1. Halo Guest, pastikan Anda selalu menaati peraturan forum sebelum mengirimkan post atau thread baru.

Yang ini HACK nya parah banget, ADUHHH!!

Discussion in 'Wordpress' started by heri83, Jan 9, 2012.

  1. Jamalhacker

    Jamalhacker Super Hero

    Joined:
    Feb 12, 2011
    Messages:
    805
    Likes Received:
    18
    Biasanya bukan hanya blog sobat aja yang kena. Tp, seluruh blog yang sama-sama menggunakan 1 server shared hosting dengan agan. Soalnya, kalau nembus WP itu susah gan, tapi klo nembus server shared hosting lumayan mudah dibanding nembus WP.Klo ane sih biasanya di deface aja, hahaha...
     
  2. halflight

    halflight Super Hero

    Joined:
    Jun 4, 2009
    Messages:
    1,156
    Likes Received:
    66
    Location:
    In your mind...
    wah... parah nie... hacker2 makin merajalela... :|
     
  3. indrazack

    indrazack Newbie

    Joined:
    Oct 13, 2011
    Messages:
    33
    Likes Received:
    0
    Nemu article dr Wordpress.org


    Problem solved - I hope (and strongly believe)
    - I closed down the site with a simple "site's down" index.html file on root (to avoid malware problems for visitors)
    - Shut out all .com visitors temporarily using WP Ban (hxxp://lesterchan.net/portfolio/programming/php), since the attack came from/via the US.
    - removed all files not in use on the server, including themes, plugins and even a phpMyAdmin installation
    - upgraded from WP 2.6.2 to 2.6.5. No plugins failed (which would be the case with the newest WP, 2.7.1)
    - Installed AskApache Password Protect (hxxp://wordpress.org/extend/plugins/askapache-password-protect/) (great tip from jdembowski above - in Hardening WordPress) to make a protective shield around the site.
    - Scanned site using WP Exploit scanner (http://ocaoimh.ie/exploit-scanner/) and the freeware antivirus and link-checker software AVG (hxxp://free.avg.com/download?prd=afe). Even avg found things the plugins didn't discover. Eg Symantec didn't find anything on a downloaded copy of the site.
    Using antivirus software was far from obvious. As a Mac user this is just not a common problem.
    - After finding a hack in one plugin I replaced most of them with fresh copies. (We're talking about a site with three WP installs, just one was hacked.)
    - Placed an empty index.html file in the plugins folder (to avoid robots from entering)
    - Removed the .com ban
    - Asked visitors to report eventual problems
    Think that was all.
    It's just amazing how much time one can waste because some silly jerk manages to enter your site.
    I hope procedure can help others. Feel free to add other tips!
    Kjetil


    sumber: hxxp://wordpress.org/support/topic/best-way-to-avoid-hackers
     
    Last edited by a moderator: Jan 12, 2012
  4. dedensupiyanto

    dedensupiyanto Super Hero

    Joined:
    Jun 26, 2010
    Messages:
    2,089
    Likes Received:
    441
    Location:
    RahasiaFB.Info
    Wah mantabs bener, dikupas tuntas dimari ne.. Ikut nyimak aja deh..
     
  5. gadgets

    gadgets Ads.id Starter

    Joined:
    Nov 25, 2009
    Messages:
    91
    Likes Received:
    1
    Location:
    Surabaya
    Sharing aja barangkali manfaat

    biasanya klo wordpress masuknya hacker dari theme atau plugin, jadi teliti dan hati2 menggunakan theme atau plugin yg dijual tapi dapetnya free, biasanya theme atau plugin free sudah diberi code tertentu untuk exploit, atau mungkin dari plugin yg lagi dipake, tapi ada bug yg ga ketahuan

    install anti virus dikomputer agan2, saya pake avast, update terus, klo ada yg inject script ke website kita, biasanya avast langsung detect sebagai trojan dan bisa ditunjukkan folder dan filenya, meskipun kita buka langsung, jadi bisa cepet ketahuan

    script inject biasanya ada di folder wp admin, wp content theme atau plugin, biasanya file yg dinject index.php footer.php, function.php

    klo dah kejadian dihack, coba nonaktifkan dulu plugin yg mencurigakan, klo dah terlanjur ga bisa login ke wp admin, buka lewat ftp..lanjut ke wp content - plugin, rename plugin yg mencurigakan agar deactive

    cari script inject pada file yg mencurigakan, lalu hapus

    selalu update versi wordpress anda, jangan pake theme atau plugin yg tidak compatible update wordpress..krn theme atau plugin yg tidak update rawan adanya bug yg bisa dijadikan jalan masuk hacker

    Jadwalkan Selalu backup website anda, seluruh file dan folder wordpress juga databasenya.


    klo ada yg salah mohon maaf gan...

    ane nubie yg masih belajar
     
  6. bimapraze

    bimapraze Super Hero

    Joined:
    Apr 1, 2010
    Messages:
    883
    Likes Received:
    66
    Location:
    Pendopo Islam Kejawen
    ganti theme aja gan
     
  7. hernawanjr

    hernawanjr Super Hero

    Joined:
    May 31, 2010
    Messages:
    857
    Likes Received:
    32
    Location:
    di hatimu
    wadu sama,, kena juga aneee
     
  8. Phoenix009

    Phoenix009 Ads.id Fan

    Joined:
    Dec 1, 2009
    Messages:
    147
    Likes Received:
    1
    Location:
    surabaya
    hadeh,, masih aja ada yg iseng seperti ini..

