Support Forum

Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
general-topic
Complete reinstall
Avatar
fiddlerman
Member
Free Members
sp_UserOfflineSmall Offline
Jul 27, 2012 - 6:25 am

Apparently my Violaman.com site was hacked. Thankfully it's not on the same server as FiddlerMan.com and doesn't get much traffic but somehow it's the one that always gets hacked.

I have the forum set as the home page for the site and can only presently run the site if I move or delete the simple-press folder. I can't even get on my wp-admin if the plugin is activated.

Now to my question: I reinstalled the simple-press folder and upgraded the plugin and still had the same problem. What are all the files and or folders that must be reinstalled to do a full and complete reinstall? Hopefully the problem is not in my database.
If it is, we'll have to deal with that afterwards.

"The richest person is not the one who has the most, but the one who needs the least."


Learn to Play Violin for Free - http://www.fiddlerman.com

Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Jul 27, 2012 - 8:58 am

afraid you wont like the answer... the only files required to run simple press are the plugin files in plugins/simple-press itself... at least that I can think of that would keep any part of the site from working... but not sure why db issues would even bring down the whole site...

so lets start from the beginning and be a bit more detailed about what can only run the site and admin if the plugin is deleted... what does that mean? what do you see on any page front or back?? and anything in the server error log?

Avatar
fiddlerman
Member
Free Members
sp_UserOfflineSmall Offline
Jul 29, 2012 - 10:41 pm

When I try to activate the forum I receive this warning:

"Plugin could not be activated because it triggered a fatal error."

"The richest person is not the one who has the most, but the one who needs the least."


Learn to Play Violin for Free - http://www.fiddlerman.com

Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Jul 29, 2012 - 11:48 pm

how did you get the plugin to your server? looks like maybe the wp plugin installer which does not work on plugins with more then 1 directory level depth... can you confirm?

Avatar
fiddlerman
Member
Free Members
sp_UserOfflineSmall Offline
Jul 30, 2012 - 5:55 am

I uploaded it directly via FTP. Took the latest one from the download page.

"The richest person is not the one who has the most, but the one who needs the least."


Learn to Play Violin for Free - http://www.fiddlerman.com

Avatar
Yellow Swordfish
Glinton, England
SP Master
sp_UserOfflineSmall Offline
Jul 30, 2012 - 6:12 am

So what else? Did you remove all the files that were already there first? Which might be worthwhile. And what version was running previously? And can you define what you mean by 'hacked'? What exactly happened?

andy-signature.png
YELLOW
SWORDFISH
Avatar
fiddlerman
Member
Free Members
sp_UserOfflineSmall Offline
Jul 30, 2012 - 6:25 am

I deleted the whole simple-press folder first, then uploaded a new one from your download page. The replacement that I uploaded was also the latest version.

Which files are you referring to removing? I only replaced the simple-press folder and nothing else. Should I remove the /wp-content/sp-resources folder too? Any other folders or files? I was able to get the site working but the only plugin that won't activate is the simple:press plugin.

According to my host:

Pierre,

It looks to me like the files were hacked and something inserted in to most of them, I tried to replace the core wordpress files from the base package but still having trouble with it. Do you have a clean backup copy of the site?
-------------------------
Regards,

James
GOTOnames Support Department

"The richest person is not the one who has the most, but the one who needs the least."


Learn to Play Violin for Free - http://www.fiddlerman.com

Avatar
Yellow Swordfish
Glinton, England
SP Master
sp_UserOfflineSmall Offline
Jul 30, 2012 - 7:39 am

Sounds like you did the right thing.

The problem here is that we have many hundreds of downloads and activations that do NOT trigger any errors so assuming the files you uploaded were not themselves corrupted in any way there should be no reason why yours should be any different.

Coupled to this is the fact that the WP message is woefully useless and of no help at all. It also does not necessarily mean that the problem lies in SP. I am not for one moment trying to claim that the problem can NOT lie in SP - just pointing out the probabilities.

'It looks to me like the files were hacked and something inserted in to most of them' is also not really that informative.

If this were me I would be replacing the entire WordPress codebase. NOT the 'wp-content' folder initially but all of the rest. 'wp-content' is for your themes and plugins and other data so that needs to remain and, if necessary, be combed manually for any issues if they remain when all of the other code is replaced.

It would be useful if your host were to actually look into how any attack happened in the first place.

andy-signature.png
YELLOW
SWORDFISH
Avatar
fiddlerman
Member
Free Members
sp_UserOfflineSmall Offline
Jul 30, 2012 - 7:53 am

Thanks,

I realize that my host is not very useful. I guess you get what you pay for. I asked several times how the attacks could have taken place and which files were added but never a response.

Since I have switched hosts with Fiddlerman.com I have never had an issue.

Thanks for your great and quick reply as usual.

"The richest person is not the one who has the most, but the one who needs the least."


Learn to Play Violin for Free - http://www.fiddlerman.com

Avatar
Yellow Swordfish
Glinton, England
SP Master
sp_UserOfflineSmall Offline
Jul 30, 2012 - 7:57 am

Please do let us know what you do and if it works etc...

andy-signature.png
YELLOW
SWORDFISH
Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1170
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Mr Papa: 19448
Ike: 2086
Brandon: 864
kvr28: 804
jim: 650
FidoSysop: 577
Conrad_Farlow: 531
fiddlerman: 358
Stefano Prete: 325
Member Stats:
Guest Posters: 620
Members: 17370
Moderators: 0
Admins: 4
Forum Stats:
Groups: 7
Forums: 17
Topics: 10128
Posts: 79626