cách khắc phục Website dùng Wordpress bị hack
Cách xử lý nếu website dùng Wordpress đã bị hack - Nguồn: WPSecurityLock
1. Nhanh chóng xóa tập tin index.php ở thư mục gốc của Wordpress. Thay thế bằng một tập tin index.html với nội dung website đang sửa chữa.
2. Vào phần "File Manager" hoặc FTP và tìm thời điểm website bị hack bằng cách nhìn vào các tập tin php. Các tập tin thường sẽ có cùng thời gian và ngày tháng.
3. Sao lưu lại toàn bộ dữ liệu website về máy tính, kể các hình ảnh và media trong wp-content/uploads, có thể sẽ dùng để cài đặt lại. Mở thư mục wp-content/plubins trên máy chủ và ghi lại tên của những plug-in mà bạn đã sử dụng cho Wordpress.
4. Xóa toàn bộ tất cả các tập tin (file) Wordpress có trên máy chủ lưu trữ web. Vào wordpress.org và tải một phiên bản Wordpress mới nhất.
5. Giải nén và tải (upload) toàn bộ file lên máy chủ web thông qua FTP. Nên dùng SFTP để mã hóa toàn bộ dữ liệu khi chuyển file. Sau đó tải tập tin wp-config.php đã sao lưu về máy tính trước đó vào thư mục gốc của Wordpress trên máy chủ web. Toàn bộ thông số kết nối cơ sở dữ liệu sẽ được thiết lập trở lại.
6. Tải tiếp những hình ảnh và tập tin media ở thư mục wp-content/uploads đã sao lưu lên máy chủ.
7. Tải thư mục theme (giao diện website) đã sao lưu lên thư mục wp-content/theme trên máy chủ.
8. Tải (download) lại các plug-in với phiên bản mới nhất và đưa (upload) chúng lên trên máy chủ web. Có thể một số plug-in yêu cầu kích hoạt trở lại nhưng với cách này sẽ không mất dữ liệu đi kèm.
9. Đăng nhập vào quản trị Wordpress ở wp-admin. Truy cập vào trang chủ website của bạn và thử click lên một số liên kết xem có hoạt động bình thường không. Trường hợp liên kết bị lỗi 404 (lỗi trang không hiện diện) thì bạn vào wp-admin, cập nhật lại liên kết bằng cách click lần lượt Settings > Permalinks > Save Changes.
Kiểm tra lại lần nữa xem các liên kết đã hoạt động bình thường chưa.
10. Truy cập vào máy chủ web, thiết lập lại quyền hạn (CHMOD) cho tất cả các thư mục là 755, tất cả các tập tin hình ảnh, php, media, html... là 644. Đừng bao giờ thiết lập 777 cho bất kỳ thư mục nào.
Cuối cùng, thay đổi toàn bộ mật khẩu quản trị Wordpress, FTP và email của bạn. Không nên dùng chung một mật khẩu.
Tham khảo thêm cách bảo mật cho tập tin wp-config.php
The wp-config.php file contains very sensitive information about your WordPress installation, including your database access, table prefix and Secret Keys.
The wp-config.php file is a standard part of your WordPress installation. It defines the configuration settings required to access your MySQL database. If your self-hosting WordPress, there's no way of getting around not using it.
It's your job to protect it! You certainly don't want this file falling into the wrong hands in the event of a server problem. You can protect it by encrypting it's content when you upload and denying access to it.
How to protect your WordPress wp-config.php file:
Anytime you upload the wp-config.php file, and ANY directory or file to your server, you should only use SFTP or FTPES. By using either of these methods, your data is encrypted while being sent to the server.
If you just upload via plain FTP, your files are seen as plain text and that's not want you want to feed a lurking evil hacker for lunch. If you don't know if you have SFTP or FTPES, call your hosting company and ask. I personally use FTPES on GoDaddy on one of my sites and SFTP on HostGator on another.
If you don't have SSH enabled on your hosting, DON'T run over and enable it. You will lose some downtime and your database. For now, go to Step 2 so you can at least hide it, until you have time to get it set up properly.
Download your .htaccess file from the server. This is located in the same section as your wp-config.php or index.php file. (If you don't have an .htaccess file, then you will need to create one, see directions below).
Using a text editor, like Notepad, open your .htaccess file.
Copy and paste the following code into your .htaccess file to deny access to your wp-config.php file.
# protect wpconfig.php
<files wp-config.php>
order allow,deny
deny from all
</files>
When saving your changes using "Notepad," make sure that you change the "Save as type" dropdown to "All Files" so that it does not change your .htaccess file into a .txt file.
If you're having a problem copying and pasting the code above, you can download our sample here. Please note: This is just a sample. Be sure that you just copy and paste the portion to protect your wp-config into your own .htaccess file.
How to create your own .htaccess file:
Open up "Notepad" on your computer.
Copy and paste the code to deny access to your wp-config.php file (see above).
Click on File > Save As >
Change File Name to .htaccess
In the "Save as type" dropdown, change to "All Files."
Upload this file to your server in the top-level of your WordPress files are (index.php, wp-app.php, wp-config.php, etc.).
Although there are many more things that you can do to protect your WordPress website, knowing that your wp-config.php file is now more protected should give you some peace of mind. Sleep better tonight!
