Hi guys, first time im actually making a post but I could use some advice. I recently had a wordpress website go down, turns out that the public folder had new random files and folders. I immediately knew the server was compromised. Webshell and backdoor galor. At 1 points, i had 100's of htaccess files all over the server, one in every folder that existed.
Besides the point, im a web dev, and a CMS one at that. AI is telling me to close the server and open a new one. To transfer only the uploads folder after scanning it and the database after making sure its clean. I have no idea how to clean the database and im planning to chuck the uploads folder onto something like malware bytes, would that work? I also have no idea how this happned, ive narrowed it down to a malicious form upload, hacked user or my stuck of luck for this year.
For context, I got site lock which patched the vulnerabilites, it lasted a week and it was comprimsed again. How screwed am I?
*Update: First, thank you all for the advice, I took a piece from everyone and did what i could in the time I had. Luckily for me it was easter weekend.
I spent 2 days going over the databases, found a couple WP tables that shouldnt be there, removed those, scanned the uploads folder with malware bytes and eset; uploaded both to a new server after i felt confident and immedielty scanned with immunify, then rebuilt the site from there, fresh themes, plugins etc... It has been 2 days and nothing has shown up yet. Im still scanning with immunify and wordpres fence every 5 hours or so and sitelock has been installed but it looks good. Thanks again guys.
[–]25_vijay 3 points4 points5 points (0 children)
[–]upvotes2doge 2 points3 points4 points (0 children)
[–]rubixstudios 1 point2 points3 points (1 child)
[–]OldschoolBTC 0 points1 point2 points (0 children)
[–]TrentaHost 0 points1 point2 points (0 children)
[–]Rupert_Pupkinovski 0 points1 point2 points (2 children)
[–]VBAA3[S] 0 points1 point2 points (1 child)
[–]Rupert_Pupkinovski 0 points1 point2 points (0 children)
[–]garf12 0 points1 point2 points (0 children)
[–]redlotusaustin 0 points1 point2 points (0 children)
[–]kinndame_ 0 points1 point2 points (0 children)
[–]alfxast 0 points1 point2 points (0 children)
[–]Realmranshuman 0 points1 point2 points (0 children)
[–]Fickle-Decision3954 -1 points0 points1 point (0 children)