Go Back   WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum
Register Blogs FAQ Social Groups CalendarHelp Desk

Reply
 
LinkBack Thread Tools
Old 06-12-2009, 02:04 AM   #1
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS...UPDATE...NOT WORDPRESS

APPARENTLY WORDPRESS IS NOT THE CULPRIT - COINCIDENCE THAT THE SITE WAS HIT WHILE I WAS BROWSING WORD PRESS - MORE INFO ON POST 107 - THIRD PAGE.

I was just in admin on my new blog - was browsing the themes and all of the sudden my avast went nuts. I cut the connection but it was too late - my blog has JS redirect virus now -- new so I'm just going to toss it and hope that it can't spread on that server.

It is on the WP website itself so EVERYONE with WP might be vulnerable now.
Best thing you can do is shut down your php until they fix their virus problem because it will invade your whole site - everything but HTML.

This is NOT a joke.

I have contacted WP in a bug report and reported the virus on twitter hoping their admin will see it quickly - if anyone has an inside track to WP admin - they need to be notified IMMEDIATELY.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 02:07 AM   #2
King of WordPress plugins
War Room Member
 
Join Date: Feb 2009
Location: Los Angeles
Posts: 385
Thanks: 0
Thanked 42 Times in 30 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Yeah, because it's really possible to shut down your "php"...
Soflyy is offline   Reply With Quote
Old 06-12-2009, 02:08 AM   #3
says you need to become a
War Room Member
 
Michael Silvester's Avatar
 
Join Date: Apr 2006
Location: Australia.
Posts: 2,671
Blog Entries: 4
Thanks: 355
Thanked 208 Times in 113 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Michael Silvester
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Wow...

Thanks for the heads-up Sal!

So you were actually inside your wordpress.com admin
when that all happened?

Take Care,

Michael Silvester
Michael Silvester is online now   Reply With Quote
Old 06-12-2009, 02:08 AM   #4
Warrior Member
War Room Member
 
bookmarkr's Avatar
 
Join Date: Apr 2009
Location: Australia
Posts: 29
Thanks: 3
Thanked 3 Times in 3 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by HBZSoftware.com View Post
Yeah, because it's really possible to shut down your "php"...
At least you're getting the heads up if you have a blog on wordpress.

For sale.
bookmarkr is offline   Reply With Quote
Old 06-12-2009, 02:12 AM   #5
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by HBZSoftware.com View Post
Yeah, because it's really possible to shut down your "php"...
Look I'm not a tech but I do know that this can wipe out your php because My main site was hit a few months back - and my tech is world class security - ask Kevin Riley and Peter Bestel if I'm kidding. You might not be able to turn off your php, but everything on it can get pretty badly messed up from these things. This isn't a normal virus. It's taking down sites left and right.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 02:13 AM   #6
GarrieWilson.com
War Room Member
 
GarrieWilson's Avatar
 
Join Date: Jul 2006
Location: Mount Vernon, IL
Posts: 4,232
Blog Entries: 20
Thanks: 487
Thanked 299 Times in 184 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by HBZSoftware.com View Post
Yeah, because it's really possible to shut down your "php"...
You can disable PHP or tell it PHP files only use the extention .xxx

GarrieWilson is online now   Reply With Quote
Old 06-12-2009, 02:22 AM   #7
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

I not only lost everything php, I can't use mysql at all -we are rebuilding everything possible in HTML - it doesn't seem to effect HTML. I hadn't even started working on this one yet - the address my avast brought up with the alarm was the wordrpress install - I hadn't even hit install, page 6 of the themes menu was just loading. As soon as the alarm went off I cut that page and went back to my admin but I already wasn't able to get back on admin - avast blocked it.

On my other site we lost our forum, cube cart, coppermine photo gallery, and blog. There were so many security holes chewed that the virus was coming back in as fast as my tech could plug the holes. Every page in php was effected.
Peter Bestel is having problems not being able to keep it off and Kevin just had someone fix his site, not sure if he was able to totally get rid of it but if it is on the Wordpress site itself, nobody is safe and nobody will be able to keep it off. They are on their way to crashing out php on a lot of servers.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 02:28 AM   #8
GarrieWilson.com
War Room Member
 
GarrieWilson's Avatar
 
Join Date: Jul 2006
Location: Mount Vernon, IL
Posts: 4,232
Blog Entries: 20
Thanks: 487
Thanked 299 Times in 184 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Sal,

You might want to consider getting a new host that will keep your server secure and a new tech guy because it sounds like he isnt as great as you may think.

