Detecting and removing an AnonymousFox user in WordPress

AnonymousFox is a known WordPress vulnerability where users are able to exploit vulnerable WordPress plugins to gain access to the Cpanel account file system.

If you notice your WordPress user credentials are no longer working, you may need to reset your WordPress admin password manually. Once your WordPress admin passwords have been reset, it is also recommended to change your WordPress database password

You can do this by logging into Thexyz Client Area and making your way to your active services. 

Your WordPress hosting service may be called Managed WordPress Hosting or cPanel Usage Instance. Click on it once located.

Locate WP service

From the management page, click Login to cPanel.

cPanel Login

From here you can search for phpmyadmin or locate the icon as pictured below.

phpmyadmin

Find the database of your WordPress installation and expand your database to show all the tables and look for wp_users

expand database

Click wp_users.

wp-users

Look for any user called something like AnonymousFox_ywx and rename the user. You can also update the password in the user_pass field. Make sure you select MD5 from the dropdown Function

AnnonymousFox user

While here, it is also a good idea to reset your database password by following the guide to change your WordPress SQL password. 

As with all open-source software, it is important to always use the most recent version of wordpress as this will contain important WordPress security fixes. You should also keep your WordPress theme and plugins up to date too, as these are often exploited with malicious code. If you notice you have a hacked WordPress website, please see: Help, my website was hacked.

 

 

  • 130 Người dùng thấy bài viết này hữu ích
Câu trả lời này có hữu ích không?

Bài viết liên quan

Enabling two-factor authentication

Setting up 2-factor authentication (or 2FA) provides a second line of defense. If your password...

Password Help

Here at Thexyz we take your account security very seriously and want to make it easy for you to...

Logging in with social media profiles

You can login to your account at Thexyz with Twitter, Facebook and Google. Before adding these...

Help, my website was hacked

Firstly don't panic, although it is a traumatic experience for any site owner when malicious code...

Blocking access to WordPress admin

Blocking access to your WordPress admin area is a great way to improve the security of your...