Russell Aaron Designs

My 3.4.2 WordPress Installation Was Hacked. The Details Are Below. Thank You CloudFlare!

Hey everyone. SO I have something pretty interesting for you to read. I am a freelance developer and I am working on a website called POP PERCEPTION. Well, with all of the WordPress 3.5 issues that have been going on, the owners made a decision to wait on the update. Hey that rhymed. Cool.

Anyways, so today We got the message that read Error Establishing Database Connection. That’s pretty normal. I’ve gotten that before and have solved the issue. So I logged into my site using FTP (FileZilla) and the first thing I notice is that all of my files inside of the root folder are duplicated & pre-pended with a ._ in front of them. None of the original files were touched, just duplicated and pre-pended. So I did what anyone would do in that situation. I called the Hosting Company (Media Temple) and let them run their checks.

Now, the owners of the site do have a Snap Shot Backup Plan on Media Temple. So we are able to restore the site back to the way it looked a few days ago. But the people at Media Temple have no idea what this is or how it got there. I shot an email over to my good friends at Sucuri.net and maybe they can come up with an idea. To say the least, it was a crazy day for that site.

I also found out that Media Temple has a plan that allows you to add an extra 1GB of Disk Space to your server for 6 hours, incase you need some extra room while making changes or deleting files. That was pretty cool to know.

So since the site is running on Cloudflare, their site is showing a cached version, until the back up is fully complete. That is pretty cool. You can see a picture of that screen shot, because its the Featured Image of this post.

Here is the screen shot of my FTP Server showing the files. Followed by A screen shot of the ._wp-config.php file.

Exit mobile version