WTH - Help me with hacked wordpress plugins

Discussion in 'Services' started by glenv, Jan 21, 2009.

  1. #1
    Person must understand not only wordpress but understand scripts that hackers may use to hi-jack sites.

    I have a site that is based on Wordpress. It has been working fine. This morning I had added my Google Analytics code to the footer and decided then I would update some plugins. Anytime I clicked on the settings of a plugin I had added it took me to:

    http://example.biz/

    I have disabled all plugins and added then back in one at a time and it still does it no matter how few I have and when I change up the order I reload them.

    I had someone looking at it and he is giving up after working hard trying to figure it out. He did discover the hacker is somehow loading an iframe to facilitate promoting his url.

    If anyone is willing to take a look I would sure appreciate it. Let me know by PM and I will send you ftp, wp-admin etc.

    The other member has done this:

    -checked all plugins for malicious code, and deactivated them

    -checked .htaccess in root + subfolders

    -installed a fresh copy of WP 2.7.

    -checked database for noscript, display,...

    Also see image attachment below for more information he provided.

    Please reply with quote and how quick you can get on this.
     
    glenv, Jan 21, 2009 IP
  2. vithca

    vithca Guest

    Messages:
    278
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #2
    One thing to consider if you are on shared (or worse free) hosting is that this could be done at server level. Try uploading a blank page something.htm and see if the iframe has been added.
     
    vithca, Jan 21, 2009 IP
  3. glenv

    glenv Peon

    Messages:
    930
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #3
    Its a dedicated server.

    The iframe only hijacks admin setting urls. The hijack does not effect what the user sees. Thats why I need someone with both server and wordpress skills.



     
    glenv, Jan 21, 2009 IP
  4. rliddle

    rliddle Peon

    Messages:
    248
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #4
    I have experienced your pain, and have thus written a program (paid - but worth it) which scans daily to see if you have been hacked so it can be fixed quickly. Not the answer you are looking for, but it is good to know. It is in my signature.

    Good luck man.
     
    rliddle, Jan 21, 2009 IP