I'm being hacked!!!

Discussion in 'Site & Server Administration' started by smackthat, Apr 14, 2008.

  1. #1
    Dear all,

    I just so happened to log on to my blog (self hosted blog using wordpress) today, and I noticed there's a long list of html codes linking to adults, viagra websites etc in my footer php. I never inserted those.

    Immediately I remove those, but after 10 mins later, new html codes popped up. Again i deleted again and again. I've deleted 19 times in the last 7 hours.

    Can you guys tell me what's wrong with it? Is there a bug or something in my blog? Or simply someone's hacking my blog??

    Please tell me..... I'm frustrated... and I'm sleepy, I can't monitor it 24/7

    Please help, your expertise is very much appreciated...

    Example of the codes: (just 0.001% of it)
    <!-- ~ --><u style="display:none"><a href="hxxp://brainoff*com/weblog/index.php?p=01741">difference between xanax and klonopin</a> <a href="hxxp://brainoff*com/weblog/index.php?p=03156">hypothyroid and ativan interaction</a> <a href="hxxp://brainoff*com/weblog/index.php?p=058">patent how long viagra</a>

    I've replaced tt with xx, and . with *
     
    smackthat, Apr 14, 2008 IP
  2. djacobs

    djacobs Well-Known Member

    Messages:
    238
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    140
    #2
    Looks like an XSS injection. Are you running the latest version of Wordpress?
     
    djacobs, Apr 14, 2008 IP
  3. smackthat

    smackthat Peon

    Messages:
    176
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I'm using wp 2.1, any idea how to get this sorted out?
     
    smackthat, Apr 16, 2008 IP
  4. djacobs

    djacobs Well-Known Member

    Messages:
    238
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    140
    #4
    Upgrade to the latest stable version. 2.5
     
    djacobs, Apr 16, 2008 IP
  5. _RaZoR_

    _RaZoR_ Peon

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Always best to keep updated with the latest versions no matter what it is you're using in my opinion (I'm saying that a lot nowadays lol).
     
    _RaZoR_, Apr 16, 2008 IP
  6. zidane-1986

    zidane-1986 Banned

    Messages:
    41
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    also check the security setting (using .htaccess...)
     
    zidane-1986, Apr 16, 2008 IP
  7. inworx

    inworx Peon

    Messages:
    4,860
    Likes Received:
    201
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Versions prior to 2.3 had a major security issue. You should consider getting latest version for stability, and of course, better security.
     
    inworx, Apr 19, 2008 IP
  8. sydneyaus

    sydneyaus Active Member

    Messages:
    1,110
    Likes Received:
    44
    Best Answers:
    0
    Trophy Points:
    88
    #8
    Remove the crap, before the search engines punish you, and upgrade to the latest version of WP.
     
    sydneyaus, Apr 19, 2008 IP
  9. smackthat

    smackthat Peon

    Messages:
    176
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Dear all,

    Thanks for your good opinion, I've done the upgrading, and everything looks perfect, not seeing the code anymore.

    Thanks again! Cheers
     
    smackthat, Apr 20, 2008 IP