GarrieWilson is online now   Reply With Quote
Old 06-12-2009, 02:35 AM   #9
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by GarrieWilson View Post
Sal,

You might want to consider getting a new host that will keep your server secure and a new tech guy because it sounds like he isnt as great as you may think.
Garrie - my tech is out now (heart surgery and family problems) he disabled everything for us though - and plugged the holes but didn't get everything cleaned - he did security for Government websites.

Anyhow -- this isn't MY site I'm talking about now - - this is on WORPRESS's site. That means every script hooked to it is in danger - and if you want to mess with it, fine, but you might want to talk to Kevin and find out the problems that his tech went through with it if you don't think mine was capable. Or find out if Peter was able to FINALLY get them off or if he is having to rebuild (which won't do much good since it's on worpress itself now).

Like I said - this is not a JOKE - not by a hell of a longshot. No one who is dealt with this one so far is going to take this lightly.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 02:46 AM   #10
Veteran Marketing Warrior
War Room Member
 
Join Date: Jun 2009
Posts: 601
Thanks: 20
Thanked 80 Times in 63 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by HeySal View Post
I was just in admin on my new blog - was browsing the themes and all of the sudden my avast went nuts. I cut the connection but it was too late - my blog has JS redirect virus now -- new so I'm just going to toss it and hope that it can't spread on that server.

It is on the WP website itself so EVERYONE with WP might be vulnerable now.
Best thing you can do is shut down your php until they fix their virus problem because it will invade your whole site - everything but HTML.

This is NOT a joke.

I have contacted WP in a bug report and reported the virus on twitter hoping their admin will see it quickly - if anyone has an inside track to WP admin - they need to be notified IMMEDIATELY.
My servers have world class security as well. On one server I host sites for others, many of which have been hacked.

After much digging I discovered that the sites had actually been hacked over FTP.

Looks to me as if the users have caught a "drive by" trojan which is either a key logger or sends login details to the hacker.

I do not know he origin, but I do know it is spreading fast around the 'net.

I always suggest people run an anti-trojan program every day. The best in my view is:

A-Squared

Not aff link.
Adrian Cooper is offline   Reply With Quote
Old 06-12-2009, 02:48 AM   #11
You R GREAT if you are A
War Room Member
 
George Wright's Avatar
 
Join Date: Jul 2002
Location: Shakey/Sunny CA, USA.
Posts: 6,759
Blog Entries: 31
Thanks: 2,919
Thanked 1,835 Times in 737 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

HeySal,

Forgive my ignorance. When you say Wordpress are you talking about the blogs that are actually hosted by WP or the WP blogs we have installed on our own hosts.

Thanks,

George Wright

Coming Soon. InformationMotherload
STAY TUNED
When This Link Goes Live
You Will... To Be Continued
Line 6 Because I'm a WarRoom Member
George Wright is offline   Reply With Quote
Old 06-12-2009, 02:50 AM   #12
The Lord is My Sheppard
 
warf's Avatar
 
Join Date: Jun 2009
Location: Clarksville, TN
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
Social Networking View Member's Myspace Profile  View Member's Twitter Profile 
Contact Info
Send a message via Yahoo to warf
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

If you downloaded anything from any warez sites a person would be just asking for a hijack. another thing. avoid windows servers. linux can't physically host a virus. it's total impossible. The only thing a iframe virus is such: a iframe that opens a location on another website ( server ) and hosts the virus or maluware etc.etc.etc.
The best way to avoid this:
1.) only go to sites that you are familiar with
2.) use upper n lower case letters with symbols in your passwords to your websites.
3.) if you have to go to a website, go to yahoo google msn and see what is pulled up about the site. even siteadvisor.com/sites/thewebsitename.com/summary/
4.) before installing any program do your homework on it to ensure that your not installing a program that has a known exploit.

Anyhow I hope I was in some assistance

warf is offline   Reply With Quote
Old 06-12-2009, 03:09 AM   #13
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by George Wright View Post
HeySal,

Forgive my ignorance. When you say Wordpress are you talking about the blogs that are actually hosted by WP or the WP blogs we have installed on our own hosts.

Thanks,

George Wright
George - anything php is vunerable. I'm hearing a lot of denial here but this is the worst to hit the net yet. It is of Russian origin.

At the end of last year Government computers were hacked. My techs computer was hacked -- at the bios level! A few months later the JS redirect viruses started cropping up -- a lot of people that have it don't even have a clue. Avast will tell on it, but won't take it off, even though it looks like it is doing or has done so. It has to be removed manually.

