{"id":10992,"date":"2017-12-28T13:51:36","date_gmt":"2017-12-28T12:51:36","guid":{"rendered":"http:\/\/flaven.fr\/?p=10992"},"modified":"2017-12-28T19:48:54","modified_gmt":"2017-12-28T18:48:54","slug":"hack-wordpress-a-quick-introduction-to-diagnose-restore-and-protect-a-hacked-wordpress","status":"publish","type":"post","link":"https:\/\/flaven.fr\/2017\/12\/hack-wordpress-a-quick-introduction-to-diagnose-restore-and-protect-a-hacked-wordpress\/","title":{"rendered":"Hack, WordPress &#8211; A quick introduction to diagnose, restore and protect a hacked WordPress"},"content":{"rendered":"<p>I do mainly today mobile applications but I have still few websites running on WP and I have worked with WordPress since a long time. It is an easy, nice and economic way to make a website or even to run an API for a mobile application. Mostly because WordPress is very simple to take in hand for newbies.<\/p>\n<p><b>The drawback of WordPress is the extreme vulnerability of the CMS to hacking. If you possesses a WP in production, be sure to look after it, making the required updates especially both for themes, plugins and the core code. If not, soon your site will be vulnerable and an easy prey for hackers even the most novice ones.<\/b><\/p>\n<p>Is it the approach of Christmas Time or the end of the year? Some hackers made me a present : they have brutally hacked one of the WP site that I have installed long time ago.<\/p>\n<p>Who to blame ? No-one, expect me, the site owner or both of us. Indeed, the updates have been not been made properly, nothing has been really made to secure the installation&#8230; I know few people who are managing web servers that I have a word for WP that is relegated to a noxious plague known as WordPox. There is also some sexist and delicate designations for WP, known as &#8220;pute digitale&#8221; or the more scatological  &#8220;pezzo di merda secca digitale&#8221;. Anyway something that is turning around the concept of digital whore that seems accessible to anyone but with a very high risk on contamination. Oooops.<br \/>\nIndeed, this is outrageously sexist and inaccurate towards WP if you intend to take some prophylactic measures, that we will see in a couple of lines below.<\/p>\n<p>Anyway, the very first reaction when your site is hacked is that you feel sorry not to have been more cautious. When, you check the website from codex.wordpress.org, the first advice is pretty simple and quite wisely too.<\/p>\n<blockquote>\n<p><b>Stay calm.<\/b><\/p>\n<p>When addressing a security issue, as a website owner, you&#8217;re likely experiencing an undue amount of stress. It&#8217;s often the most vulnerable you have found yourself since being on line and it&#8217;s contrary to what every one told you, &#8220;Hey, WordPress is Easy!!&#8221;<\/p>\n<\/blockquote>\n<p>Source :  <a href=\"https:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked\" target=\"_blank\">https:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked<\/a><\/p>\n<p>Apart from being calm, I was wondering what kind of venereal disease or I&#8217;d rather what kind of &#8220;French disease&#8221; the WordPress installation  has contracted.<\/p>\n<h4>What kind of hack is that?<\/h4>\n<p>Just find this weird injection at the beginning of the wp-config.php file&#8230;. Ugly, is that serious Doctor ?