Finding vulnerability allowing hack?
Just noticed that from yesterday someone has logged into admin and was running some scripts unauthorized.
And just now, I seen a new plugin get created which I deleted right away
I have already changed permissions for that admin and password, but I think they can use any as I seen my name used from a Russian ip address.
What an I do to find & remove their way in?
Here is log shot from first attack:
30151 smolinaro 12:16, 22nd Jun 2015 plugin.php update plugin id = 1869 178.73.196.73
30150 smolinaro 12:15, 22nd Jun 2015 plugin.php edit plugin id = 1869 178.73.196.73
30149 smolinaro 12:15, 22nd Jun 2015 plugin.php update plugin id = 1869 178.73.196.73
30148 smolinaro 12:15, 22nd Jun 2015 modlog.php choose 178.73.196.73
30147 smolinaro 12:14, 22nd Jun 2015 plugin.php edit plugin id = 1869 178.73.196.73
30146 smolinaro 12:13, 22nd Jun 2015 plugin.php 178.73.196.73
30145 smolinaro 12:13, 22nd Jun 2015 plugin.php update 178.73.196.73
30144 smolinaro 12:06, 22nd Jun 2015 plugin.php add 178.73.196.73
30143 smolinaro 12:05, 22nd Jun 2015 plugin.php files 178.73.196.73
30142 smolinaro 12:05, 22nd Jun 2015 plugin.php modify 178.73.196.73
30141 smolinaro 11:59, 22nd Jun 2015 cronadmin.php edit 178.73.196.73
30140 smolinaro 11:58, 22nd Jun 2015 adminlog.php choose 178.73.196.73
30139 smolinaro 11:57, 22nd Jun 2015 subscriptions.php transactions 178.73.196.73
|