On my site and many others WP was hosted on my server - I don't use fly by night servers, but still will be going to servage after this - just dumping everything that worked on php.

We had them get on our site manually - Fin had it hooked up so bots couldn't get on it - it was a live member. Got in and ran something on it manually from what he could tell. Built security holes all over so they could get back in then set a bot in there and loaded fake JS codes on EVERY PAGE that wasn't pure HTML. It was a mess. Enough so that I'm just dumping the whole load of php programs. After 3 years of continual build and a thosand or two pages, it's just easier.

ECS_Dave just set this WP up for a JV we are getting ready to build. So the blog is on his server - not sure which one - doesn't matter, the virus came straight from the wordpress site. I was browsing for a theme and page 6 of the theme menu was loading and that is when my avast went off. I disconnected from the page immediately but it wasn't fast enough because I can't access my admin page now - my Avast won't let me. It was that fast. Avast gave the address of the virus as http://wordpress...../install/ but I had not even tried to install one of the themes yet.

That's all I can tell you. It is on wordpress.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 03:16 AM   #14
there is no spoon
War Room Member
 
Peter Bestel's Avatar
 
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,194
Blog Entries: 3
Thanks: 171
Thanked 355 Times in 139 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Can't join in the conversation much as I'm just out the door, but Sal is right, nasty little buggers. I can't confirm that the Wordpress site is infected (don't fancy going there just to check) but if it's on your server then your blogs and websites become unusable, flagged as trojan sites and redirect to numerous 'suspicious' sites.

My sites are looking OK just now but I've had to spend a lot of time on this issue and I've become a tad paranoid because of it.

Peter

Peter Bestel is offline   Reply With Quote
Old 06-12-2009, 03:28 AM   #15
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

yeah - avast gave a wordpress.com address for it -- but I was in such a damned big hurry disconnecting before it got my admin that I didn't get the whole thing - got my admin anyway. I am scanning my own computer right now just for gp's and will check my log and see if the compete address is listed even though I disconnected like a mad hatter to get away from it. I know it was on page 6 of the theme menu if you search it without perimeters - but all that means is that before the night is over it will probably be on all of the themes and into the widgets as well. It travels damned fast once it gets in. With so few anti-virus programs able to detect it half the web is going to be infested if they don't shut it down right away.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 03:57 AM   #16
HyperActive Warrior
 
Join Date: Jul 2007
Location: across the universe
Posts: 347
Thanks: 7
Thanked 23 Times in 21 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

So if your site is infected it looks all scrambled up or how can you tell if it's been infected?
emigre is offline   Reply With Quote
Old 06-12-2009, 04:13 AM   #17
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

You won't see it. The only way you will know it is there is if you have Avast - it will alert you that there is a virus. If you are good at Java script codes you will see slight differences from real codes - it loves yahoo counters. If you have one and know the Java script you have almost an automatic signal right there. Not sure how the site will act to others because my avast blocks access to an infected sites. Most anti-virus programs won't detect it. If it's on your computer Avast will make you believe it took it off, but it doesn't - you have to do it manually - if you go to my profile, go all the way back to the beginning of my thanked posts and the discription of the one you get on your computer itself will be described there. There is a similar audio address, too.

On your website, it just creates complete havoc as it sinks in (it's a worm that eventually plants a root kit so nothing is safe if you don't get it off. It will redirect visitors to other sites as well. Not good ones either. Great for your future traffic, eh?

Thanks Russia - I used to be proud of my Cossack roots.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 04:17 AM   #18
Freeman Creations
War Room Member
 
GrantFreeman's Avatar
 
Join Date: Nov 2006
Location: Somewhere next to a desert cactus, USA.
Posts: 1,078
Blog Entries: 6
Thanks: 273
Thanked 62 Times in 37 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to GrantFreeman
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Thanks Sal. Considering starting a wordpress blog tonight and came across the thread. I see a few mentions of the JS virus at McAfee's site:

JS/Downloader-BNL

Is this the same one you're talking about? If it is,

"This trojan can get installed while browsing Websites where it has been hosted."

Sounds like it might be a good idea to wait on installing any WordPress themes if anyone else is thinking about it.

Grant
GrantFreeman is offline   Reply With Quote
Old 06-12-2009, 04:23 AM   #19
Zen Redneck
War Room Member
 
Join Date: Jul 2002
Location: Erie, PA
Posts: 12,247
Blog Entries: 4
Thanks: 1,066
Thanked 8,793 Times in 2,327 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Possibly the problem?

PHP Script Injection Exploit in WordPress 2.7.1 | TechJaws: Internet Security and SEO


Get... Paul's Handy Little Guide to the Warrior Forum

Trust me. It will help. And it's free.