<br \/>\nThen, after, you find this, you just follow the thread of the ball to the source with the help of Google and Malwaredecoder.com<\/p>\n<p><b>The infected file<\/b><\/p>\n<pre lang=\"php\">@include \"...wp-\\x63onte\\x6et\/pl\\x75gins\\x2fakis\\x6det\/f\\x61vico\\x6e_9e3\\x335b.i\\x63o\";<\/pre>\n<p><b>The path decoded by alwaredecoder.com<\/b><\/p>\n<pre lang=\"php\">@include \"\/[path-to-the-wp-install]\/wp-content\/plugins\/akismet\/favicon_cr6m5a.ico\";<\/pre>\n<p><b>Rename favicon_cr6m5a.ico to favicon_cr6m5a.txt then make obfuscation code reverse engineering with malwaredecoder.com<\/b><\/p>\n<pre lang=\"php\">\r\nif (!defined('ALREADY_RUN_i9gf4u95y82hhxk6vnqq1wkmd2yrbrb'))\r\n{\r\ndefine('ALREADY_RUN_i9gf4u95y82hhxk6vnqq1wkmd2yrbrb', 1);\r\n\r\n $vzmykcweljo = 0512; function mmaxsv($jvhlpxcgue, $nxnkuazsjoblv){$nxnkuazsjoblv = ''; for($i=0; $i < strlen($jvhlpxcgue);\r\n ...\r\n<\/pre>\n<p><b>The path decoded by Malwaredecoder.com<\/b><\/p>\n<pre lang=\"php\">\r\n\r\n@ini_set('error_log', NULL);\r\n@ini_set('log_errors', 0);\r\n@ini_set('max_execution_time', 0);\r\n@error_reporting(0);\r\n@set_time_limit(0);\r\n\r\n\r\nif(!defined(\"PHP_EOL\"))\r\n{\r\n    define(\"PHP_EOL\", \"\\n\");\r\n}\r\n...\r\n<\/pre>\n<p>Source : <a href=\"https:\/\/malwaredecoder.com\/\" target=\"_blank\">https:\/\/malwaredecoder.com\/<\/a><\/p>\n<h4>What can I do?<\/h4>\n<p><b>Here is a quick TodoList of what you imperatively need to do if your WP has been hacked<\/b><\/p>\n<ul>\n<li>Save the wp-config.php file, your images, and your personal files one by one (not the folder as it may contain unwanted files).<\/li>\n<li>Make sure that there is no malicious code in the saved wp-config.php file.<\/li>\n<li>Wipe out the entire folder where WordPress is installed.<\/li>\n<li>Upload a new clean full package of the latest WordPress version.<\/li>\n<li>Re-upload your wp-config.php file and images.<\/li>\n<li>Re-install the latest versions of your plugins and themes.<\/li>\n<li>Change the passwords for all WordPress admin users. Please use passwords that are hard to guess.<\/li>\n<li>Change the hosting Control Panel password and all MySQL passwords.<\/li>\n<\/ul>\n<p><b>Some kind of SQL queries that will help to check the content of your database if there's been some damages.<\/b><\/p>\n<pre lang=\"sql\" escaped=\"true\">\r\nSELECT * FROM wp_posts WHERE post_content LIKE '%&lt;iframe%'\r\nUNION\r\nSELECT * FROM wp_posts WHERE post_content LIKE '%&lt;noscript%'\r\nUNION\r\nSELECT * FROM wp_posts WHERE post_content LIKE '%display:%'\r\nUNION\r\n<\/pre>\n<h4>Main security measures you can do or not...<\/h4>\n<p>Roughly, protecting WP consist of spreading Htaccess files everywhere! Htaccess files will help control the way visitors can interact with your website. The htaccess file is also used to block specific traffic from being able to view your website.<\/p>\n<p><b>1. Modify the existing .htaccess of WP<\/b><br \/>\nThe idea is to protect more carefully the access to some core files of WordPress eg wp-config.php, the .htaccess itself, prevent listing for directories...etc. You just have to modify the existing .htaccess of WP.<\/p>\n<p><b>2. Add your own .htaccess for \/wp-admin\/<\/b><br \/>\nA second .htpasswd will be created to also secure more efficiently the administration dashboard <\/p>\n<p><b>Be sure sure to place the .htpasswd, not in the root directory<\/b><\/p>\n<p><b>3. Create the file .htpasswd and add the user <i>mysuperuser<\/i><\/b><\/p>\n<pre lang=\"bash\">htpasswd -c \/[path-to-your-htpasswd-file]\/.htpasswd mysuperuser<\/pre>\n<p>If you don't current have an .htpasswd, use the \"-c\" option to create the file with the first user. It will prompt you for a password and encrypt it for you.