You need check what is in plugin/newsletter?i don't use elementor (never use it in my life)
and i have other site that not running script from here and not have that warning
i think ( i hope i wrong )...
wp ---> install plugin ---[ plugin sent some trigger "hello this $domain in online" ] ---> save
random day --> source server that already save the triger call $domain/plugin/newsletter ---> run script
throw the dice... if i have download script / plugin that have that php QUERY.. then .boom.... wp-config revealed...
well i did not say that this is because BABIATO, but i think this is more to person... i still trust babiato....
the problem is i only use themes and plugin from here on that site and once again... i never mention babiato fault and never think about that.
but maybe because "500 resource under approval! " then one or two script missed from check...
and as mention on screenshot the query are blocked by Hide My WP.
helloYou need check what is in plugin/newsletter?
Then plugin/newsletter from Babiato or not?
And not all hack reason come from themes, plugins on Babiato, it also come from your hosting security, your easy password or from security holes of untouched themes, plugins on your site.
Anyway, not 100% resources here safe because many guys still insert code to untouched version: for nulling, for copyright, promo links or other purpose. You don't know what inside it if you not have untouched version & skill to check & compare both versions.
All resources on net always use at your own risk. If you got hack, take your time to do all essential actions to make your site safe then. Trust recommendations from security experts, don't trusted anyone else!
Good luck!
Really, like I said, attacks not only come from bad version of theme, plugin you downloaded here (if it really bad).hello
thankyou for your reply
the plugin newletter (or something) is not the only one plugin that have "backdoor" (if i can say that), like my screenshot. it use other plugin too.
like i said before
i only use plugin/themer (pro/full/premium version) from here, not other download places, i trust babiato...
and for me.. personally, i am new member here, maybe about 1 years or less, but i never get this attack before. and i always use resources from babiato that already "official" put on resources list. not from comment or hot link.
and i use only on test site. no impact for me, but other member here must re check their script.
sadly im not programmer so i cant understand how to compare untouched and nulled. of course no secure places even for "official version/real paid license"
but better to share ... so other member can more carefull....
PM sent@NewLoginOnTheBlok please send me a PM with a download link containing a full archive of plugins and themes folder from your affected install.
yes. i already see that site
I can suggest you some free tools to help staying safe in this GPL world. you can google & download these 2 useful softwares.hello
thankyou for your reply
the plugin newletter (or something) is not the only one plugin that have "backdoor" (if i can say that), like my screenshot. it use other plugin too.
like i said before
i only use plugin/themer (pro/full/premium version) from here, not other download places, i trust babiato...
and for me.. personally, i am new member here, maybe about 1 years or less, but i never get this attack before. and i always use resources from babiato that already "official" put on resources list. not from comment or hot link.
and i use only on test site. no impact for me, but other member here must re check their script.
sadly im not programmer so i cant understand how to compare untouched and nulled. of course no secure places even for "official version/real paid license"
but better to share ... so other member can more carefull....
thank you for your suggestionI can suggest you some free tools to help staying safe in this GPL world. you can google & download these 2 useful softwares.
1. WinMerge - use to compare files content between 2 or more folders for changes. useful to learn what had changed between the original/untouched vs nulled/so called 'gpl'
2. grepWin - use to bulk find/search for particular or suspicious strings/code/external call/backdoor resides in all files within selected folder. first thing to do is always scan for 'http' string for any suspicious domain/url/api/callback/etc.
Not person!yes. i already see that site
but the question is
how this "person" / "machine" know my site up ?
i have many website.... but why only that new site got scanned ?
same ip (shared ip on my vps)
that domain is not new.. about 1 years and i have some domain with same tld and same year too
the different is,,, i just install wp and plugin few days before 1st brute
i thougt that was only some kind internet brute....
i want to test copy the plugin to another site (new site) but i think that will not work
why?
we know this step
If abc.check exist then sent "hello $domain is here"|| then delete abc.check
else remove line 123
end
and i never save babiato script on my computer, every time i need it, i just re download. admin can see my log. sometimes i download same plugin multitimes lol
forgive for my bad englishNot person!
Hack bot automatically scan all IPs of server providers, it not care/ know your site new or old like the grandmas. When it scan & catch a name of plugins or themes have security problems we know, it says WOW, then try to do essential works to hack.
You can block bot of Google, Bing because it legic but no way to block hack/ spam bot when your site live.
If you create a new WP on a cheap hosting/ vps and not turn of discussion features, hundred spam commnets should come just a few hours laters. But on some good hosting now, they can block most bad bot for you .