1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Huge Problem!! Please Help!!

Discussion in 'WordPress' started by baskin, Jan 25, 2009.

  1. #1
    Hello,

    I guess I am in real trouble. I was just viewing my blog's Google Analytics report and I found a really bizzare url from my themes folder which actually does not physically exist... its something like
    /wp_content/themes/classic/bankofamerica.com/....

    I really dont know where it came from. And I again checked my analytics account 2 minutes ago and there is another similar link...
    /wp-content/themes/classic/www.wellsfargo.com.www .wellsfargo. com
    Does anyone know what the problem is about??
    I have set my folder permissions to 644, but even then, this is happening.
    Where could the fault lie...??
    Here is the screen shot...

    [​IMG]
     
    baskin, Jan 25, 2009 IP
  2. carminx

    carminx Peon

    Messages:
    381
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #2
    as you can see your site was hacked. now it host a scam for bank of america. remove it and take a look at the logs.
     
    carminx, Jan 25, 2009 IP
  3. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    how am i supposed to do that!!??:confused:
     
    baskin, Jan 25, 2009 IP
  4. buldozerceto

    buldozerceto Active Member

    Messages:
    1,137
    Likes Received:
    43
    Best Answers:
    0
    Trophy Points:
    88
    #4
    I think someone was trying to hack you. Check the IP address to block them.
     
    buldozerceto, Jan 25, 2009 IP
  5. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Checking IP and blocking!!?? How is that...:confused:
    God!!! Wats happening...
     
    baskin, Jan 25, 2009 IP
  6. myp

    myp Well-Known Member

    Messages:
    1,281
    Likes Received:
    71
    Best Answers:
    0
    Trophy Points:
    140
    #6
    The files may be hidden, make sure you enable 'show hidden files' in your ftp and then you should be able to delete them.

    Edit: As for ip blocking, if the visits to those urls were direct then just ban the ip addresses of those visitors. If it wasn't direct, then it may not actually be the people who did the hack as they could've simply followed a link.
     
    myp, Jan 25, 2009 IP
    farrhad likes this.
  7. craiger22

    craiger22 Well-Known Member

    Messages:
    1,472
    Likes Received:
    99
    Best Answers:
    0
    Trophy Points:
    170
    #7
    I would also contact your host as well. They can log into the root account to be sure everything is clear. I am sure that they wont want the problem either.
     
    craiger22, Jan 25, 2009 IP
    farrhad likes this.
  8. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Thanks guys... I did contact the host. But they said that even they were not able to view any such file. I also enabled the "show hidden files" option, but nothing is seen as such...


    I just checked for the IP addresses in my cPanel and I am not sure whether or not to ban the IP

    I didnt understand this "Referer" thing... now, should I ban the IP address given as 'Host' ??
    Also, there are a range of IP addresses from 64.12.116.14 to 64.12.117.108 which are displayed in the same way as above.
    Should I ban this entire range??
     
    baskin, Jan 25, 2009 IP
  9. bojomojo

    bojomojo Peon

    Messages:
    921
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #9
    this is code injection, you placed correct permissions for the folder but not the theme files
    your theme files has been edited to show such links, I would go over them to see which has such links and remove them, then re build your sitemap.
     
    bojomojo, Jan 26, 2009 IP
  10. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Hi, Can you be a bit more clear about this ? I mean, this link starts from my main theme folder and not from any of its sub folder. And my main theme folder consists of no files. It just has sub folders and they are set to 755.

    So where exactly should I go and search for these links?
     
    baskin, Jan 26, 2009 IP
  11. bojomojo

    bojomojo Peon

    Messages:
    921
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #11
    all the theme files, go to the theme editor in wp control panel, and insoect each file in there. they are not many.
     
    bojomojo, Jan 26, 2009 IP
  12. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Done that... but no such links found in any of the theme files...:confused:
     
    baskin, Jan 26, 2009 IP
  13. myp

    myp Well-Known Member

    Messages:
    1,281
    Likes Received:
    71
    Best Answers:
    0
    Trophy Points:
    140
    #13
    Check your page source to see if the bad links are still there (in firefox you can right click and hit 'view page source'.) If they are you and you haven't made any mods to your theme then you can simply delete it and then upload a fresh copy of it (if you have made mods, then you can still do this and redo the mods if you want.) See if that fixes it...
     
    myp, Jan 26, 2009 IP
  14. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Thankfully, the problem is solved for now as these links are not showing up anymore in my traffic report. But I wish it wont pop again in future.
    Thanks a lot you guys :)
     
    baskin, Jan 26, 2009 IP
  15. craiger22

    craiger22 Well-Known Member

    Messages:
    1,472
    Likes Received:
    99
    Best Answers:
    0
    Trophy Points:
    170
    #15
    craiger22, Jan 26, 2009 IP
  16. baskin

    baskin Banned

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Thank you craiger :)
    I did install the plugin.
    Things are going good now :)
     
    baskin, Feb 6, 2009 IP