Jeste li ikad plaćali za fixanje hacked sajta?

Kakvo ste iskustvo imali i kome ste platili? Sitelocku? Malcare? Nekom liku sa Fajvera?

I koji hosting provider ima najbolji security? Ono baš za budale, pa kad se i inficiraš oni te očiste? Ako takvo šta postoji.

Ne nisam nikada čistio sam ih sam, u 99% slučajeva bila je neka glupost sa nekim wp-pluginom. Tako sam brisao svaki i provjeravao da li cron ubacuje kakvu skripticu :smiley:

Ja čistim godinama bukvalno i vraća mi se. Neki dan kupio WP Cerber PRO za pet sajtova i jednog od njih hakira i usere se u SERPs sa nekim kineskim slovima, redirecta ti traffic na neke kineske shopove. Preselio sam na novi VPS, restorao “čist” backup ali vratiće se opet. Gledam WPfixit je najjeftiniji, hmm.

Cron ?
Da li vidiš šta se update-a posljednje u file manageru ?

Kako se koristi Cron?

@ace spomenuo sam prije par dana u slicnoj temi https://sucuri.net/ pa pokušaj s njim. Meni je pomogao…

1 Like

action_scheduler_run_queue

[ “WP Cron” ] 2021-10-24 11:37:37
now ActionScheduler_QueueRunner->run() Every minute
Select this row wp_fastest_cache_Preload

None 2021-10-24 11:40:44
3 minutes 7 seconds WpFastestCache->create_preload_cache() Once Every 5 Minutes
Select this row cerber_bg_launcher

None 2021-10-24 11:41:36
3 minutes 59 seconds Closure Every 5 Minutes
This is a WordPress core event and cannot be deleted recovery_mode_clean_expired_keys

None 2021-10-24 11:51:39
14 minutes 2 seconds WP_Recovery_Mode->clean_expired_keys() Once Daily
Select this row cerber_hourly_1

None 2021-10-24 12:00:00
22 minutes 23 seconds cerber_do_hourly_1() Once Hourly
Select this row cerber_hourly_2

None 2021-10-24 12:10:00
32 minutes 23 seconds cerber_do_hourly_2() Once Hourly
This is a WordPress core event and cannot be deleted wp_privacy_delete_old_export_files

None 2021-10-24 12:36:18
58 minutes 41 seconds wp_privacy_delete_old_export_files() Once Hourly
This is a WordPress core event and cannot be deleted wp_version_check

None 2021-10-24 13:18:50
1 hour 41 minutes wp_version_check() Twice Daily
This is a WordPress core event and cannot be deleted wp_update_plugins

None 2021-10-24 13:18:50
1 hour 41 minutes wp_update_plugins() Twice Daily
This is a WordPress core event and cannot be deleted wp_update_themes

None 2021-10-24 13:18:50
1 hour 41 minutes wp_update_themes() Twice Daily
This is a WordPress core event and cannot be deleted wp_scheduled_auto_draft_delete

None 2021-10-24 13:31:20
1 hour 53 minutes wp_delete_auto_drafts() Once Daily
This is a WordPress core event and cannot be deleted wp_https_detection

None 2021-10-24 13:44:25
2 hours 6 minutes wp_update_https_detection_errors() Twice Daily
Select this row wpseo-reindex-links

None 2021-10-24 14:03:27
2 hours 25 minutes None Once Daily
Select this row aioseop_cron_check_remote_notices

None 2021-10-24 14:23:03
2 hours 45 minutes None Once Daily
This is a WordPress core event and cannot be deleted delete_expired_transients

None 2021-10-24 18:37:30
6 hours 59 minutes delete_expired_transients() Once Daily
Select this row jetpack_v2_heartbeat

None 2021-10-24 20:42:07
9 hours 4 minutes None Once Daily
Select this row jp_purge_transients_cron

None 2021-10-24 20:43:06
9 hours 5 minutes None Once Daily
Select this row wbcr/gac/update_analytic_library

None 2021-10-24 23:10:22
11 hours 32 minutes WGA_ConfigGACache->update_local_analytic() Twice Daily
This is a WordPress core event and cannot be deleted wp_scheduled_delete

None 2021-10-25 01:18:57
13 hours 41 minutes wp_scheduled_delete() Once Daily
Select this row cerber_daily

None 2021-10-25 04:20:00
16 hours 42 minutes cerber_daily_run() Once Daily
Select this row wp_fastest_cache_0

[ “{“prefix”:“all”,“content”:“all”,“hour”:“5”,“minute”:“0”}” ] 2021-10-25 07:00:00
19 hours 22 minutes WpFastestCache->setSchedule() Once a Day
Select this row wpseo_ryte_fetch

None 2021-10-26 14:03:28
2 days 2 hours None Once Weekly
This is a WordPress core event and cannot be deleted wp_site_health_scheduled_check

None 2021-10-29 14:20:02
5 days 2 hours WP_Site_Health->wp_cron_scheduled_check() Once Weekly
Select this row dst_update_ad-inserter

None 2021-11-23 07:31:11
4 weeks 1 day DST_Client->update() Once Monthly

ovo je iz Crontrol plugina, nemam ja pojma koji cronjob je tu sumnjiv, ovaj action_scheduler_run_queue kad odeš na edit kaže The event you are trying to edit does not exist.

Ja sam jednom imao problem nakon instalacije nekog plugina.

Resio sam problem tako sto sam kontaktirao Support Hostinga (Bluehost) i oni su resili problem, sad ne znam kakav je problem kod tebe ali verujem da ako je neka glupost da ti to i podrska moze resiti.

Naah, podrška KnownSrv-a to ne može nit želi riješiti. Dobri su oni jer dozvoljavaju svakakav sadržaj da se hosta i hosting je pouzdan ali apsolutno ih ne interesuje security servera, to je uvijek tvoj problem.

Dao sam 170 eura za cleanup jednog većeg sajta, koji je na serveru sa još 7 addon domena koje su također s rupama i 2h kasnije mi u sidebaru haker ubacuje link. Eto za šta sam spickao 170 eura jbt. I niko ne nudi cleanup per server, što bi bilo cool, jer haker uvijek zarazi i druge sajtove ili čak van public_htmla može praviti backdoors ili imati shell pristup. Većina ovih servisa ima pogrešnu filozofiju totalno i hoće da te oderu po jednom sajtu, a često ti jedan sajt ne zaradi dovoljno ni da plati tu mjesečnu cijenu što oni traže za security.

Jedino rješenje potrpati svaki sajt na svoj cpanel, što je opet trošak jer i te cpanele naplaćuju, ali nije puno, samo je smorno. Jer ova gamad ti ne želi očistiti server, nego sajt lol. Ovo je ko da ti naprave bravu u jednoj sobi, a kuća otključana.

1 Like

Ne bi bilo loše da nam privatno ili javno podijeliš link sajta da vidimo koje su to reklame i da podijelis screeshoot sa cpanela foldere Theme i plugins.

Da li imaš neku nulled theme na sajtu ?

Da li si pokušao brisanjem plugina jednog po jednog ?

Možda ti forum može pomoći s obzirom da imamo dosta njih koji se bave sa serverima i hostinzima :slight_smile:

Bas nezgodna situacija. Ne znam, meni se pojavljivalo ovo

Mada opet mislim da je veciniski uzrok ovakvih problema oko wp plugina.

Promjeni ime foldera plugini pa pokušaj ući. :smiley:

ImunifyAV mi rijesava stvar ili dadne prijedlog gdje da pogledam rucno

kako se ovo instalira na server?

Na dedicated serverima imam Plesk, a Imunify instaliram kao extenziju.

1 Like