<\/p>\n<p><b>Command to list the files including the .htpasswd<\/b><\/p>\n<pre lang=\"bash\">ls -la<\/pre>\n<p>If you already have the .htpasswd file and would like to append a new user, repeat the command with the \"-c\".<\/p>\n<p><b>Command to add a new user<\/b><\/p>\n<pre lang=\"bash\">htpasswd -c \/[path-to-your-htpasswd-file]\/.htpasswd mysuperuser2<\/pre>\n<h4>Find the real path for your WP installation<\/h4>\n<p>In order to get the real path to your WordPress installation send a php file with the following command inside at the root directory of your installation.<\/p>\n<pre lang=\"php\">\r\necho (''.getcwd().'');\r\n<\/pre>\n<p><b>You will get printed probably something like this, depending your hosting service.<\/b><br \/>\n<code>\/home\/[user-account-or-ftp-user-account]\/www<\/code><\/p>\n<p><b>Create the <code>.htpasswd<\/code> file and add a new user named <code>mysuperuser<\/code><\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_htpasswd_1.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>Enter the password for <code>mysuperuser<\/code><\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_htpasswd_2.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>You are done. Send, via FTP, the file <code>.htpasswd<\/code> out of the root dir of your WP directory<\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_htpasswd_3.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>The .htaccess that have to uploaded in the wp-admin directory. Be sure to put the correct to the .htpasswd<\/b><\/p>\n<pre lang=\"text\">\r\n# SECURITY WORDPRESS for wp-admin\r\nAuthUserFile [path-out-the-wp-dir]\/.htpasswd\r\nAuthGroupFile \/dev\/null\r\nAuthName \"Access Restricted\"\r\nAuthType Basic\r\nrequire valid-user\r\n<\/pre>\n<h4>Scanning the files of your previous WP<\/h4>\n<p>As you have made a fresh and new installation as you may need to re-upload some of the existing files from your previous WP eg uploads directory, plugins, themes...<\/p>\n<p><b>I strongly advised you to scan these files that are probably infected, with malware more discrete, so you need to find and destroy it. These files are potential threats for your new WP such as backdoors, code injections, malicious iframes, hidden eval code, the the base64 family:<code>base64_decode, gzinflate(base64_decode, eval(gzinflate(base64_decode, eval(base64_decode...<\/code> and more. We have used for this task one of the most popular plugin named wordfence<\/b><\/p>\n<p><b>Wisely, I have runned the plugin <code>wordfence<\/code> locally before uploading the all stuff on the new WP installation and guess what I found a bunch of crap installed by a hacker in order to perform malicious activity.<\/b><\/p>\n<p><b>Launching the scan, being locally accelerated the scan process.<\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_scan_wordfence_1.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>Locally, I always have weak password the famous admin:admin and <code>wordfence<\/code> warned me on that. Good Boy!<\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_scan_wordfence_2.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>This one warning is typically what I was expecting from <code>wordfence<\/code><\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_scan_wordfence_3.