• Black Blog Media
    • Home
    • News
    • Videos
    • Security
    • Social Media
    • Monetization
    • Bloggers
    • Tech
    • SEO
  • Tags: security

    After An Attack: The Aftermath

    Written by zillz s
    • Tweet
    0 comments
    I apologize for the melodrama...kinda. But you are here, and that's what matters! :) I hope that you are enjoying your Labor Day.

    My blackberry and my gmail account was ON FIRE Friday.

    Users approached me with questions such as, "why would hackers create such attacks on their sites?"

    To answer such a question, you might as well have ask, "why would a person do anything?" It's an answer that you'll be pondering for awhile, and then all of a sudden you'll resign to the true answer, which just may be the simplest: "Because they can." And you'll find that the time you've taken pondering such an act would be better spent on securing and prevention of exploiting vulnerabilities in your system.

    A lot of infected/affected users have used some of the suggestions that I posted here, but ultimately, even if you've gone through the suggested items, the attack not only gets into your WP core files...but also your database. You'll have to reinstall fresh.

    That means you can do it, or hire some guy to do it.

    1. First fix the permalink structure. You can do so by entering your admin area, choose Settings. Choose Permalinks. And choose your preferred setting. Most of our users either have Day and Name or Month and Name. If I designed your site, I most likely chose Day and Name. Goto your plugins page. Note the plugins that you find necessary. Go to your Appearance tab, click widgets. Save all of the information that is present in your text widgets. Save it in some text file or something.

    2. You will have to export your content in a WXR format (wordpress extended rss). To do so, while you are still in your admin, choose Tools and then Export. I would also suggest that users attribute all content to ONE user. I say this because since the hack is also listed, but not seen, as an administrator, you don't want to take chances.

    export to wxr

    3. Once you've made sure that you have the WXR file, you'll want to back up your site's theme files, and your images in your uploads folder. You can do so by FTP or by using whatever program that your host uses for file transfer. I know that GoDaddy has a java solution for this; Dreamhost uses a web application; and those that have cPanel (bluehost, hostgator, etc.) can use File Manager. Check with your host. Get busy.

    4. Confirm that you have what you needed to save. Next you have to delete all of your wordpress files and its database. If you have used something with a one-click install, fantastico, etc., then I suggest that you check with that first. There may be a one-click uninstall as well. Being that the methods of uninstalling and installing WP can generally change from host to host, make sure that you follow THEIR instructions. Confirm deletion of files and database.

    5. Reinstall WP with preferred or host-suggested method. Make sure that you are using the latest stable. Upload your uploads and theme folder. Set your permalinks. Add the latest version of your chosen plugins, paste in your widget stuffs, and finally import your posts...and pray that the plugins still work with the latest WP setup.

    At this point, you're like "phew! I'm glad this is over!" Well, you've just installed the latest WP and got rid of the hack. You still have some work to do to fortify your installation. We'll deal with that a little later.
    • Stay up-to-date with the latest Tips, Monetization, SEO and more! Follow Black Blog Media on Twitter and Facebook and Enter Your E-mail Address For Updates.

    0 comments:

    Post a Comment

    Newer Post Older Post Home
    Subscribe to: Post Comments (Atom)
    • May (1)
    • March (1)
    • February (2)
    • January (3)
    • December (3)
    • November (3)
    • October (5)
    • September (5)
    • August (7)
    • July (9)
    • June (6)
    • May (2)
    • April (3)
    • March (8)
    • January (4)
    • December (6)
    • November (12)
    • October (15)
    • September (11)
    • August (18)
    • July (27)
    • June (21)
    • May (8)
    • April (6)
    • March (6)
    • February (8)
    • January (11)
    • December (8)
    • November (13)
    • October (19)
    • September (16)
    • August (18)
    • March (1)
  • Popular Posts

    • Instagramers: Please Don't Bore Me With Your Lame Pictures
      T here was big hype when Instagr.am debuted on Android this spring ( iPhone users felt like the spoiled child whose mother is forcing them...
    • Black in America 4: The New Promised Land - Silicon Valley Trailer
      CNN's Soledad O'Brien follows entrepreneurs as they pitch their technology ideas to investors in Silicon Valley. Black in America 4: Jou...
    • Mark Zuckerberg: Inside Facebook
      As I was watching the news about Facebook's $5B IPO, CNBC aired a special they acquired from BBC on the inner workings of Facebook. Someth...
    • 4 Tips For Social Media Beginners
      Social Media Can Be A Pain In The Ass Do I really need social media? I can’t tell you how many times I’ve been asked this question. So I’...
    • Stuxnet: Cyber Warfare Goes Mainstream
      Steve Kroft talks to internet security experts about a sophisticated digital assassin called Stuxnet. The virus was so complex and well-w...

    Stay Connected

    Sign up for updates to your inbox

    Exits

    • BBM on Twitter
    • BBM on Facebook
    • Pumpsicle
    • MANDOM Magazine
    • ZS Music Blog
    • DESTROY The Innanet
    • Black Weblog Awards
  • Black Blog Media
    Zillz Designed It
  • Articles  |  BBM blog  |  Twitter |  Facebook |  Contact |  Exits

    Black Blog Media is an educational social media and Web 2.0 news source for bloggers with any level of experience. All items are property of their respective owners. BlackBlogMedia assumes no responsibility for those items. If there is a discrepancy, please do not hesitate to contact us.


    © 2009 - 2012 Black Blog Media |  Terms & Policy |  RSS Feed XML |  Sitemap
    ZS Music Blog |  MANDOM Magazine |  DESTROY The Innanet |  Pumpsicle