HELP! What To Do! iFrame Pixel Placed On My Site But Not By My Hand!

3 replies
Just found out that one of my websites had a pixel (iFrame) placed that wasn't done by my hand. When analyzing it with Firebug it redirected me to this website: http://protection.myar.net.in/in.cgi?2

Seems to be some script behind it that redirects people to a different website each time?

Now I have some programmers from India that are creating a new website for me. They are the only ones with the login info, next to me. But the last login was 4 days ago as the project leader has his marriage and the rest of his team were invited. The pixel wasn't there 2 days ago, my programming team didn't logged in for 4 days. So I could savely state that they can be excluded?

I am thinking that someone has injected this pixel in the SQL database or something? Somebody with more knowledge on this matter that could shed some more light on this matter would greatly help!

Also, what's is the greater benefit behind these pixels? Redirected traffic to their site? To get more hits? Was placed on a website that receives 2k visitors a day.

Deleted this by going in my FTP server and there was this .PHP file added with a very long md5 string. Deleted it, and with it, the pixel.
#hand #iframe #pixel #site
  • Profile picture of the author Will Edwards
    If your password was disclosed, it could quite easily proliferate if the recipient did not exercise the same care as you. I would change your passwords and discuss the matter with the company who was doing the work.

    Will
    {{ DiscussionBoard.errors[5569009].message }}
  • Profile picture of the author ibacklinkpro
    Your log shows that there were no logins in 4 days right? I would guess your CMS is the culprit, perhaps need to go to something more secure, like the latest version of WordPress or just a different one... there are quite a few CMSs that do not have all of their security holes patched up... Or perhaps the version of your CMS is old and you simply need to update it. Removing this PHP file will not fix the problem, this guy will be back most likely.

    I highly doubt your password is the issue here, unless your logs show logins...
    Signature

    Here is How to Steal Your Competitor’s High PR Backlinks:
    http://www.warriorforum.com/warrior-...free-demo.html

    {{ DiscussionBoard.errors[5569042].message }}
  • Profile picture of the author StevenJones
    The logs don't show logins, an old WP version could be the problem, it happens to be on a website that hasn't got the latest WP version yet. Will update now and monitor the site for a few days. Cheers.

    PS. Already checked up with the programmers, and it isn't by their doing either.
    {{ DiscussionBoard.errors[5569125].message }}

Trending Topics