Paul Myers is online now   Reply With Quote
Old 06-12-2009, 04:36 AM   #20
Christmas Rocker
 
Join Date: Aug 2006
Location: North Pole
Posts: 2,380
Blog Entries: 1
Thanks: 545
Thanked 696 Times in 372 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

I experienced something similar with Kaspersky this week. It flagged ad.doubleclick.net redirects on bbc.co.uk and apple.com as phishing sites.

I phoned doubleclick about it and seems to have cleared up.

Martin

"Merda taurorum animas conturbit"
Martin Luxton is offline   Reply With Quote
Old 06-12-2009, 04:50 AM   #21
French Warrior
War Room Member
 
cima's Avatar
 
Join Date: Feb 2009
Location: Marseille, France
Posts: 146
Thanks: 11
Thanked 4 Times in 3 Posts
Social Networking View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?

Cheers, Samuel.

My Brand New Forex Trading System :
www.UltimateForexTradingMethod.com

And My Forex Review Blog : www.UltimateForexReview.com
cima is offline   Reply With Quote
Old 06-12-2009, 04:55 AM   #22
Advanced Warrior
War Room Member
 
zeurois's Avatar
 
Join Date: Feb 2007
Posts: 511
Thanks: 24
Thanked 23 Times in 9 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by Paul Myers View Post
It's because they (wp) recently introduced the auto-upgrade feature, which requires writing permissions, and therefore, any code injection can alter your php/theme files and forward the virus/exploit to others. It sucks. I just upgraded to 2.8 without even knowing about this thread but I hope they've fixed it already and I'm not exposed.


zeurois is offline   Reply With Quote
Old 06-12-2009, 05:01 AM   #23
Advanced Warrior
 
John Henderson's Avatar
 
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 601
Thanks: 264
Thanked 189 Times in 134 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by cima View Post
Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?
Samuel, the infection happens on the remote server that hosts your blog -- not on the computer you have at home.

However, the operating system that your server uses (Windows, Linux, MacOS) could be a factor in how susceptible it is to certain attacks.
John Henderson is offline   Reply With Quote
Old 06-12-2009, 05:03 AM   #24
Freeman Creations
War Room Member
 
GrantFreeman's Avatar
 
Join Date: Nov 2006
Location: Somewhere next to a desert cactus, USA.
Posts: 1,078
Blog Entries: 6
Thanks: 273
Thanked 62 Times in 37 Posts
Social Networking View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to GrantFreeman
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

It's not a dumb question According to this it's possible:

Are Windows PCs Threatened by Malware Harbored on Mac & Linux OS’s? - Security Corner

The way I understand this, is if I downloaded a wordpress theme on my mac, and:

• uploaded it to my server space- It could effect people with PC's that visit my site
• sent it to a friend with a PC - It could effect my friends computer

Edit: or is this just an attack on web hosting machines only? Trying to understand this.

Grant

Quote:
Originally Posted by cima View Post
Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?

Cheers, Samuel.
GrantFreeman is offline   Reply With Quote
Old 06-12-2009, 05:07 AM   #25
Veteran Marketing Warrior
War Room Member
 
Join Date: Jun 2009
Posts: 601
Thanks: 20
Thanked 80 Times in 63 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by cima View Post
Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?

Cheers, Samuel.
Hackers write trojans for PC's.

A Mac is much safer from that perspective.
Adrian Cooper is offline   Reply With Quote
Old 06-12-2009, 05:10 AM   #26
Veteran Marketing Warrior
War Room Member
 
Join Date: Jun 2009
Posts: 601
Thanks: 20
Thanked 80 Times in 63 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by John Henderson View Post
Samuel, the infection happens on the remote server that hosts your blog -- not on the computer you have at home.

However, the operating system that your server uses (Windows, Linux, MacOS) could be a factor in how susceptible it is to certain attacks.
John: While that is generally true, there is a new breed of attack happening now.

Hackers are collecting logins via trojans and hacking sites over FTP - I am sorting out this issue for people hosted on one of my servers.

Trojans are nasty and insidious, which is why everyone should regularly scan for them using A Squared or whatever.
Adrian Cooper is offline   Reply With Quote
Old 06-12-2009, 05:20 AM   #27
Advanced Warrior
 
John Henderson's Avatar
 
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 601
Thanks: 264
Thanked 189 Times in 134 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by apc01 View Post
John: While that is generally true, there is a new breed of attack happening now.

