Ukuphepha kwe-WordPress · Ukuhlolwa Kwezinsolo

Yazi kahle ukuthi kwenzekeni kusayithi lakho.

I-Armory Security iyithuluzi olitholayo lapho isayithi le-WordPress lisengozini — noma lingase libe — sengozini. Lithwebula isisekelo sobuqotho se-SHA-256, liqinisekisa ama-checksum ayisisekelo nama-plugin, lifuna ama-web-shells kanye ne-PHP efihliwe, futhi lihlola izindawo zokucasha ezithandwa kakhulu umhlaseli. Ukufunda kuphela kanye nokuhlola kwangaphambili: kukutshela okwenzekile ngaphambi ushintsha noma yini.

Thola i-Premium — $49/ngonyaka Bona izici I-core yamahhala · I-Premium $49 ngonyaka
🔍 isisekelo sobuqotho be-SHA-256 🐚 Umzingeli wegobolondo lewebhu 👻 Ukutholwa kwe-Ghost-admin 🧾 Ukuthumela ubufakazi ngaphandle 🔒 Okufundwayo kuphela ngokuzenzakalelayo
yoursite.com/wp-admin · Ukuphepha Kwezikhali
# ukuskena kwezikhali — ubuqotho befayela + ukuskena kwegobolondo lewebhu
amasheke ayisisekelo ✓ kuqinisekisiwe (I-WordPress 6.x, ukungafani okungu-0)
ama-checksum e-plugin ! 1 ishintshiwe akismet/akismet.php
ukuzingela igobolondo lewebhu ⚠ Ukuthola okungu-1 okuqukethwe kwe-wp/ukulayishwa/2026/04/.cache.php
i-eval efihliwe (base64_decode( … )) · Iqhutshwa yi-POST
abaphathi bezipoki ⚠ 1 ifihliwe umsebenzisi “wp-svc” · wadala ngo-03:14 UTC
imizila yobugebenga ✓ akukho lutho
i-cron enonya ✓ akukho lutho
ama-plugin/ama-drop-in ✓ ukuhlanza
# isisekelo esigciniwe · iphakheji yobufakazi isilungele ukuthunyelwa ngaphandle
$

Fakazela okwenzekile, bese ukukulungisa

Uhlelo lokusebenza oluphelele lokuphendula ezigamekweni — hhayi nje esinye isithwebuli esithi “ungase utheleleke”.

🧬

Isisekelo sobuqotho befayela

Isitokwe se-SHA-256 sawo wonke amafayela, ngokuhlukahluka kwesidingo — bona ukuthi yini engeziwe, eshintshiwe noma esusiwe njengoba wawuhlanzekile.

Amasheke e-core kanye nama-plugin

Qinisekisa amafayela e-WordPress core kanye nama-plugin ngokumelene nama-checksum asemthethweni ukuze uthole ikhodi ephazanyisiwe ngokushesha.

🐚

Umzingeli we-malware we-Web-shell kanye ne-PHP

Isiginesha + injini ye-heuristic ethola ama-web-shells kanye ne-PHP efihliwe — abahlaseli bamaphethini e-eval/base64/POST bayacasha ekulayishweni.

👻

Ukutholwa kwe-Ghost-admin

Umphathi ofihliwe ongaphezulu ubika ukuthi umhlaseli wengezwe buthule ukuze agcine indawo yakhe.

🛣️

Ukuhlolwa komzila ongalungile kanye ne-cron

Hlola imizila ye-REST/AJAX enonya, imicimbi ye-cron ehleliwe, ama-plugin e-mu kanye nama-drop-in asetshenziselwa ukuqhubeka.

📡

Ukukhishwa kwesizinda se-C2 / okuphumayo

Khipha ama-domain anekhodi eqinile kanye nokulawula okuvela kumafayela asolisayo ohlu lwakho lokuvimba kanye nokufanisa i-IOC.

👮

Ukuthembana kweseshini yokuphatha kanye nokuphakelayo kokuhlasela

Bona ukuthi ubani ongene ngemvume, kusuka kuyiphi i-IP kanye nedivayisi, ngokuphakelayo kokuhlasela okubukhoma kwamasignesha esicelo angenayo.

🛡️

Ukuqinisa kanye kanye nokuvalelwa

Faka ukuqinisa isikhathi sokusebenza, vala isayithi bese uhlukanisa amafayela asolwayo — izenzo ezihlosiwe neziguquguqukayo ozilawulayo.

🧾

Ukuthunyelwa kobufakazi obunesitembu sesikhathi

Thumela iphakheji yobufakazi enesitembu sesikhathi (i-ZIP/CSV) — irekhodi elihlanzekile lokutholakele kombiko wakho noma umbungazi wakho.

Kumahhala ukuthola. I-Premium yokuphendula.

I-funnel yokuthola imahhala unomphela — isisekelo, amasheke, ukuzingela i-web-shell, ukuhlolwa kwe-ghost-admin kanye nokuphikelela. I-Premium iguqula i-Armory isuke ekubeni “kwenzekeni?” iye “ekuyiphatheni”: ukuqapha okuqhubekayo, izexwayiso zesikhathi sangempela kanye nobufakazi obulungele inkantolo.

  • Izisekelo ezihleliwe kanye nezaziso zokukhukhuleka
  • Ukuqapha kwe-akhawunti yokuphatha kanye neseshini ngesikhathi sangempela
  • Ukuqhathaniswa kwe-Indicator-of-compromise (IOC)
  • Izinqwaba zobufakazi ezifakwe isitembu sesikhathi kanye nomugqa wesikhathi
yoursite.com/wp-admin · Ilayisensi Nohlelo
# mahhala uma kuqhathaniswa ne-premium
MAHHALA ukuphepha · umongo · ama-plugin · igobolondo · i-polyglot
i-htaccess · i-db · mu · isikhathi sokusebenza · umsebenzi
I-PREMIUM ishejuli · bukela · umlindi · okuphakelayo · amaseshini
ukuqina · ukuvalelwa endlini · inqwaba · umugqa wesikhathi
izizinda · imizila · ama-authhooks · ama-perms · i-cron
ioc · ai
# ukuthuthukiswa kusendaweni kusuka ku-WP Admin → Ilayisensi Nohlelo
$

Kusukela ku-"mhlawumbe kuqhekeziwe" kuya ezimpendulweni

Awekho ama-ejenti, akukho ukulayishwa kwamafayela akho efwini. Konke kusebenza ngaphakathi kwe-WordPress yakho.

Faka iskena samahhala

Layisha i-plugin bese uyisebenzisa. I-fill funnel isebenza ngokushesha — akukho khiye odingekayo.

Isisekelo kanye nokuskena

Thatha isisekelo se-SHA-256, qinisekisa ama-checksum bese usebenzisa i-web-shell, i-ghost-admin kanye ne-persistence sweep.

Phendula futhi ufakazele

Valela, qinisa bese uthumela iphakheji yobufakazi enesitembu sesikhathi. Thuthukela ku-premium yokuqapha kanye nezexwayiso.

Qala mahhala namuhla

Isithwebuli se-forensic esigcwele simahhala unomphela. Engeza impendulo ye-Premium kanye nokuqapha ngo-$49/ngonyaka — thuthukisa indawo kusuka ku-WP Admin noma nini.

Mahhala
$0 phakade
I-funnel yokuthola okugcwele · zonke izingosi
  • Isisekelo sobuqotho be-SHA-256 kanye nomehluko
  • Ukuqinisekiswa kwe-Core & plugin checksum
  • Umzingeli we-PHP ofihliwe kanye ne-webshell
  • Ukuhlolwa kwe-Ghost-admin, umzila, i-cron kanye ne-mu-plugin
  • Ukuthunyelwa kobufakazi (i-ZIP/CSV)
Thola isaziso sokuqalisa
I-Premium
$49 /unyaka
Impendulo · ukuqapha · ubufakazi · indawo eyi-1
  • Konke kumahhala
  • Izisekelo ezihleliwe kanye nezaziso zokukhukhuleka
  • Ukuphathwa kwesikhathi sangempela kanye nokuqapha iseshini
  • Okuphakelayo kokuhlasela okubukhoma kanye nokufaniswa kwe-IOC
  • Ukuqina ngokuchofoza kanye, ukuhlukaniswa kanye nomugqa wesikhathi

