Nexology Community
 
     
 
   

Go Back   Nexology Community > Nexus Zone > News and Announcements

Reply
 
LinkBack Thread Tools Display Modes
Old 05-20-2010, 09:48 AM   #11
HN Dinosaur
 
Pinsprings's Avatar
 
Join Date: Apr 2002
Location: Indiana, USA
Posts: 1,717
One of my WP sites disappeared yesterday. I opened a ticket and was told that it was compromised. I am assuming that it was Gumblar, because I was sent to the blog post about Gumblar.

I have checked and rechecked my computer and it seems to be clean.

I did the re-install through my WP admin and it seems to have fixed the problem. Is that all that I need to do? To implement FastCGI, all that I have to do is tick FastCGI in Plesk, right? Do I need to untick anything?
__________________
~Vicky
A very happy and proud HostNexus Linux Shared Hosting owner.

Actions speak louder than forwarded e-mails or bumper stickers.
Pinsprings is offline   Reply With Quote
Old 05-20-2010, 10:20 PM   #12
HN Top Canine
 
NexDog's Avatar
 
Join Date: Jan 2002
Location: The Nexus
Posts: 13,347
FastCGI won't protect against a direct hack but helps protect you against a worm on a server that may spread between sites. To use FastCGI just tick in Plesk.
__________________
Laurence - [HostNexus Administrator]

- Need Support? Quickest reponses are found at the Support Helpdesk!
- Stay in touch! Make sure you are subscribed to our Lists.
NexDog is offline   Reply With Quote
Old 06-02-2010, 06:34 AM   #13
You and what a
 
RobbieLePommie's Avatar
 
Join Date: Aug 2002
Location: Sydney
Posts: 5,936
Coming a bit late in on this one....

We had this all over another shared server for my work [not HostNexus] been fighting it for a few weeks before this thread, even.

Actions taken:
- Delete unused wordpress, make sure others are updates.
- Checked the users to ensure that they are no suspricious ones,
- Looked for all *.php files containing "eval(base64_decode(" (without the quotes) ; these are about 6 lines long and are the entry point.
- And then comes the hard part - establishing what has changed . The hacker on the shared server we used liked injecting scripts into the HTML, so we just hunted for "document.write(unescape(" (without the quotes) and, once ruling out the Google Analytics code, we found some of the damage.
- We set a monitoring script to establish when a file was updated (this e-mailed several of us, plus the last few entries in the log file - and is how we're picking off the entry points)
- Finally set permissons to lock down what could be written to. One downside of running PHP as fast-cgi is that PHP runs with the same permissions as the ftp-user; if you run as a module, then it runs with Aapache permissions and these are easier to lock. We also set permissions so that other users on the server couldn't write to our area.

A right pain - but that's the downside of "free" software.
__________________
Rob
----------------------------
For your information, there's a lot more to ogres than people think.
RobbieLePommie is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 05:55 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 RC1
Copyright ©2001 - 2009, HostNexus