Hackers are collecting logins via trojans and hacking sites over FTP - I am sorting out this issue for people hosted on one of my servers.

Trojans are nasty and insidious, which is why everyone should regularly scan for them using A Squared or whatever.
Yes, my mistake... An infection on your desktop machine co-ordinated with an attack on your online accounts and hosted space. Very nasty.
John Henderson is offline   Reply With Quote
Old 06-12-2009, 05:56 AM   #28
Senior Warrior Member
War Room Member
 
Tony Dean's Avatar
 
Join Date: Jun 2007
Location: Woking, Surrey, UK
Posts: 2,043
Thanks: 184
Thanked 88 Times in 76 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Does this mean we can't visit any WP blogs out there that are specifically hosted at WP?
Or can we visit other blogs that use WP elsewhere?

Tony Dean is offline   Reply With Quote
Old 06-12-2009, 06:03 AM   #29
Advanced Warrior
War Room Member
 
zoobie's Avatar
 
Join Date: Sep 2007
Location: hong kong
Posts: 933
Blog Entries: 2
Thanks: 3
Thanked 39 Times in 34 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by cima View Post
Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?

Cheers, Samuel.

Well Samuel. it is a php exploit or javacript level. It is nothing to do if you are using windows MAC or Linux.. It accepts the web browsers, Perhaps IE I think...

any issue using Firefox? anyone knows?

zoobie is offline   Reply With Quote
Old 06-12-2009, 06:14 AM   #30
Portuguese Warrior
War Room Member
 
Fernando Veloso's Avatar
 
Join Date: Nov 2008
Location: Good Old Europe
Posts: 3,487
Blog Entries: 6
Thanks: 1,310
Thanked 810 Times in 556 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to Fernando Veloso
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Thanks for the heads-up Sal.

Damn, Lots of trouble ahead this weekend. Is Hostgator usually secure from this issues?



Portugal Internet Marketing Since 2004.
Fernando Veloso | Seo Portugal | Empresa SEO
Fernando Veloso is offline   Reply With Quote
Old 06-12-2009, 07:46 AM   #31
Advanced Warrior
 
John Henderson's Avatar
 
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 601
Thanks: 264
Thanked 189 Times in 134 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

While I was getting something to eat today, I was watching "Working Lunch" on BBC2 (it's a show dedicated to money and business matters, and it's on at lunchtime).

The hosts of the show said "The gremlins have got into our website, so we can't direct you to that at the moment...". I immediately thought of this thread...

http://news.bbc.co.uk/1/programmes/w...ch/default.stm
John Henderson is offline   Reply With Quote
Old 06-12-2009, 11:25 AM   #32
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by Fernando Veloso View Post
Thanks for the heads-up Sal.

Damn, Lots of trouble ahead this weekend. Is Hostgator usually secure from this issues?
Usually secure doesn't seem to matter much with this one. As I said - the one on my site was actually planted by a member - and that means a live person brought it in. Bots could NOT get on my site. We were actually lullled by our level of security. Hadn't had spam on the site of any sort in over a year. It was a Russian - member name "easter" password "bunny". Real sense of humor. The virus seems to build security holes before it drops codes so that when it gets shut out it can get back in, then it starts on Java codes. The codes are very similar to real codes. You have to check every inch of your site when infected.

This virus started around about the time the US Gov computers got hacked. That might be a coincidence, but it also might just be some sort of show of power, too. Both Russian sources. So are they going to cyber war on the world or what?

IF you think that email phishers were sick bastards - this thing makes them look like boy scouts. I'm wondering how long it's going to be before they start stamping this crud with an "over 100 million served" sign.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 11:31 AM   #33
French Warrior
War Room Member
 
cima's Avatar
 
Join Date: Feb 2009
Location: Marseille, France
Posts: 146
Thanks: 11
Thanked 4 Times in 3 Posts
Social Networking View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Thanks everybody for having answered... That seems to be such a nasty virus. But why do those jerks need to set up such virus ?!?!! What's the interest ??

My Brand New Forex Trading System :
www.UltimateForexTradingMethod.com

And My Forex Review Blog : www.UltimateForexReview.com
cima is offline   Reply With Quote
Old 06-12-2009, 11:35 AM   #34
AT gmail DOT com
War Room Member
 
CDarklock's Avatar
 
Join Date: May 2009
Location: Kent, WA
Posts: 6,947
Blog Entries: 4
Thanks: 1,740
Thanked 5,485 Times in 2,510 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via ICQ to CDarklock Send a message via MSN to CDarklock Send a message via Skype™ to CDarklock
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Why exactly is this story not on Slashdot - or any other news outlet I can find - after nine hours? Is this not really a WP site issue?

