Hi,
my WordPress websites are hacked daily as well as the some other domain directory without website init, random .php files are uploaded/injected. Also some wp code files, like index, wp-config, wp-setting, are injected with extra encrypted code, I am quick to delete the problematic code manually but it comes back the next day every day. I am sick of it.
We are changing all FTP, wordpress, c-panels passwords to very difficult one, updating plugins, delete all free plugins do whatever i can, but can't identify the problem that how the random .php files has been created, or avoid it.
The most interesting fact is that all the malicious php files created on the day were stated that the "Last Modified Date" was long times ago. For example, yesterday i check the website, I deleted all malicious files and php code, all clean, it's all good. This morning, some malicious php files were created with the Last Modified date of, e.g. 20 Dec 218. How's that possible?
I am wondering if it is possible to see how the .php files are being injected?
how they are being added to the account?
would the logs help me see where it's coming from? if so, where can i find the log? thanks
what is the most effective way to avoid them?
See screen capture:
Plz see the screen capture files
my WordPress websites are hacked daily as well as the some other domain directory without website init, random .php files are uploaded/injected. Also some wp code files, like index, wp-config, wp-setting, are injected with extra encrypted code, I am quick to delete the problematic code manually but it comes back the next day every day. I am sick of it.
We are changing all FTP, wordpress, c-panels passwords to very difficult one, updating plugins, delete all free plugins do whatever i can, but can't identify the problem that how the random .php files has been created, or avoid it.
The most interesting fact is that all the malicious php files created on the day were stated that the "Last Modified Date" was long times ago. For example, yesterday i check the website, I deleted all malicious files and php code, all clean, it's all good. This morning, some malicious php files were created with the Last Modified date of, e.g. 20 Dec 218. How's that possible?
I am wondering if it is possible to see how the .php files are being injected?
how they are being added to the account?
would the logs help me see where it's coming from? if so, where can i find the log? thanks
what is the most effective way to avoid them?
See screen capture:
Plz see the screen capture files
Attachments
-
222.9 KB Views: 7
-
331.9 KB Views: 6
-
260.4 KB Views: 6
-
348.5 KB Views: 6
-
326 KB Views: 6
-
197.6 KB Views: 7
Last edited by a moderator: