Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #517467

    Hello

    We recently noticed an exploit on one of our sites running enfold… it seems to have mainly gone for the layer slider part of our site, along with a few other plugins…

    Have you had any other reports of this? Any idea how to resolve this? apart from replacing the files?

    ================================================================
    /home/southwes/public_html/wp-content/plugins/contact-form-plugin/languages/general.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/3rd-party/3rd-party.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/_inc/scss/admin.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/images/rss/plugin.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/images/rss/template.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/json-endpoints/class.wpcom-json-api-get-comment-endpoint.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/json-endpoints/jetpack/class.jetpack-json-api-check-capabilities-endpoint.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/shortcodes/cartodb.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/shortcodes/css/rtl/options.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/shortlinks.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/site-icon.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/theme-tools.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/theme-tools/system.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/tiled-gallery/tiled-gallery/tiled-gallery-item.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/modules/verification-tools/test.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/jetpack/scss/_utilities/file.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/plugins/nashr-seo/includes/user.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/config-layerslider/LayerSlider/demos/v5/dirs.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/config-layerslider/LayerSlider/static/codemirror/mode/htmlmixed/test.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/config-layerslider/LayerSlider/static/codemirror/mode/php/search.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/forum.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/framework/php/avia_shortcodes/img/list.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/themes/enfold/template-blank.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/uploads/2014/07/files.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-content/uploads/2014/javascript.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/canonical.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/class-pop3.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/class-wp-error.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/js/jquery/config.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/js/tinymce/plugins/compat3x/css/diff.php: PHP.Trojan.Uploader FOUND
    /home/southwes/public_html/wp-includes/js/tinymce/plugins/wpautoresize/config.php: PHP.Trojan.Uploader FOUND

    #517474

    Hi duncanfbell!

    Can you please post the link to your website? Please make sure that you are using the latest version of Enfold – http://kriesi.at/documentation/enfold/updating-your-theme-files/

    Which plugins are you using?

    Cheers!
    Yigit

    #517484

    Hello
    It has the latest version of wordpress and latest enfold.. latest plugins… I just deleted a few that were not active but showed up in the malicious files list… (Jetpack?)
    Now installed
    Contact Form by BestWebSoft
    RSS Includes Pages
    XML Sitemaps
    Happy to make you an admin account to login if you want to have a look, or FTP account?

    • This reply was modified 9 years, 4 months ago by duncanfbell.
    #517500

    I have also ensured all user accounts on the site have new extremely safe passwords.

    #517703

    Hi!

    You need to clean your site.
    You can either contact someone to do it for you or try with sucuri API and sucuri service, who will guide you as should.

    You can contact one of our Customization Contractors, who will help you out with the process.
    http://kriesi.at/contact/customization

    Let us know if we could do anything else, regarding our theme

    Cheers!
    Basilis

Viewing 5 posts - 1 through 5 (of 5 total)
  • You must be logged in to reply to this topic.