add it to my definition updates sot that it can be automatically removed, but it’s nit in any of the usual places. I will keep looking but I have been very busy and I’m swamped with requests for help right now. This is a volunteer effort for me, I only get paid by the voluntary donation made by people like you, I’ll do the best I can for you and I’ll let you know when I find this one.
Meenakshi,
Your Threat looks like it might be a new one. I don’t know if it is listed in the “Postential Threats” or not but my plugin can only remove it for you if it is a “Known Threat”. If you can send me your WP Admin login I can confirm where this threat is and add it to my Definition Updates so that it can be automatically removed.Please send login details directly to me: eli At gotmls DOT net
Aloha, Eli
March 23, 2015 at 8:04 am in reply to: Website get redirect to strange link – the plugin wasn't able to fix it #1105Make sure you have downloaded the latest definition updates and if it still does not find this mobile redirect then you can send me your WP Admin login and I will look for it myself. Then I can add it to my definition updates and it can be automatically removed.
This is because your web server does not have permission to write to your wp-config.php file, which is where my plugin installs the patch.
If you want to install this patch then you should make sure that the wp-config.php file is writable by the apache user.
make sure there is also a writable quarantine folder in the uploads directory. If that doesn’t help then maybe you would be willing to email me directly with your WP Admin login so that I can take a look at it myself.
Thanks. I added that eval variant to my Known Threat.
Yes, please send me this file and I will add it to my Definition Updates ASAP.
It is also possible that the quarantine directory is not writable, in which case it would not be able to make a backup of these infected files before cleaning them. That would prevent it from continuing, as a backup is an essential step before make any file-system changes.
If you still can get it to clean those files and you would be willing to send me your WP admin login then I would be willing to take a look at it personally.
This sounds like a permission problem. Maybe those infected files are not writable. You can try to check and change the permission of those files with an FTP client like Filezilla.
Let me know if you need more help.
The swirling icon by the brute-force protection indicates that your server is being checked for session compatibility. if it takes a whole minute and return the “No response from server!” then there is something preventing the session test for confirming session compatibility. I can’t say for certain what the problem with your server is without seeing it but if this test fails then my brute-force protection may not work on your server until the underlying issue is resolved.
If you want me to take a look at it you can email me directly with your WP Admin login and I’ll see if I can tell you why it won’t work on your server.
Thanks for sending me your login info.
I can see the files that you cleaned with my plugin in the quarantine. They don’t look like they have any strange characters at the beginning but when I copy the contents and submit it to a string parser I wrote then an invisible character gets decoded at the beginning of the file. This is a bit fishy but it’s not malicious. I downloaded the source for the LayerSlider plugin and it looks like this html file is part of the original install so I have removed it from the definitions. If you download the lasted definition update then this file will no longer be detected as a Known Threat. You can also restore those files from the Anti-Malware Quarantine if you want to, although I don’t think they are really necessary.
Thanks for helping me resolve this issue. Please let me know if you have any more questions.
Would you be willing to send me your WP admin login so that I can figure out why it caught that file? I would really like to get to the bottom of this, for you, and also for myself. I need to know that it was not wrong for my plugin to remove the contents of that file, and if it was wrong I really need to fix it.
-
AuthorPosts

