4 ms·
Dreamhost runs setuid, which means that any exploit can overwrite any of your files. Without looking at all of your files, merely installing a new version of wo
by cd34 15y ago
Dreamhost runs setuid, which means that any exploit can overwrite any of your files. Without looking at all of your files, merely installing a new version of wordpress doesn't remove the exploits that they have uploaded in the templates/, uploads/ and other directories.
Wordpress.com runs in WPMU mode with a limited sandbox, which makes those exploits difficult to insert.
Since you're running 3.3.1, and there is only one known remote exploit in the wild that was reported in early December that still remains unpatched, you're probably fairly safe. I would suspect more of your problem is remote exploits that have been installed over time that haven't been removed.
You'd probably be best finding a WordPress consultant to come in there for $50 and clean things up. Most hosting companies aren't equipped to handle securing sites when you're paying $10/month for hosting. There are dedicated WordPress hosting companies out there - including WordPress.com, but, short of keeping WordPress updated, I don't know if they proactively look for security issues.
Cloudflare claims to block these types of requests, but, from what I've witnessed, you need to start with a clean site.