.htaccess attacks are very frustrating, period! I wanted to write this to share the numerous methods and techniques I used to recover my websites from a recent .htaccess attack.
This type of attack on WordPress install will create .htaccess files on every single directory of the install and that file would have some codes that would modify directory access. I tried various things. I deleted these files, but it got recreated instantly.
Change Login Passwords
First step is to change login passwords to something super strong. In wordpress, in Cpanel, and in webhost.
Rename The Main Folder
This is the only thing that stopped the auto-generated index.php and .htaccess files from re-creating – to change the name of the main folder that houses all WordPress install files from FTP.
Once you rename this folder, you will have to go into cpanel and make sure the correct folder name is updated for the domain and any other places that use folder location.
Security Scan the Hell Out of It
I used Wordfence plugin and use their free Scan feature to scan the entire directory of the WordPress install. The beauty of this plugin scanner is, it will show which files are infected or modified, or injected. You can directly delete those files.
Alternatively, you can also go into FTP and delete .htaccess files but that is a very tedious process. I found this scanner plugin did a much better job.
If core files are modified, you will want to download a new WordPress copy of the same version you have installed and replace those files. Wordfence plugin was able to replace those with core files as well.
Add Protections For Future
I have installed Sucuri Security plugin after clearing out everything. I like this plugin because it can send me notifications of any changes to files or changes to content.
If your web host provides any security products you can also activate those.
You could also add Login Limit Plugins and modify login page url plugins such as WPS Hide Login.
1 month ago
Cold Exposure Continued.
In Stock Tank with a bucket of Ice I learned how to expose to cold and use it to enhance my physical existence. As the Northern hemisphere is heading into…
3 months ago
Life Without the Game: Finding Fire Beyond the Sports High
Sports we know today is a very recent invention compared to the vast history of humanity. Before stadiums and scoreboards, there was play, dance, rituals and movement. People ran, wrestled,…
3 months ago
How Can I Trust You?
Life on earth is possible because we transact with everything around us. Inhaling and exhaling is a transaction. We are always in relationships with the things around us. In our…
9 months ago
Embrace Your Kids, Before You Know it, They Will Grow Up
If you have kids, have you ever heard someone tell you this "Embrace your kids as much as you can, because before you know it, they will grow up and…
10 months ago
My First 38 Hour Upavasa (Fast)
What I Knew About Upavasa Fasting also known as Upavasa (in Sanskrit), was practiced long ago in ancient yogic traditions. Gautum Buddha went on periods of intense Upavasa in search…
1 year ago
DIY Backyard Solar Panel Stand
I have always been fascinated with using alternate methods to generate power to run day-to-day machines. There is nothing better than using the sun's power to generate electricity, which gives…
1 year ago
What You Said is Very Disrespectful
How many times did someone say something and you felt it was disrespectful or it was respectful? It is kind of a learned thing isnt it? What is respectful and…
2 years ago
Courage To Be By Ourselves
I wanted to explore and write about the power of being alone by ourselves, in light of the passing away of a dear friend I knew from high school. When…
2 years ago
Educated People Have Caused More Destruction, Than Those Who Are Not
I once saw in a small village in Sri Lanka where people live bare minimum very close to nature. No plastic, no processed foods, no fad diets, no exercise regime,…
2 years ago
How I recovered from .htaccess attack on WordPress install
.htaccess attacks are very frustrating, period! I wanted to write this to share the numerous methods and techniques I used to recover my websites from a recent .htaccess attack. This…
3 years ago
Procrastination
If you are procrastinating something, that means obviously you don’t like what you have to do. If you like what you have to do, you wouldn’t stop doing it, wouldn't…