Talk Marketing Now
Donate to the Darklock Liquor Fund
Hey; I got nothin' to do today but smile,
'n-da, 'n-da, doo-da, and here I am.
CDarklock is offline   Reply With Quote
Old 06-12-2009, 11:51 AM   #35
Advanced Warrior
War Room Member
 
Barbara Eyre's Avatar
 
Join Date: Jan 2006
Location: North Carolina
Posts: 903
Thanks: 98
Thanked 31 Times in 25 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

I'm still confused, as this question hasn't been directly answered - I'm seeing references to both.

Does this affect only blogs hosted at WordPress.com ?

Or - does it also affect blogs that we install on our own websites?

Or - does it only concern WordPress themes (not themes from 3rd parties), which means it doesn't matter if your blog is installed on your own site or is hosted by WordPress.com ?

Barbara Eyre is offline   Reply With Quote
Old 06-12-2009, 11:53 AM   #36
Battle Scarred Warrior
War Room Member
 
MichaelHiles's Avatar
 
Join Date: Feb 2009
Posts: 2,563
Thanks: 665
Thanked 1,780 Times in 744 Posts
Social Networking View Member's Twitter Profile  View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Hey HeySal... PHP is teh suxx0r... in fact, any interpreted script is more vulnerable... check out DotNetNuke - The Leading Open Source Web Content Management Framework for ASP.NET

FOLLOW ME ON TWITTER!!! @MichaelHiles
Circle Me on Google+... http://gplus.to/michaelhiles
>>>>>>>> GET THE STRAIGHT TALK at http://www.michaelhiles.com
MichaelHiles is offline   Reply With Quote
Old 06-12-2009, 12:02 PM   #37
Advanced Warrior
War Room Member
 
SusanneUK's Avatar
 
Join Date: May 2008
Location: Swansea, South Wales, UK
Posts: 981
Thanks: 512
Thanked 182 Times in 123 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile 
Contact Info
Send a message via Skype™ to SusanneUK
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by Barbara Eyre View Post
I'm still confused, as this question hasn't been directly answered - I'm seeing references to both.

Does this affect only blogs hosted at WordPress.com ?

Or - does it also affect blogs that we install on our own websites?

Or - does it only concern WordPress themes (not themes from 3rd parties), which means it doesn't matter if your blog is installed on your own site or is hosted by WordPress.com ?
You and me both, I would also like clarification on these points, if anyone can give it that is

Sue

One-to-One WordPress Coaching Service Available at Low Hourly Rate - Let the frustration end now! WordPress Installs, Theme Design, Site Tweaks & other WordPress services available
SusanneUK is offline   Reply With Quote
Old 06-12-2009, 12:25 PM   #38
there is no spoon
War Room Member
 
Peter Bestel's Avatar
 
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,194
Blog Entries: 3
Thanks: 171
Thanked 355 Times in 139 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

This is my experience for those that need some clarification.

I've got a number of wordpress blogs hosted on Dreamhost (shared hosting). I use a mix of freebie themes and a few on the paid theme, Thesis. About three weeks ago my PC got a bunch of trojans, viruses etc all at once. At the same time my Dreamhost account was attacked with this Javascript iframe redirect, affecting ALL my wordpress blogs and a few static websites that I've got on that server.

It installs extra code into php files, normally index.php, admin.php, a few theme php files including both the free ones and Thesis and also onto some plugin files.

Installing Wordpress plugin 'Exploit Scanner' identified the baddies and I was able to clean up all the sites, only for it to return a few days later.

I purchased Craig Desorcy's Block Lock Down e-book, followed his instructions and since have been clean. Can't recommend that one highly enough.

Cleaning the PC has taken an eternity but I reckon I'm as clean as I can be for now.

I can't comment on the issue with the actual Wordpress site site being infected as I've not experienced it, but it's not impossible, for sure.

I reckon the initial infection on my PC keylogged my FTP and got to my server that way. I've got Roboform but for some reason wasn't using it for Filezilla (which I've sinced dumped). I now use Secure FTP together with Roboform.

Touch wood, everything appears clean, but I've said that before...

Check out the link that Paul Myers posted earlier in this thread, pretty much explains the minimum that needs to be done.


Peter

PS No doubt better quality hosting may have saved some hassle - hindsight's such a wonderfully accurate science.