Ukukhokha okuphephile nge-Stripe · khansela noma nini

Uke wayekethisa njengamanje futhi udinga usizo olusebenzayo? Buza ngempendulo yochwepheshe ezigamekweni →

I-ROfunda kuphela

Ukuhlolwa kwe-forensic - kuqala, ungalimazi ngokuzenzakalelayo

I-Armory ibamba ubufakazi futhi ikutshele okwenzekile ngaphambi kokuthi uthinte noma yini. Ukuqinisa, ukuvalelwa endlini kanye nokuvalelwa endlini kuyizenzo ezicacile nezihlosiwe ozikhethayo ukuzithatha — akukaze kube yizimanga ezizenzakalelayo.

🔒

Isebenza kuseva yakho

Amafayela akho awalokothi alayishwe kumuntu wesithathu. Ukuhlaziywa kwenzeka ngaphakathi kwe-WordPress yakho.

🧾

Ubufakazi obulungele inkantolo

Okutholakele okunesitembu sesikhathi, okungathunyelwa ngaphandle ongakunikeza umphathi wakho noma umbiko wakho.

🧩

Isebenza ne-WAF yakho

Igcwalisa ama-firewall afana ne-Wordfence — iyaqinisekisa futhi iyalulama, hhayi amabhlogo kuphela.

Kumahhala ukuqala

I-funnel yokuthola ephelele imahhala. Thuthukisa ukuze uthole impendulo nokuqapha uma usukulungele.

Imibuzo, iyaphendulwa

Ingabe ukuphepha kwezikhali kumahhala?

Yebo — isithwebuli se-core forensic simahhala: isisekelo sobuqotho se-SHA-256, ukuqinisekiswa kwe-core/plugin checksum, ukuzingela kwe-web-shell kanye ne-obfuscated-PHP, ukutholwa kwe-ghost-admin kanye nayo yonke i-funnel yokuthola. I-Premium ingeza impendulo ebukhoma, ukuqapha kanye nezici zobufakazi.

Ingabe kuzoshintsha noma kuzophula isayithi lami?

Cha. I-Armory iwukuhlolwa kwe-forensic kuqala futhi ifundwa kuphela ngokuzenzakalelayo: ikutshela ngqo okwenzekile ngaphambi kokuthi ushintshe noma yini. Ukuqina, ukuvalelwa endlini kanye nokuvalelwa endlini kuyizenzo ezicacile, zokuzikhethela ozibangela wena.

Ngingayiqhuba eceleni kwe-Wordfence noma enye i-plugin yokuphepha?

Yebo. I-Armory yakhelwe okwamanje lapho isayithi lisengozini — noma lingase libe — sengozini, lihambisana ne-firewall/WAF esikhundleni sokuyishintsha. Igxila ekuqinisekiseni ukuthi yini eshintshile nokuthola ubufakazi, hhayi ekuvimbeleni ithrafikhi.

Yini engezwa uhlelo lwe-premium?

I-Premium ivula uhlangothi lokuphendula nokuqapha: izisekelo ezihleliwe, ukuqapha kwe-akhawunti yokuphatha kanye neseshini ngesikhathi sangempela, ukuphakelwa kokuhlasela okubukhoma, ukuqina kokuchofoza okukodwa, ukuhlukaniswa, ukufanisa inkomba yokuyekethisa kanye nezinqwaba zobufakazi ezifakwe isitembu sesikhathi.

Malini i-premium futhi ngiyithenga kanjani?

I-Premium iyi $49 ngonyaka kwesayithi elilodwa, elikhokhiswa ngokuphephile nge-Stripe — khansela noma nini. Ngemva kokukhokha uthola ukhiye wakho welayisensi nge-imeyili ngokushesha; uyisebenzise ngaphakathi kwe-WP Admin ngaphansi kwe- Ukuphepha Kwempahla Yezikhali → Ilayisensi Nohlelo.

Lungela ngaphambi kwesivumelwano esilandelayo.

Thwebula isisekelo esihlanzekile, wazi isikhathi lapho noma yini ishintsha, bese ufakazela okwenzekile. Qala mahhala, thuthukela ku-Premium ngo-$49 ngonyaka uma ufuna ukuqapha kanye nempendulo.

Thola i-Premium — $49/ngonyaka