    jangan pake yg nulled mas bro untuk pluginnya jadinya ya gt klo ada yg nulled2 :senyum:
     
  9. moneyhunter

    moneyhunter Super Hero

    Joined:
    Jun 22, 2010
    Messages:
    828
    Likes Received:
    242
    Location:
    free forex signal www.fxbom.com
    ente mainan CPM model paid to promote ga? itu kan suka redirect ke adsnya kalo ga ya berarti hackernya menggunakan metode yang sama seperti CPM yang suka redirect ke situs adsnya. coba di scan pake sucuri.net bagus tuh buat ngecek script2 yang berbau hacking
     
  10. jawsplanet

    jawsplanet Super Hero

    Joined:
    Apr 12, 2011
    Messages:
    1,776
    Likes Received:
    104
    Location:
    Tangerang
    wah,baru tau ane ada web yg bisa ngecek script berbau hack sob :D
     
  11. hernawanjr

    hernawanjr Super Hero

    Joined:
    May 31, 2010
    Messages:
    857
    Likes Received:
    32
    Location:
    di hatimu
    gimana nih cara pencegahannya,,,???
     
  12. Reynaldi Hartono

    Reynaldi Hartono Super Hero

    Joined:
    Feb 19, 2010
    Messages:
    764
    Likes Received:
    48
    coba cek file .htaccess gan. Siapa tahu itu yang diinject.
     
  13. n1vXchi

    n1vXchi Newbie

    Joined:
    Dec 26, 2011
    Messages:
    17
    Likes Received:
    0
    Kalau kasusnya seperti ini bisa saja visitor yang dari USA dah difilter untuk redirect ke situsnya yang ngehack. Filternya ada di file .htaccess, kalau pake cpanel buka aja lewat File Manager. Jangan lupa centang option Show Dot Files.
     
  14. hernawanjr

    hernawanjr Super Hero

    Joined:
    May 31, 2010
    Messages:
    857
    Likes Received:
    32
    Location:
    di hatimu
    kali ini sy cuma function.php yg diserang
    htaccess n laennya msh aman
    ni bug nya di mana,,,,,

    trpaksa smntara cm bisa chmod 555 theme files /:)
     
  15. joufi

    joufi Ads.id Fan

    Joined:
    Jan 8, 2009
    Messages:
    202
    Likes Received:
    0
    Coba scan pake plugin TAC masbro
     
    Last edited: Jan 13, 2012
  16. 7heaven

    7heaven Ads.id Fan

    Joined:
    Jul 29, 2009
    Messages:
    125
    Likes Received:
    3
    Location:
    UK
    Hahaha :lol:
    dulu ane jg pernah ngalamin yg kyk gini... :nangis:
    siapa bilang gak ada untungnya ? ada kok...ane dpt 3000 unique visitors per hari sampe situs ane yg rangkingnya jutaan tembus 300 ribuan di alexa :silau:

    sama bro...dulu ane jg kelimpungan nyari dimana2
    sampe akhirnya gak sengaja nemu script yg bisa bersiinnya...
    klo gak salah nama penyakit yg situs bro derita => injected iframe
    artinya ada script iframe yg ditanamkan di situs masbro oleh hacker
    sehingga menyebabkan redirect k situs laen...

    penyebabnya ?

    klo ane DULU...gara2 pake software FTP bajakan yg dapet2 aj dr situs crack-an
    tanpa ane sadari, software FTP tsb lgsg mengirimkan info situs kita k hacker yg bersangkutan !

    cara bersiinnya?

    -silaken download script pembersihnya di hxxp : // www. produk-digital .com / cleaninjectedcode.rar (tanpa spasi)
    -extract, n upload di situs/blog masbro
    -dah itu, akses lewat browser, maka akan tampil seperti ini : View attachment 15285
    -centang auto clean nya n klik start
    -jgn lupa lakukan hal yg sama di semua direktori2 yg ada di situ biar BERSIH !

    yakin bisa ?
    hmmm klo saya dulu gitu bro...dan kasusnya sama...jd saya rasa it's works! intinya, saya just share aja...siapa tau bisa membantu...

    pencegahan ?

    -ganti password ftp hosting kamu secara berkala
    -jangan simpan username dan password ftp di ftp client komputer !
    -jangan install blog/website pakai fantastico/one click installer yang disediakan hosting kamu

    oke masbro, segitu dulu aja deh....moga bermanfaat ! :cerutu:
     
    heri83 and roulette like this.
  17. jawsplanet

    jawsplanet Super Hero

    Joined:
    Apr 12, 2011
    Messages:
    1,776
    Likes Received:
    104
    Location:
    Tangerang
    wah,thanks sob,ane coba dlu
    buat ngecek web2 ane
     
  18. anti83

    anti83 Newbie

    Joined:
    Jul 7, 2011
    Messages:
    25
    Likes Received:
    2

    Makasih mas 7 heaven..kyknya bisa dipakai nih caranya..blog ane jg hampir mirip kena hacknya..
     
  19. sangdj

    sangdj Newbie

    Joined:
    Jan 13, 2012
    Messages:
    22
    Likes Received:
    1
    kemarin situs ane jga kena deface, yg deface sepertinya dari arab soalnya pake huruf arab semua.
     
  20. roulette

    roulette Super Hero

    Joined:
    Jan 14, 2011
    Messages:
    1,309
    Likes Received:
    468
    Location:
    Kota Angin
    wewww,,, suka deh gan! jempol penceted!

    :hmm2: berarti ini hacker cuma nyaring visitor dari US doank ye! anjlok donk traffik blog kita! cek n ricek dulu ahh,,,
     

Share This Page