• Welcome to DNForum.com - Domain Investor Forum, Free Domain Marketplace and a community for 45+ domain pros
    If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the oldest global domain name community on the internet and continues to grow every day. There are over 45,000 domainers on DNForum doing everything from buying domains, selling domains, using our free in-house built tools, learning about domains and discussing domains. Take a minute and Register.

Spam Injected Wordpress Theme

Status
Not open for further replies.

Shane

New Member
Legacy Platinum Member
Joined
Jul 6, 2012
Messages
1,719
Reaction score
354
So I just had to reset my server after receiving a nice message from Google informing that one of my websites was phishing. After a long hour of digging through my files I found a number of contaminated folders. I believe "the travel theme" (http://thetraveltheme.com/) was the source of my headache. Just wanted to warn everyone here just in case they stumble upon this beautifully skinned hell hole. STAY AWAY!
 
It's not spam, it's a malicious attempt to grab banking details from unsuspecting visitors. The hackers use your site to host the fake landing page. I know because I had around a million of these phishing attacks circa xmas time last year.
 
So I just had to reset my server after receiving a nice message from Google informing that one of my websites was phishing. After a long hour of digging through my files I found a number of contaminated folders. I believe "the travel theme" (http://thetraveltheme.com/) was the source of my headache. Just wanted to warn everyone here just in case they stumble upon this beautifully skinned hell hole. STAY AWAY!


timthumb
 
So I just had to reset my server after receiving a nice message from Google informing that one of my websites was phishing. After a long hour of digging through my files I found a number of contaminated folders. I believe "the travel theme" (http://thetraveltheme.com/) was the source of my headache. Just wanted to warn everyone here just in case they stumble upon this beautifully skinned hell hole. STAY AWAY!

Is "the travel theme" THE cause or hacker
injected malicious code into "the travel theme"?
 
The theme would have a security vulnerability it's not the hacker. As suggested above, you should install the timthumb vulnerability scanner plugin.
 
It's not spam, it's a malicious attempt to grab banking details from unsuspecting visitors. The hackers use your site to host the fake landing page. I know because I had around a million of these phishing attacks circa xmas time last year.

Yes exactly. It's a huge pain in the ass. I'm not sure if it was injected into the theme or if it was someone manipulating a security vulnerability. I'm pretty sure it was part of the the though. After installing the template and adding content I noticed the website was uunusually slow. I'm not an expert with this stuff by anymeans but I wanted to warn you guys about a potentially devastating issue.
 
fwiw you can still use the wp theme. simply identify and delete the phishing files and update the timthumb script using the plugin.
 
I was unable to delete the files. I tried with FTP, Plesk and SSH. The files showed up on my FTP client but the server didn't recognize them. It was a bizarre situation. This is my first month with a dedicated server though so I might be overlooking something simple. How do I scan my server for malicious files? Is there a piece of software I can use to help stop this type of problem?
 
Great, another thing I need to be paranoid about! :smilewinkgrin:

Is there a specific target niche that the hack is going after?
 
Great, another thing I need to be paranoid about! :smilewinkgrin:

Is there a specific target niche that the hack is going after?

It's a travel theme so I'm assuming the travel niche.
 
I was unable to delete the files. I tried with FTP, Plesk and SSH. The files showed up on my FTP client but the server didn't recognize them. It was a bizarre situation. This is my first month with a dedicated server though so I might be overlooking something simple. How do I scan my server for malicious files? Is there a piece of software I can use to help stop this type of problem?

That would be because your host changed file permissions.


Is there a specific target niche that the hack is going after?

Any niche. If your short and ugly you would be vulnerable.
 
shoutout to all the sexy ladies on DNF, you can take advantage of me :lol:
 
Status
Not open for further replies.
Back
Top Bottom