[SECURITY ISSUE] Many WordPress sites attacked with a1spysoftware.com link

Discussion in 'WordPress' started by jinsona, Nov 18, 2009.

  1. #1
    Hi,

    This is an alert for WordPress users.

    There is a report that many WordPress sites being hacked and malicious links and trojans being injected to the sites. The common feature of this attack is the injection of link to a1spysoftware.com site.

    My site was attacked multiple times in the last 2 weeks. I got report from other WordPress users about similar attack featuring links to a1spysoftware.com. This attack happens to even on the latest 2.8.6 version of WP.

    There is a thread on WordPress support forums regarding this
    http://wordpress.org/support/topic/327762
    Code (markup):
    Siteexplorer reveals hundreds of blog affected by this
    
    http://siteexplorer.search.yahoo.com/search?p=http%3A%2F%2Fwww.a1spysoftware.com%2F&fr=sfp&bwm=i
    Code (markup):
    Please report if you have experienced this and share how you cleaned this mess.

    Thanks
     
    jinsona, Nov 18, 2009 IP
  2. ads2help

    ads2help Peon

    Messages:
    2,142
    Likes Received:
    67
    Best Answers:
    1
    Trophy Points:
    0
    #2
    I saw the last reply on that topic was 2 weeks ago. Any more recent news?

    Funny, the hacker's website now has 40k backlinks, most of them is from the hack I guess.

    Wonder how they get in.
     
    ads2help, Nov 18, 2009 IP
  3. ThreeGuineaWatch

    ThreeGuineaWatch Well-Known Member

    Messages:
    1,489
    Likes Received:
    69
    Best Answers:
    0
    Trophy Points:
    140
    #3
    Where exactly does it inject the link? I am looking on some of those site and I do not see it.

    Could be a vulnerability in a plugin?

    EDIT: Ok, I see - it appends it to the footer.
     
    ThreeGuineaWatch, Nov 18, 2009 IP
  4. hostingsupport

    hostingsupport Peon

    Messages:
    180
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    i am really afraid that some common using plugin authors is going to hack the users site !!!
    this is a really security error...
    since iam using this wp 2.8.6 i used only my own scripts also i checks every script for the bugs and holes..
    :D

    if any one has this prob and doesn't know hw to remove the infection please fell free to pm me and i will fix it for you.
    happy to help :)
     
    hostingsupport, Nov 18, 2009 IP
  5. SteveWh

    SteveWh Member

    Messages:
    74
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    48
    #5
    SteveWh, Nov 18, 2009 IP
  6. jinsona

    jinsona Well-Known Member

    Messages:
    1,066
    Likes Received:
    93
    Best Answers:
    0
    Trophy Points:
    140
    #6
    jinsona, Nov 18, 2009 IP
  7. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #7
    This is one of the reasons why I moved my own blog over to MT and moved all of our client blogs over to Serendipity ages ago.

    edit: I personally prefer using http://milw0rm.com/ to monitor.

    reedit: Wordpress (And everything else that comes out of Automattic since that wp-syntax plugin is one of theirs as well) needs to have an actual external security audit. Every one previously done has either been internal or informal.
     
    theapparatus, Nov 19, 2009 IP
  8. Pixelrage

    Pixelrage Peon

    Messages:
    5,083
    Likes Received:
    128
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I wonder if a hacked Wordpress site will set off a flag in Google Webmaster Tools/Labs?
     
    Pixelrage, Nov 19, 2009 IP
  9. ilook

    ilook Well-Known Member

    Messages:
    1,602
    Likes Received:
    15
    Best Answers:
    1
    Trophy Points:
    165
    #9
    ilook, Nov 19, 2009 IP
  10. Pixelrage

    Pixelrage Peon

    Messages:
    5,083
    Likes Received:
    128
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Pixelrage, Nov 19, 2009 IP
  11. ilook

    ilook Well-Known Member

    Messages:
    1,602
    Likes Received:
    15
    Best Answers:
    1
    Trophy Points:
    165
    #11
    I submitted a report too.
    Everybody should do that to grab the attention of Google.;)
     
    ilook, Nov 19, 2009 IP
  12. theapparatus

    theapparatus Peon

    Messages:
    2,925
    Likes Received:
    119
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Congrats, you just encouraged a DDoS attack against Google. Please note that you've just admitted to doing so in public where your IP address is on record.

    I think just one or a few reports is fine. This isn't an election.
     
    theapparatus, Nov 19, 2009 IP
  13. ilook

    ilook Well-Known Member

    Messages:
    1,602
    Likes Received:
    15
    Best Answers:
    1
    Trophy Points:
    165
    #13
    Pfffffffffffff... DDOS attack on Google.
    The 30 people that REALLY take their time to fill in that form.
    Come on....:rolleyes:
     
    ilook, Nov 19, 2009 IP