Jump to content


Photo
- - - - -

My first hack! All .php files effected. Help...


  • Please log in to reply
5 replies to this topic

#1 robbin_g

robbin_g

    Advanced Member

  • Members
  • 57 posts
  • Country: Country Flag

Posted 26 February 2012 - 03:11 PM

Wheeeee! So I've been hacked by a .ru redirect bot. Joy of Joys. Apparently all .php files were modified with in a 5 minute period last Tuesday. I'm willing to take the time to manually restore things as my last back up is old-ish. What are the files that are most critical to my PageLines and WordPress install/layout that SHOULDN'T be obliterated by a clean install and edited manually? Thanks in advance...

#2 catrina

catrina

    Advocate

  • Members
  • 12345 posts
  • LocationCalifornia
  • Country: Country Flag

Posted 26 February 2012 - 05:30 PM

Were there any customizations you made using the Pagelines Customize plugin? If so, perhaps you should save those files so you don't have to make the customizations again.

#3 robbin_g

robbin_g

    Advanced Member

  • Members
  • 57 posts
  • Country: Country Flag

Posted 28 February 2012 - 04:32 PM

What are those files called so I can copy them?

#4 catrina

catrina

    Advocate

  • Members
  • 12345 posts
  • LocationCalifornia
  • Country: Country Flag

Posted 29 February 2012 - 03:09 AM

They exist only if you're using the Pagelines Customize plugin. Included should be a style.css file and functions.php file (located in the pagelines-customize folder in the plugins directory).

#5 robbin_g

robbin_g

    Advanced Member

  • Members
  • 57 posts
  • Country: Country Flag

Posted 01 March 2012 - 10:24 AM

I've been manually editing .php files for days. I hope I found the worm file that rewrote them all....

#6 Danny

Danny

    Is Awesome!

  • Moderators
  • 17015 posts
  • LocationManchester, UK
  • Country: Country Flag

Posted 01 March 2012 - 12:02 PM

Hi Robbin, If you've been hacked then I highly recommend you start from fresh just to be on the safe side, rather than edit the files manually. Also, who is your host ?