Closing Doman Auctions
DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeRegisterMembershipsGetting StartedDomain Tools Domain EbooksSEO Software Domain Resellers Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Content Development > Website Development and Design Discussion
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 07-31-2009, 10:01 AM   #1 (permalink)
Platinum Lifetime Member
 
elivate's Avatar
 
Name: Peter
Last Online: Yesterday 08:16 PM
iTrader: (30)
Join Date: Aug 2005
Posts: 1,571
DNF$: 0
Location: Canada
Country:


Unhappy Wordpress site hacked... please help!

Update:
ok, so I just found all of the links in my footer.php file, so I am guessing this means that someone hacked in and accessed the files and also the ftp server ??




So I just got an email from Google mentioning that one of my sites is being removed from the index due to hidden text...

Sure enough, I check the source and a bunch of crap links have been injected into my site...

When I log in to the back end of WordPress I can't find the links in the actual page content or in the links section, has anyone had this happen before?

The code has this before the links:

<!--linksb-->
<b style="display:none">

and this after:

<!--linkse-->


Any thoughts?

I just made sure my WordPress install was up to date and I changed the password on the main account...


Last edited by elivate; 07-31-2009 at 10:08 AM..
elivate is offline   Reply With Quote
Sponsored Ads
Old 07-31-2009, 10:40 AM   #2 (permalink)
No Avatar
 
Last Online: Yesterday 09:34 PM
iTrader: (87)
Join Date: Mar 2003
Posts: 4,413
DNF$: 6,593
Location: Washington,DC


Can you tell us more, just for our own education.

I know some of the freebie templates are not always free because of this type of threat.
But, you are saying they hacked in?
Or, they already knew there was a backdoor?
__________________
Act Now


Twitter - dotcomgroup
actnow is offline   Reply With Quote
Old 07-31-2009, 11:09 AM   #3 (permalink)
41 LLL.nets For $35k!
 
tekz999's Avatar
 
Last Online: Today 01:11 AM
iTrader: (318)
Join Date: Jun 2003
Posts: 5,208
DNF$: 18,554
Location: Hong Kong
Country:


Which FTP program are you using to upload files?
Are your anti-spyware anti-malware anti-virus internet security suite up-to-date?
tekz999 is online now   Reply With Quote
Old 07-31-2009, 12:55 PM   #4 (permalink)
Platinum Lifetime Member
 
elivate's Avatar
 
Name: Peter
Last Online: Yesterday 08:16 PM
iTrader: (30)
Join Date: Aug 2005
Posts: 1,571
DNF$: 0
Location: Canada
Country:


ok, so I was able to fix this and I am now 99% sure what happened...

When you create a WordPress site you get an "admin" account and a randomly generated password. You should ALWAYS change the password and it is alco a good idea to create a new account altogether, so do not use admin at all... I know this but in thia case I did not make this change...

What the "hackers" do is they use their own password generator script which would likely be the same as what WordPress uses and they then use some program to brute force the site... once they get in they can change whatever they want in the "Edit Themes" section... So no ftp access was actually required to change the file...

So the lesson learned (which I already knew) is that you should never use the default admin account to manage your WordPress site...

I am lucky they didn't do much worse...
elivate is offline   Reply With Quote
Old 07-31-2009, 08:02 PM   #5 (permalink)
Exclusive Lifetime Member
No Avatar
 
Last Online: Yesterday 10:40 PM
iTrader: (24)
Join Date: Feb 2009
Posts: 892
DNF$: 4


thanks for informing us
__________________
buying lll.ca and generics. PM list and prices
victornumber is offline   Reply With Quote
Old 08-01-2009, 01:35 AM   #6 (permalink)
Platinum Lifetime Member
 
imneazmh's Avatar
 
Name: Neaz M H
Last Online: Today 12:08 AM
iTrader: (0)
Join Date: Jan 2009
Posts: 246
DNF$: 510
Location: Earth


I think that changing theme would be ultimate solution in this case. In future, please use wp themes from authentic sites whether free or paid. Remember, all free themes are not good.
__________________
Follow me on Twitter
imneazmh is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:16 AM.
Copyright @2001-2009 DNForum.com