Wordpress & 123-reg

Soldato
Joined
12 Nov 2002
Posts
14,600
Location
In my own little world
Twice in the last 6 months I've had a trojan get into my hosting and start diverting the browser to another web page. This morning I received an email from [email protected] saying someone had posted a comment and to allow or disallow. I clicked on the link (it actually displayed the url) and once my Wordpress page opened a strange pdf document also opened that was in English but didn't make much sense. Looking back through the Acrobat Reader previous documents it opened from my profile temp folder (been deleted now).

I've since downloaded the contents of the site and run scans with AVG, Defender and Ad-aware on the folder and my whole computer and found nothing. Last time this happened I did the same before uploading the contents again and everything was fine, I also changed my login details just to be certain. The strange thing was 123-reg had no idea as if they don't run any security scans them selves which makes me believe their hosting is compromised as I haven't logged into the site for 3 months as I use it purely for my own entertainment.

MW
 
As with all open source software, you need to keep both Wordpress and any plugins up to date. Vulnerabilities are frequent and very dangerous.

I'd be surprised if 123-reg were at fault.
 
I've updated all the plugins and wordpress and will see what happens.

It was the AVG IE plugin that picked up the trojan and warned me it was there.

MW
 
Watch out - the attackers might have left a backdoor script (or 10) behind which will let them modify your site again without needing to re-exploit the original vulnerability.
 
Back
Top Bottom