Cover Bug in WordPress 3.3.1 Hole To Hack



Looking for wordpress 3.3.1 for bug holes in the hack is very easy for hackers infiltrated, so obvious example is in the file

domainxxx.com / wp-admin / admin-functions.php

domainxxx.com / wp-admin / menu.php

domainxxx.com / wp-admin / menu-header.php

domainxxx.com / wp-admin / options-head.php

and many more that others, in fact it is a powerful wordpress for problems like this but for some reason this version many bugs or holes are easily infiltrated by hackers. besides bug that could wordpress hackers infiltrated there are also plugins that can be compromised by hackers so before installing the plugin please look for the weaknesses and shortcomings in google might have gone there to write about the plugin.

one example that friends wordpress website hacked mass as shown below



that according to the party he was hosting there is a little mistake and now it is in the delete some but I personally think because bugs can pass that on top wordpress. The above image can be checked in your domain domainxxx.com / root.htm

To cover the hole in the Bug WordPress Hack
one way to mitigate the website please go to cpanel and create files in the wp-admin folder with the name. htaccess and enter the following scrip

[Sourcecode language = "plain"]
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule (admin-functions | menu | menu-header |-head options | upgrade-functions). Php $ http://ahmadfaza.com/ [L]

order allow, deny
deny from all
satisfy all

[/ Sourcecode]

srcip intent of the above is considered a bug mengredirek file2nya domain to us, please replace ahmadfaza.com with the name of each website.

after giving the file there are some files that should be removed is
install.php ==> in wp-admin
readme.php ==> in public_html
and do not use plugins that have been positively easy to hack
WordPress Ajax Gallery 3.0 (already removed from the database WordPress.org)
Global Content Blocks WordPress 1.2 (already removed from the database WordPress.org)
WordPress WordPress Allow PHP in Posts and Pages plugin 2.0.0.RC1
WordPress Menu Creator 1.1.7
WordPress WP DS FAQ plugin (it has been deleted from the database WordPress.org)
WordPress WP Forum (already removed)
WordPress File Groups (already removed)
WordPress Contus HD FLV Player (already removed)
WordPress Easy Contact Form Lite (already removed)
IP-Logger WordPress Plugin (already removed)
MM Duplicate WordPress Plugin (already removed)
WordPress jetpack plugin
E-commerce WordPress 3.8.6

0 komentar:

Posting Komentar