Peter Bestel is offline   Reply With Quote
Old 06-12-2009, 12:35 PM   #39
Breakthrough Expert
War Room Member
 
Mark Riddle's Avatar
 
Join Date: Aug 2002
Location: Finally in Branson, MO !!, USA.
Posts: 1,171
Thanks: 228
Thanked 187 Times in 121 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

A Short answer to the can the mac be infected.

YES, and thousands are, because so there are so few people even bothering using AV software on macs there are tons of them infected.

Remember, Mac Operating system is isn't really an independent system its an interface written on top of the BSD version of unix.

Sal in the opening post is talking about the Wordpress.COM hosted site. NOT self hosted word press.


Mark Riddle

Mark Riddle is offline   Reply With Quote
Old 06-12-2009, 01:33 PM   #40
Is a...
War Room Member
 
ECS Dave's Avatar
 
Join Date: Sep 2007
Location: In the USA...
Posts: 862
Blog Entries: 8
Thanks: 48
Thanked 45 Times in 42 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to ECS Dave
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

I'm not certain how this code is getting into the php files...

I looked at a couple and they had some encoded javascript code
at the end of each of them. I didn't (shame on me) note which files,
but as this was a "new" installation, went ahead and uninstalled
using the fantastico utility. I then installed a new instance of the
latest wordpress (2.8), and have not seen any issues, thus far.

Of course, the password was changed...

By no means am I a web-security expert, nor do I portray one
in any shape or fashion, anywhere...
However, I have learned
the very first line of defense should be one's own machine.
This includes, but is not limited to a current, updated, and
reputable virus scanner -- A "malware" scanner -- and perhaps
some diligence with regards to the sites you visit.

Be Well!
ECS Dave

ECS Dave is offline   Reply With Quote
Old 06-12-2009, 01:39 PM   #41
Is a...
War Room Member
 
ECS Dave's Avatar
 
Join Date: Sep 2007
Location: In the USA...
Posts: 862
Blog Entries: 8
Thanks: 48
Thanked 45 Times in 42 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to ECS Dave
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by Mark Riddle View Post
Sal in the opening post is talking about the Wordpress.COM hosted site. NOT self hosted word press.


Mark Riddle
Actually Mark, Sal's talking about a self-hosted wordpress installation.
She was using the "Add New Themes" interface, built into the WP
dashboard, which links to the wp-themes.com site. Being the brave
soul that I am, I browsed the pages myself, but (thankfully) was unable
to recreate the error/problem/issue.

Be Well!
ECS Dave

ECS Dave is offline   Reply With Quote
Old 06-12-2009, 01:41 PM   #42
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

That's right Mark - this time I am talking about the wordpress site itself. I was browsing the themes available when I was hit.

On my other site - the WP was on my site's server - but it was actually the phpbb forum that they came in through.

Once more - if you have php scripts running, you are vulnerable. Anything with 777 permissions is vulnerable. I don't think it matters what system you are on and I think that some hosts are safer than others but not sure that any are completely safe. I'm not sure at this point if anything will ever be completely safe again.

I think I'm seeing that AVG is also able to detect the virus. Still probably have to remove it by hand, it really knows how to protect itself.

Whoever said their static scripts got hit too - that is just too scary to think about.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 01:54 PM   #43
HyperActive Warrior
War Room Member
 
Leon McKee's Avatar
 
Join Date: Jan 2009
Location: Bend, OR
Posts: 102
Thanks: 6
Thanked 9 Times in 8 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Mark, can you provide some independent links to verify your statements concerning the Mac OS?

Leon McKee

Quote:
Originally Posted by Mark Riddle View Post
A Short answer to the can the mac be infected.

YES, and thousands are, because so there are so few people even bothering using AV software on macs there are tons of them infected.

Remember, Mac Operating system is isn't really an independent system its an interface written on top of the BSD version of unix.

Sal in the opening post is talking about the Wordpress.COM hosted site. NOT self hosted word press.


Mark Riddle
Leon McKee is offline   Reply With Quote
Old 06-12-2009, 02:02 PM   #44
Breakthrough Expert
War Room Member
 
Mark Riddle's Avatar
 
Join Date: Aug 2002
Location: Finally in Branson, MO !!, USA.
Posts: 1,171
Thanks: 228
Thanked 187 Times in 121 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by Leon McKee View Post
Mark, can you provide some independent links to verify your statements concerning the Mac OS?

Leon McKee
Mac OS X - Wikipedia, the free encyclopedia

FreeBSD - Wikipedia, the free encyclopedia

Apple - Mac OS X Leopard - Technology - UNIX

Mark Riddle is offline   Reply With Quote
Old 06-12-2009, 02:03 PM   #45
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Dave - you did recreate it - or just didn't get rid of it. The main domain URL still sets off my avast. I'm not going any further on it as I don't want to have to get this thing off of my own computer, too.

