Exploit Scanner
This plugin searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames. It does not remove anything. That is left to the user to do. Latest MD5 hash values for Exploit Scanner: 17e2ccfc834d691bc68cc5c64f9bed89 exploit-scanner.php (1.5.2) 1d5f9d6220fe159cd44cb70a998a1cd7 hashes-4.6.php fbdf61c17f65094c8e331e1e364acf68 hashes-4.6.1.php 477d128d84802e3470cec408424a8de3 hashes-4.7.php d53210f999847fbd6f5a2ecac0ad42f2 hashes-4.7.5.php Latest SHA1 hash values for Exploit Scanner: 1decc1e47a53d1cab9e8f1ef15b31682198367ee exploit-scanner.php (1.5.2) 5cec64380a2acdc876fd22fbbbbf8c335df1ed3f hashes-4.6.php 99d9e7be23a350f3d1962d0f41e7b4e28c00841e hashes-4.6.1.php 1eeab377a1afc6d776827a063678d2461b29e71d hashes-4.7.php 8c890a6af26bb74e9d17e5d2b21d6be27764da45 hashes-4.7.5.php See the Exploit Scanner homepage for further information. Interpreting the Results It is likely that this scanner will find false positives (i.e. files which do not contain malicious code). However, it is best to err on the side of caution; if you are unsure then ask in the Support Forums, download a fresh copy of a plugin, search the Internet for similar situations, et cetera. You should be most concerned if the scanner is: making matches around unknown external links; finding base64 encoded text in modified core files or the wp-config.php file; listing extra admin accounts; or finding content in posts which you did not put there. Understanding the three different result levels: Severe: results that are often strong indicators of a hack (though they are not definitive proof) Warning: these results are more commonly found in innocent circumstances than Severe matches, but they should still be treated with caution Note: lowest priority, showing results that are very commonly used in legitimate code or notifications about events such as skipped files Help! I think I have been hacked! Follow the guides from the Codex: Codex: FAQ – My site was hacked Codex: Hardening WordPress Ensure that you change all of your WordPress related passwords (site, FTP, MySQL, etc.). A regular backup routine (either manual or plugin powered) is extremely useful; if you ever find that your site has been hacked you can easily restore your site from a clean backup and fresh set of files and, of course, use a new set of passwords. Updates Updates to the plugin will be posted here, to Holy Shmoly! and the WordPress Exploit Scanner page will always link to the newest version. Other Languages Unfortunately for people using WordPress versions for other locales some of the file hashes may be incorrect as some strings have to be hardcoded in their translated form. Here are some file hashes for WordPress in other languagues provided separately by other members of the community: Japanese – thanks to Naoko German – thanks to Robert Wetzlmayr The hash files should only be declaring an array called $filehashes and the majority of the hashes should still be the same.
Top keywords
- php11×2.37%
- hashes-48×1.72%
- files6×1.29%
- scanner6×1.29%
- wordpress5×1.08%
- exploit4×0.86%
- exploit scanner4×0.86%
- results4×0.86%
- site4×0.86%
- codex3×0.65%
- file3×0.65%
- hacked3×0.65%
Hack-Info
Now, “Hack-Info” – it is a standalone independent complete tool. Previously, it was like Add-On for “iThemes Security”. But time has shown that it is bad to be dependent on others.. Especially when their DB structure changes. “Hack-Info” make improve the perception of information about events, which is important to quickly and in detail see and understand. Without the need for unnecessary clicks and conversions. “Hack-Info” notifies the site administrator by providing a detailed list of IP addresses, requests – attempts to scan resources and search for passwords with names. Features An additional level of security for your site. Simply, Briefly and in Detail. Even without going to the site admin area, you will be informed about the activity of the current day. Any person can be a recipient of notifications. Not necessarily the Administrator. Adjustable interval for the formation of the Digest. The e-mail report received contains full and detailed information about the nature of attempts to hack your site: In cases of Brite Force, user names are displayed. So, one glance is enough for you to understand what you’re dealing with: a routine search or a targeted attack on an already compromised name. In cases of URL scanning, requests are displayed. Timely analysis of such requests allows you to draw conclusions about which Plugins, Themes or Scripts are vulnerable, and in time to abandon their use in their projects. The information digest is compact and minimalistic, but at the same time it easily and visually gives a complete information picture. You do not have to go to your site to get more details. Therefore, even being outside the usual workspace, on a slow Internet, but having the ability to read mail – you will be fully informed, and therefore, if necessary, you can make the necessary and fast decisions. And this approach is many times more effective than messages like: “To see the list of blocked IP addresses and to know the parameters of requests – click on the button …” And then, still it will be necessary to login … In the control panel, the Administrator can view all reports with various data sets: “Scan URLs & Files,” “Scan from IP,” “Brute-Force User Names,” and “Brute-Force from IP.” Color marks allows you to evaluate the activity of grouped data.
Top keywords
- site5×1.33%
- information4×1.06%
- ip4×1.06%