adf.ly bots injected in my wordpress site

Discussion in 'WordPress' started by sahirfarid, Sep 24, 2012.

  1. #1
    Hey all!

    I have been facing this problem since last one week, some one has injected adf.ly bot in my website and now whenever I click on any of my website's link, than it opens adf.ly page instead of website's link. I have updated, and re-installed the whole site but it happened again. My sites URL is yesiknowthat.com, any idea? any solution?

    Regards
     
    sahirfarid, Sep 24, 2012 IP
  2. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #2
    I found this JS code before the </html> tag:

    
    <script>
    var adfly_id = [B]95535[/B];
    var adfly_advert = 'int';
    var exclude_domains = ['example.com', 'yoursite.com',];
    </script>
    <script src="http://adf.ly/js/link-converter.js"></script>
    
    Code (markup):
    If you remove it (theme file footer.php) the problem should be solved. I also suggest you to contact adf.ly and ask them to ban this ID.
     
    Devtard, Sep 24, 2012 IP
  3. sahirfarid

    sahirfarid Active Member

    Messages:
    240
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #3
    Thank you so much, my problem is solved but please tell me how can I stop these type of attacks..
     
    sahirfarid, Sep 24, 2012 IP
  4. JamesColin

    JamesColin Prominent Member

    Messages:
    7,874
    Likes Received:
    164
    Best Answers:
    1
    Trophy Points:
    395
    Digital Goods:
    1
    #4
    JamesColin, Sep 24, 2012 IP
  5. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #5
    I would guess that you have installed a plugin that is buggy as hell so it allows hackers to compromise your site.

    I recommend you removing all plugins with bad reputation or those that were updated years ago. Also reupload your default WP files to make sure that the hacker won't have there any backdoor that he might have left behind.
     
    Devtard, Sep 24, 2012 IP
  6. sahirfarid

    sahirfarid Active Member

    Messages:
    240
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #6
    Well, I have checked that, but I guess he breaks through my cpanel and than change the password of wp-admin.
     
    sahirfarid, Sep 25, 2012 IP
  7. sahirfarid

    sahirfarid Active Member

    Messages:
    240
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #7
    I am still facing the same issue.. :( Is there anyone to help me?
     
    sahirfarid, Sep 26, 2012 IP