Your FTP is probably compromised. Dump the site - it's not been worked on so not much loss and much easier clean up. Your whole hosting account is probably infested.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 02:36 PM   #46
Active Warrior
War Room Member
 
Join Date: Jul 2007
Location: Atlanta, GA, USA.
Posts: 93
Thanks: 14
Thanked 4 Times in 4 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Would anyone be able to advise me about this situation, please? After reading this thread, I went to check some things on a new WP self-hosted blog I just installed a couple of weeks ago. It's using version 2.8 and hosted on Hostgator.

I checked my latest visitors stats and saw something I'm concerned about. It shows:

Host: 83.148.64.25

* /featured/how-t%20.../arcade.php?phpbb_root_path=../../../../../../../../../../../../../../../../../../../../.
Http Code: 404 Date: Jun 12 09:12:17 Http Version: HTTP/1.1

* /featured/arcade.php?phpbb_root_path=http://forgottentreasures.net/../proc/self/environ%00
Http Code: 403 Date: Jun 12 09:28:16 Http Version: HTTP/1.1

Since this shows 403/404 codes does it mean everything is ok?

I am so new to WP blogs and this really has me worried.

Thanks so much for any help you can offer.

Angela
lakeview is offline   Reply With Quote
Old 06-12-2009, 02:44 PM   #47
HyperActive Warrior
War Room Member
 
Leon McKee's Avatar
 
Join Date: Jan 2009
Location: Bend, OR
Posts: 102
Thanks: 6
Thanked 9 Times in 8 Posts
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Mark, what I'm asking for are specific links that show the Mac OS is or has been infected. A lot of marketers do have Macs sitting on their desktops so it's a good idea to stay abreast of these types of issues to say the least.

Leon McKee

Leon McKee is offline   Reply With Quote
Old 06-12-2009, 03:07 PM   #48
Is a...
War Room Member
 
ECS Dave's Avatar
 
Join Date: Sep 2007
Location: In the USA...
Posts: 862
Blog Entries: 8
Thanks: 48
Thanked 45 Times in 42 Posts
Social Networking View Member's FaceBook Profile  View Member's Twitter Profile  View Member's YouTube Profile
Contact Info
Send a message via Skype™ to ECS Dave
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

I copied the code from one of the pages, and uploaded it to virustotal.com and got this result:

Virustotal. MD5: e47fd7ca9ad1adf9b0f8bba33e19fc5f JS:Bulered JS:Bulered

And google's results for "JS:Bulered" are limited, to say the least..

I tried several online JS decoders, but no go there either...

Hmmm...

Be Well!
ECS Dave

ECS Dave is offline   Reply With Quote
Old 06-12-2009, 03:14 PM   #49
The Nature Lady
War Room Member
 
HeySal's Avatar
 
Join Date: Nov 2004
Location: , , USA.
Posts: 4,099
Thanks: 2,673
Thanked 3,187 Times in 1,753 Posts
Social Networking View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by lakeview View Post
Would anyone be able to advise me about this situation, please? After reading this thread, I went to check some things on a new WP self-hosted blog I just installed a couple of weeks ago. It's using version 2.8 and hosted on Hostgator.
etc

Angela
What is your URL? My avast goes off when I land on an infected site - easiest way to tell.

Sal
PLR Ebooks: Weight - Mind - Pet/Dog
PLR Reports: Disaster
WF fundraiser WSOs: Ken Strong - KimW
HeySal is offline   Reply With Quote
Old 06-12-2009, 03:21 PM   #50
Active Warrior
War Room Member
 
Join Date: Jul 2007
Location: Atlanta, GA, USA.
Posts: 93
Thanks: 14
Thanked 4 Times in 4 Posts
Social Networking View Member's Myspace Profile  View Member's FaceBook Profile  View Member's Twitter Profile 
Default Re: WARNING - WORDPRESS.COM HAS JS REDIRECT VIRUS ON IT

Quote:
Originally Posted by HeySal View Post
What is your URL? My avast goes off when I land on an infected site - easiest way to tell.
HeySal,

It's Stress Free Wedding Planning

Thanks so very much!!! I'm in a bit of a panic here.

Angela
lakeview is offline   Reply With Quote
Reply

  WarriorForum - Internet Marketing Forums > The Warrior Forum > Main Internet Marketing Discussion Forum

Tags
redirect, virus, warning, wordpresscom

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -6. The time now is 06:45 PM.