Wordpress hacked.

Discussion in 'Site & Server Administration' started by William, Oct 30, 2009.

  1. #1
    One of my wordpress installations have been hacked.

    Someone have inserted links into the pages above the header tag. The links do not show in the source code of the pages. The only place I can see them is in google cache and in the source code of the google cache.

    I can not figure out where the problem is or how to remove it. The fact that the links only show in google seems to indicate that they are using some type of cloaking but I dont know how it is done. Any advice on where to look to be able to find it?
     
    William, Oct 30, 2009 IP
  2. logiczone

    logiczone Active Member

    Messages:
    326
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    75
    #2
    Maybe it's with the hosting which you have? Are you using a free webhost?
     
    logiczone, Oct 30, 2009 IP
  3. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #3
    We just had this discussion. Short answer: Chances are you;re using a theme with encrypting javascript in the footer and the theme developer is putting in their own links that only show when Google accesses the site. Change threads or remove the code from the theme's footer.php file.

    Long answer: I'm looking for the thread. Hold on.
     
    theapparatus, Oct 30, 2009 IP
  4. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #4
    No. It is on a dedicated server. None of the other wordpress installations on the server are affected. Other scripts or hardcoded pages are not effected.

    I can not find anything in the templates files (custom theme), the wp-blog-header.file is clean, the htaccess file is clean.
     
    William, Oct 30, 2009 IP
  5. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #5
    I am using a costum theme developed by myself. No javascrip or other encryptions in the footer.
     
    William, Oct 30, 2009 IP
  6. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #6
    theapparatus, Oct 30, 2009 IP
  7. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #7
    I have PM:d you the link.

    I am aware that WP needs to be updated and plan to do that tonight. Just want to resolve this first.
     
    William, Oct 30, 2009 IP
  8. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #8
    So you;re saying that you wrote this theme 100% from the ground up? Didn't use any other theme as a basis or a starting point?
     
    theapparatus, Oct 30, 2009 IP
  9. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #9
    I used the default theme as a starting point.
     
    William, Oct 30, 2009 IP
  10. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #10
    theapparatus, Oct 30, 2009 IP
  11. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #11
    Thanks. That seems like a great link. I will check all those files in a little while. I need to head out for 1 hour or so first.
     
    William, Oct 30, 2009 IP
  12. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #12
    I can't pull up the links though via their curl hack. Oh well. Please see what you can find and get back with us. I'm going home though for the night.
     
    theapparatus, Oct 30, 2009 IP
  13. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #13
    I think i found it.

    It was a active plugin injection as described on the site that directed to files outside the wordpress folder. Should be solved now. Thanks a million for the link. It really helped.
     
    William, Oct 30, 2009 IP
  14. William

    William Well-Known Member

    Messages:
    1,310
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    140
    #14
    Thanks. The htaccess file was among the first things i checked as well as the WP-blog-header file. But as I said in my last post. I think it is solved now. It was a active plugin injection. Should be gone now.

    I also closed the security hole they used to hack the site.
     
    William, Oct 30, 2009 IP