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<p><b>Theses warning are classical, just Out-of-Date plug-ins<\/b><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_scan_wordfence_4.jpg\" width=\"640\" height=\"480\" alt=\"Hack, WordPress - A quick introduction to diagnose, restore and protect a hacked WordPress\"><\/p>\n<h4>A possible <code>.htaccess<\/code> for your WP<\/h4>\n<p><b>The definitive <code>.htaccess<\/code> for WP. This is not this <code>.htaccess<\/code> that will protect the directory \/wp-admin\/<\/b><\/p>\n<pre lang=\"txt\" escaped=\"true\">\r\n# BEGIN WordPress\r\n&lt;IfModule mod_rewrite.c&gt; \r\nRewriteEngine On\r\nRewriteBase \/\r\nRewriteRule ^index\\.php$ - [L]\r\nRewriteCond %{REQUEST_FILENAME} !-f\r\nRewriteCond %{REQUEST_FILENAME} !-d\r\nRewriteRule . \/index.php [L]\r\n&lt;\/IfModule&gt; \r\n# END WordPress\r\n\r\n# BEGIN SECURITY\r\n\r\n# BEGIN ENVIRONMENT \r\n# SET register_globals to off security\r\nSetEnv REGISTER_GLOBALS 0\r\n# END ENVIRONMENT \r\n\r\n# NO listing for directories\r\nOptions All -Indexes\r\n\r\n# NO listing for directories\r\nIndexIgnore *\r\n\r\n# Hide server informations\r\nServerSignature Off\r\n\r\n# Enabling the tracking of symbolic links\r\nOptions +FollowSymLinks\r\n\r\n# Time zone selection\r\nSetEnv TZ Europe\/Paris\r\n\r\n# Default encoding of text and HTML files\r\nAddDefaultCharset UTF-8\r\n\r\n# protect wp-config.php\r\n&lt;Files wp-config.php&gt; \r\n    order deny,allow\r\n    deny from all\r\n&lt;\/Files&gt;\r\n \r\n# Protect .htaccess and .htpasswds files\r\n&lt;Files ~ \"^.*\\.([Hh][Tt][AaPp])\"&gt; \r\n\torder allow,deny\r\n\tdeny from all\r\n\tsatisfy all\r\n&lt;\/Files&gt; \r\n\r\n# Protect wp-login.php\r\n&lt;Files wp-login.php&gt;\r\nAuthUserFile [path-out-the-wp-dir]\/.htpasswd\r\nAuthName \"Access Restricted\"\r\nAuthType Basic\r\nrequire valid-user\r\n&lt;\/Files&gt;\r\n\r\n# Avoid comment spam\r\n&lt;IfModule mod_rewrite.c&gt; \r\nRewriteCond %{REQUEST_METHOD} POST\r\nRewriteCond %{REQUEST_URI} .wp-comments-post\\.php*\r\nRewriteCond %{HTTP_REFERER} !.your-site-domain.com.* [OR]\r\nRewriteCond %{HTTP_USER_AGENT} ^$\r\nRewriteRule (.*) ^http:\/\/%{REMOTE_ADDR}\/$ [R=301,L]\r\n&lt;\/IfModule&gt; \r\n\r\n\r\n\r\n\r\n# Avoid discovering an author's ID\r\n&lt;IfModule mod_rewrite.c&gt; \r\nRewriteCond %{QUERY_STRING} ^author=([0-9]*)\r\nRewriteRule .* - [F]\r\n&lt;\/IfModule&gt; \r\n\r\n# Disable the hot-linking of your images\r\nRewriteEngine On\r\nRewriteCond %{HTTP_REFERER} !^$\r\nRewriteCond %{HTTP_REFERER} !^http(s)?:\/\/(www\\.)?your-site-domain.com [NC]\r\nRewriteRule \\.(jpg|jpeg|png|gif)$ https:\/\/fakeimg.pl\/400x200\/?text=no-way [NC,R,L]\r\n\r\n\r\n\r\n# Caching files in the browser\r\n&lt;IfModule mod_expires.c&gt; \r\nExpiresActive On\r\nExpiresDefault \"access plus 1 month\"\r\n\r\nExpiresByType text\/html \"access plus 0 seconds\"\r\nExpiresByType text\/xml \"access plus 0 seconds\"\r\nExpiresByType application\/xml \"access plus 0 seconds\"\r\nExpiresByType application\/json \"access plus 0 seconds\"\r\nExpiresByType application\/pdf \"access plus 0 seconds\"\r\n\r\nExpiresByType application\/rss+xml \"access plus 1 hour\"\r\nExpiresByType application\/atom+xml \"access plus 1 hour\"\r\n\r\nExpiresByType application\/x-font-ttf \"access plus 1 month\"\r\nExpiresByType font\/opentype \"access plus 1 month\"\r\nExpiresByType application\/x-font-woff \"access plus 1 month\"\r\nExpiresByType application\/x-font-woff2 \"access plus 1 month\"\r\nExpiresByType image\/svg+xml \"access plus 1 month\"\r\nExpiresByType application\/vnd.ms-fontobject \"access plus 1 month\"\r\n\r\nExpiresByType image\/jpg \"access plus 1 month\"\r\nExpiresByType image\/jpeg \"access plus 1 month\"\r\nExpiresByType image\/gif \"access plus 1 month\"\r\nExpiresByType image\/png \"access plus 1 month\"\r\n\r\nExpiresByType video\/ogg \"access plus 1 month\"\r\nExpiresByType audio\/ogg \"access plus 1 month\"\r\nExpiresByType video\/mp4 \"access plus 1 month\"\r\nExpiresByType video\/webm \"access plus 1 month\"\r\n\r\nExpiresByType text\/css \"access plus 6 month\"\r\nExpiresByType application\/javascript \"access plus 6 month\"\r\n\r\nExpiresByType application\/x-shockwave-flash \"access plus 1 week\"\r\nExpiresByType image\/x-icon \"access plus 1 week\"\r\n\r\n&lt;\/IfModule&gt; \r\n\r\n# kill them etags\r\nHeader unset ETag\r\nFileETag None\r\n\r\n&lt;ifModule mod_headers.c&gt;  \r\n&lt;filesMatch \"\\.