所有浏览器登录wp-admin均跳转至notfound.name求助
Hey there, I’ve dealt with plenty of persistent malware redirect issues like this—Malwarebytes catching some threats is a start, but often there’s leftover code or hidden tweaks in your site, browser, or server causing the problem. Let’s walk through actionable steps to resolve this:
Check key WordPress files for tampering
Malware almost always injects redirect code into critical site files. Start with these:wp-config.php: Look for unfamiliardefine()statements or random code snippets at the top/bottom of the file..htaccess: Scan for unexpected RewriteRules pointing tonotfound.nameor encoded URLs. If you spot suspicious rules, back up the file then replace it with a default WordPress .htaccess:# BEGIN WordPress <IfModule mod_rewrite.c> RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] </IfModule> # END WordPress- Active theme's
functions.php: Watch forwp_redirect()calls or base64-encoded junk code that triggers the redirect.
Verify WordPress database settings and injections
Malware often modifies database values to hijack traffic:- Use phpMyAdmin (or WP-CLI) to check the
wp_optionstable forsiteurlandhomevalues—make sure they match your actual domain, not a malicious URL. - Scan
wp_postsfor hidden redirect scripts in post content, andwp_usersfor unknown admin accounts that shouldn’t exist. - With WP-CLI, run these quick commands to validate core settings:
wp option get siteurl wp option get home
- Use phpMyAdmin (or WP-CLI) to check the
Reset browser configurations
Your browser might have cached malicious scripts or had settings altered:- Clear all cache, cookies, and site data for your domain.
- Reset your browser to default settings:
- Chrome: Settings > Advanced > Reset and clean up > Restore settings to their original defaults.
- Firefox: Help > More troubleshooting information > Refresh Firefox.
- Opera: Settings > Advanced > Browser > Restore settings to original defaults.
- Uninstall any unfamiliar browser extensions—malware often hides as fake "security" or "productivity" tools.
Reinstall WordPress core files
Tampered core files can linger even after scans. Reinstalling core won’t delete your content:- From WordPress admin: Go to Dashboard > Updates > Click "Reinstall Now" under WordPress core.
- With WP-CLI: Run
wp core download --forceto replace core files with fresh, unmodified versions.
Check server-side malware
If the above steps don’t work, the threat might be hiding on your server:- If you’re on a managed host, reach out to their support—most offer free server malware scans and cleanup.
- For self-hosted servers, scan your root directory for random
.phpfiles with gibberish names, and check server configs (Apache.conf, Nginxnginx.conf) for unauthorized redirect rules.
Once you’ve gone through these steps, test accessing wp-admin again across all browsers. If the redirect still happens, double-check plugin files or custom templates for missed injected code.
内容的提问来源于stack exchange,提问作者creat15

