SQL attack on Cache folder

pending (5 posts) (4 voices)

  1. al5976
    Member

    Using version 1.3 the cache folder is vunerable to SQL injection. My site has been attacked. I have had to take the website down. Can you provide a fix for this?

    [26/Jan/2012:19:01:54 +0000] “GET /wp-content/themes/awake/lib/scripts/cache/ee4eb301273e6cf160cd348d31d455ff.php HTTP /1.1” 200 – ”-” “libwww-perl/6.03”

    ran this file – which is a fairly malicious little remote shell – effectively giving an attacker full control over your site.

    /wp-content/themes/awake/lib/scripts/cache/ee4eb301273e6cf160cd348d31d455ff.php

    Posted 3 months ago #
  2. Webtreats
    Support

    Hi al5976,

    Looks like you're using an older version of Awake with an out of date version of TimThumb.

    You can either update Awake to the latest version or update your TimThumb:

    http://timthumb.googlecode.com/svn/trunk/timthumb.php

    Posted 3 months ago #
  3. al5976
    Member

    I changed the Tim Thumb file, but the site has been attacked again. I cannot upgrade to the new theme version as the style is used is rich-black, which isn't in the new version. The site has been attacked 3 times now. I really need help.

    Posted 3 months ago #
  4. Dogmut
    Member

    Was there not an issue with that in w3 total cache.

    Posted 3 months ago #
  5. Elliott
    Support

    Here is the legacy rich black skin for Awake, http://mysitemyway.com/skins/custom-skins/legacy-rich-black-01/.

    I recommend updating Awake to the latest version but if you wish to stick with the outdated version try deleting your /wp-content/themes/awake/cache/ directory and recreate it.

    Posted 3 months ago #

Reply

You must log in to post.

Construct WordPress Theme
Construct wordpress theme
Myriad WordPress Theme
Myriad wordpress theme
Method WordPress Theme
Method wordpress theme
Fusion WordPress Theme
Fusion wordpress theme
Elegance WordPress Theme
Elegance wordpress theme
Echelon WordPress Theme
Echelon wordpress theme
Dejavu WordPress Theme
Dejavu wordpress theme
Modular WordPress Theme
Modular wordpress theme