(ico|jpe?g|png|gif|swf)$\"&gt;   \r\n    Header set Cache-Control \"public\"  \r\n&lt;\/filesMatch&gt;  \r\n&lt;filesMatch \"\\.(css)$\"&gt;  \r\n    Header set Cache-Control \"public\"  \r\n&lt;\/filesMatch&gt;   \r\n&lt;filesMatch \"\\.(js)$\"&gt;   \r\n    Header set Cache-Control \"private\"  \r\n&lt;\/filesMatch&gt;   \r\n&lt;filesMatch \"\\.(x?html?|php)$\"&gt;   \r\n    Header set Cache-Control \"private, must-revalidate\"\r\n&lt;\/filesMatch&gt; \r\n&lt;\/ifModule&gt; \r\n\r\n\r\n# Compressions of static files\r\n&lt;IfModule mod_deflate.c&gt; \r\n    AddOutputFilterByType DEFLATE text\/xhtml text\/html text\/plain text\/xml text\/javascript application\/x-javascript text\/css \r\n    BrowserMatch ^Mozilla\/4 gzip-only-text\/html \r\n    BrowserMatch ^Mozilla\/4\\.0[678] no-gzip \r\n    BrowserMatch \\bMSIE !no-gzip !gzip-only-text\/html \r\n    SetEnvIfNoCase Request_URI \\.(?:gif|jpe?g|png)$ no-gzip dont-vary \r\n    Header append Vary User-Agent env=!dont-vary \r\n&lt;\/IfModule&gt;   \r\n\r\nAddOutputFilterByType DEFLATE text\/html  \r\nAddOutputFilterByType DEFLATE text\/plain  \r\nAddOutputFilterByType DEFLATE text\/xml  \r\nAddOutputFilterByType DEFLATE text\/css  \r\nAddOutputFilterByType DEFLATE text\/javascript\r\nAddOutputFilterByType DEFLATE font\/opentype\r\nAddOutputFilterByType DEFLATE application\/rss+xml\r\nAddOutputFilterByType DEFLATE application\/javascript\r\nAddOutputFilterByType DEFLATE application\/json  \r\n\r\n\r\n\r\n# Block the use of certain scripts\r\nRewriteEngine On\r\nRewriteBase \/\r\nRewriteRule ^wp-admin\/includes\/ - [F,L]\r\nRewriteRule !^wp-includes\/ - [S=3]\r\nRewriteRule ^wp-includes\/[^\/]+\\.php$ - [F,L]\r\nRewriteRule ^wp-includes\/js\/tinymce\/langs\/.+\\.php - [F,L]\r\nRewriteRule ^wp-includes\/theme-compat\/ - [F,L]\r\n\r\n\r\n# Protection against file injections\r\nRewriteCond %{REQUEST_METHOD} GET\r\nRewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=http:\/\/ [OR]\r\nRewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=(\\.\\.\/\/?)+ [OR]\r\nRewriteCond %{QUERY_STRING} [a-zA-Z0-9_]=\/([a-z0-9_.]\/\/?)+ [NC]\r\nRewriteRule .* - [F]\r\n\r\n\r\n# Protections diverses (XSS, clickjacking et MIME-Type sniffing)\r\n&lt;ifModule mod_headers.c&gt; \r\nHeader set X-XSS-Protection \"1; mode=block\"\r\nHeader always append X-Frame-Options SAMEORIGIN\r\nHeader set X-Content-Type-Options: \"nosniff\u201d\r\n&lt;\/ifModule&gt; \r\n\r\n# END SECURITY \r\n\r\n<\/pre>\n<p><b>Files on github: Models of htaccess_for_wp_admin.txt and htaccess_for_wp_root_dir.txt. Be sure to rename as .htaccess. <a href=\"https:\/\/github.com\/bflaven\/BlogArticlesExamples\/tree\/master\/hacked_of_time_wordpress\" target=\"_blank\">https:\/\/github.com\/bflaven\/BlogArticlesExamples\/tree\/master\/hacked_of_time_wordpress<\/a> <\/b><\/p>\n<h2>Read more<\/h2>\n<ul>\n<li>Plugin Security Scanner<br \/><a href=\"https:\/\/wordpress.org\/plugins\/plugin-security-scanner\/\" target=\"_blank\">https:\/\/wordpress.org\/plugins\/plugin-security-scanner\/<\/a><\/li>\n<li>Plugin