Securely yours,
Regina Smola
1. Nhanh chóng xóa tập tin index.php ở thư mục gốc của Wordpress. Thay thế bằng một tập tin index.html với nội dung website đang sửa chữa.
2. Vào phần "File Manager" hoặc FTP và tìm thời điểm website bị hack bằng cách nhìn vào các tập tin php. Các tập tin thường sẽ có cùng thời gian và ngày tháng.
3. Sao lưu lại toàn bộ dữ liệu website về máy tính, kể các hình ảnh và media trong wp-content/uploads, có thể sẽ dùng để cài đặt lại. Mở thư mục wp-content/plubins trên máy chủ và ghi lại tên của những plug-in mà bạn đã sử dụng cho Wordpress.
4. Xóa toàn bộ tất cả các tập tin (file) Wordpress có trên máy chủ lưu trữ web. Vào wordpress.org và tải một phiên bản Wordpress mới nhất.
5. Giải nén và tải (upload) toàn bộ file lên máy chủ web thông qua FTP. Nên dùng SFTP để mã hóa toàn bộ dữ liệu khi chuyển file. Sau đó tải tập tin wp-config.php đã sao lưu về máy tính trước đó vào thư mục gốc của Wordpress trên máy chủ web. Toàn bộ thông số kết nối cơ sở dữ liệu sẽ được thiết lập trở lại.
6. Tải tiếp những hình ảnh và tập tin media ở thư mục wp-content/uploads đã sao lưu lên máy chủ.
7. Tải thư mục theme (giao diện website) đã sao lưu lên thư mục wp-content/theme trên máy chủ.
8. Tải (download) lại các plug-in với phiên bản mới nhất và đưa (upload) chúng lên trên máy chủ web. Có thể một số plug-in yêu cầu kích hoạt trở lại nhưng với cách này sẽ không mất dữ liệu đi kèm.
9. Đăng nhập vào quản trị Wordpress ở wp-admin. Truy cập vào trang chủ website của bạn và thử click lên một số liên kết xem có hoạt động bình thường không. Trường hợp liên kết bị lỗi 404 (lỗi trang không hiện diện) thì bạn vào wp-admin, cập nhật lại liên kết bằng cách click lần lượt Settings > Permalinks > Save Changes.
Kiểm tra lại lần nữa xem các liên kết đã hoạt động bình thường chưa.
10. Truy cập vào máy chủ web, thiết lập lại quyền hạn (CHMOD) cho tất cả các thư mục là 755, tất cả các tập tin hình ảnh, php, media, html... là 644. Đừng bao giờ thiết lập 777 cho bất kỳ thư mục nào.
Cuối cùng, thay đổi toàn bộ mật khẩu quản trị Wordpress, FTP và email của bạn. Không nên dùng chung một mật khẩu.
Tham khảo thêm cách bảo mật cho tập tin wp-config.php
The wp-config.php file contains very sensitive information about your WordPress installation, including your database access, table prefix and Secret Keys.
The wp-config.php file is a standard part of your WordPress installation. It defines the configuration settings required to access your MySQL database. If your self-hosting WordPress, there's no way of getting around not using it.
It's your job to protect it! You certainly don't want this file falling into the wrong hands in the event of a server problem. You can protect it by encrypting it's content when you upload and denying access to it.
How to protect your WordPress wp-config.php file:
Anytime you upload the wp-config.php file, and ANY directory or file to your server, you should only use SFTP or FTPES. By using either of these methods, your data is encrypted while being sent to the server.
If you just upload via plain FTP, your files are seen as plain text and that's not want you want to feed a lurking evil hacker for lunch. If you don't know if you have SFTP or FTPES, call your hosting company and ask. I personally use FTPES on GoDaddy on one of my sites and SFTP on HostGator on another.
If you don't have SSH enabled on your hosting, DON'T run over and enable it. You will lose some downtime and your database. For now, go to Step 2 so you can at least hide it, until you have time to get it set up properly.
Download your .htaccess file from the server. This is located in the same section as your wp-config.php or index.php file. (If you don't have an .htaccess file, then you will need to create one, see directions below).
Using a text editor, like Notepad, open your .htaccess file.
Copy and paste the following code into your .htaccess file to deny access to your wp-config.php file.
# protect wpconfig.php
<files wp-config.php>
order allow,deny
deny from all
</files>
When saving your changes using "Notepad," make sure that you change the "Save as type" dropdown to "All Files" so that it does not change your .htaccess file into a .txt file.
If you're having a problem copying and pasting the code above, you can download our sample here. Please note: This is just a sample. Be sure that you just copy and paste the portion to protect your wp-config into your own .htaccess file.
How to create your own .htaccess file:
Open up "Notepad" on your computer.
Copy and paste the code to deny access to your wp-config.php file (see above).
Click on File > Save As >
Change File Name to .htaccess
In the "Save as type" dropdown, change to "All Files."
Upload this file to your server in the top-level of your WordPress files are (index.php, wp-app.php, wp-config.php, etc.).
Although there are many more things that you can do to protect your WordPress website, knowing that your wp-config.php file is now more protected should give you some peace of mind. Sleep better tonight!
Securely yours,
Regina Smola
Không có nhận xét nào:
Đăng nhận xét