wordfence<br \/><a href=\"https:\/\/wordpress.org\/plugins\/wordfence\/\" target=\"_blank\">https:\/\/wordpress.org\/plugins\/wordfence\/<\/a><\/li>\n<li>How To Scan Your WordPress Website For Hidden Malware<br \/><a href=\"https:\/\/www.elegantthemes.com\/blog\/tips-tricks\/how-to-scan-your-wordpress-website-for-hidden-malware\" target=\"_blank\">https:\/\/www.elegantthemes.com\/blog\/tips-tricks\/how-to-scan-your-wordpress-website-for-hidden-malware<\/a><\/li>\n<li>How to Fix the Internal Server Error in WordPress<br \/><a href=\"http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-fix-the-internal-server-error-in-wordpress\/\" target=\"_blank\">http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-fix-the-internal-server-error-in-wordpress\/<\/a><\/li>\n<li>WordPress pirat\u00e9, hack\u00e9 ? Comment r\u00e9agir ? (french)<br \/><a href=\"https:\/\/wpformation.com\/wordpress-pirate-hack\/\" target=\"_blank\">https:\/\/wpformation.com\/wordpress-pirate-hack\/<\/a><\/li>\n<li>Comment se fait hacker un site web WordPress ? (french)<br \/><a href=\"https:\/\/secupress.me\/fr\/blog\/comment-hacker-site-wordpress\/\" target=\"_blank\">https:\/\/secupress.me\/fr\/blog\/comment-hacker-site-wordpress\/<\/a><\/li>\n<li>Analyzing The WordPress SoakSoak Favicon Backdoor<br \/><a href=\"https:\/\/blog.sucuri.net\/2014\/12\/analyzing-the-wordpress-soaksoak-favicon-backdoor.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2014\/12\/analyzing-the-wordpress-soaksoak-favicon-backdoor.html<\/a><\/li>\n<li>Slider Revolution Plugin Critical Vulnerability Being Exploited<br \/><a href=\"https:\/\/blog.sucuri.net\/2014\/09\/slider-revolution-plugin-critical-vulnerability-being-exploited.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2014\/09\/slider-revolution-plugin-critical-vulnerability-being-exploited.html<\/a><\/li>\n<li>Online PHP Decoder<br \/><a href=\"https:\/\/malwaredecoder.com\/\" target=\"_blank\">https:\/\/malwaredecoder.com\/<\/a><\/li>\n<li>Brute Force Attacks<br \/><a href=\"https:\/\/codex.wordpress.org\/Brute_Force_Attacks\" target=\"_blank\">https:\/\/codex.wordpress.org\/Brute_Force_Attacks<\/a><\/li>\n<li>Password Protecting wp-login.php with HTTP Authentication<br \/><a href=\"https:\/\/blogvault.net\/password-protecting-wp-login-php-with-http-authentication\/\" target=\"_blank\">https:\/\/blogvault.net\/password-protecting-wp-login-php-with-http-authentication\/<\/a><\/li>\n<li>Protect WordPress Login from Brute Force Attacks with .htaccess<br \/><a href=\"https:\/\/ivycat.com\/protect-wordpress-login-brute-force-attacks-htaccess\/\" target=\"_blank\">https:\/\/ivycat.com\/protect-wordpress-login-brute-force-attacks-htaccess\/<\/a><\/li>\n<li>FAQ My site was hacked<br \/><a href=\"https:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked\" target=\"_blank\">https:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked<\/a><\/li>\n<li>How to Password Protect Your WordPress Admin (wp-admin) Directory<br \/><a href=\"http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-password-protect-your-wordpress-admin-wp-admin-directory\/\" target=\"_blank\">http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-password-protect-your-wordpress-admin-wp-admin-directory\/<\/a><\/li>\n<li>\nHow to Find a Backdoor in a Hacked WordPress Site and Fix It<br \/><a href=\"http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-find-a-backdoor-in-a-hacked-wordpress-site-and-fix-it\/\" target=\"_blank\">http:\/\/www.wpbeginner.com\/wp-tutorials\/how-to-find-a-backdoor-in-a-hacked-wordpress-site-and-fix-it\/<\/a><\/li>\n<li>How to Find the Absolute Path to Your WordPress Root Directory<br \/><a href=\"https:\/\/premium.wpmudev.org\/blog\/daily-tip-how-to-find-the-absolute-path-to-your-wordpress-root-directory\/\" target=\"_blank\">https:\/\/premium.wpmudev.org\/blog\/daily-tip-how-to-find-the-absolute-path-to-your-wordpress-root-directory\/<\/a><\/li>\n<li>Strong Password Generator<br \/><a href=\"https:\/\/strongpasswordgenerator.com\/\" target=\"_blank\">https:\/\/strongpasswordgenerator.com\/<\/a><\/li>\n<li>Le guide ultime du fichier .htaccess dans WordPress<br \/><a href=\"https:\/\/wpmarmite.com\/htaccess-wordpress\/\" target=\"_blank\">https:\/\/wpmarmite.com\/htaccess-wordpress\/<\/a><\/li>\n<li>The plugin AskApache Password Protect<br \/><a href=\"https:\/\/wordpress.org\/plugins\/askapache-password-protect\/\" target=\"_blank\">https:\/\/wordpress.org\/plugins\/askapache-password-protect\/<\/a><\/li>\n<li>20 astuces pour s\u00e9curiser votre site wordpress (french)<br \/><a href=\"https:\/\/www.wpress-assist.com\/20-astuces-pour-securiser-votre-site-wordpress\/\" target=\"_blank\">https:\/\/www.wpress-assist.com\/20-astuces-pour-securiser-votre-site-wordpress\/<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>I do mainly today mobile applications but I have still few websites running on WP and I have worked with WordPress since a long time.&hellip; <\/p>\n<p class=\"text-center\"><a href=\"https:\/\/flaven.fr\/2017\/12\/hack-wordpress-a-quick-introduction-to-diagnose-restore-and-protect-a-hacked-wordpress\/\" class=\"more-link\">Continue reading &rarr; <span class=\"screen-reader-text\">Hack, WordPress &#8211; A quick introduction to diagnose, restore and protect a hacked WordPress<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":10994,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"bf_ai_meta_description":"WordPress hacking is common. This guide covers tools and steps to diagnose, restore, and protect a hacked WordPress site effectively.","bf_ai_og_title":"Hack WordPress: Diagnose, Restore, Protect","footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[3437,3454,3444,3447,3449,3450,3435,3452],"tags":[357,2221,358,20,106,2405,2223,2406,2407],"class_list":["post-10992","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-case-studies","category-journalism-writing","category-programming-databases","category-technology-trends","category-tutorials-how-to","category-ux-product-design","category-web-development","category-wordpress-cms","tag-htpasswd","tag-cms","tag-htaccess","tag-php","tag-plugin","tag-waf","tag-wordpress","tag-wp-admin","tag-wp-config"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p3Vuhl-2Ri","jetpack_featured_media_url":"https:\/\/flaven.fr\/wp-content\/uploads\/2017\/12\/wp_hacked_b.jpg","_links":{"self":[{"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/posts\/10992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/comments?post=10992"}],"version-history":[{"count":13,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/posts\/10992\/revisions"}],"predecessor-version":[{"id":11013,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/posts\/10992\/revisions\/11013"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/media\/10994"}],"wp:attachment":[{"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/media?parent=10992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/categories?post=10992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/flaven.fr\/happy-api\/wp\/v2\/tags?post=10992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}