Infected Webiste Help?

Discussion in 'HTML & Website Design' started by Josh Hughbanks, Feb 6, 2014.

  1. #1
    Recently some of the visitors to my site have reported that they are seeing gambling ads on the site and it is not loading. http://www.wiredirect.net

    Everytime I visit the site (or view source code) I don't see any problems. Proxy servers show to me fine, but browsershots.org said they wouldn't take a photo due to it being a gambling site (which is isn't).

    Can anyone help me track down this infection which is hiding from me.

    The users experiencing problems are using Safari and my host is HostGator if that helps.
     
    Josh Hughbanks, Feb 6, 2014 IP
  2. deathshadow

    deathshadow Acclaimed Member

    Messages:
    9,732
    Likes Received:
    1,999
    Best Answers:
    253
    Trophy Points:
    515
    #2
    Tried all four major browsers here, and it's pretty much copypasta spam -- the whole page is just filled with gibberish crap that yes, appears to have words like ... well:

    Australian casino, australian and new zealand regulation sockets yet very have electrons blackberry jde 6.0 0 download on them for third usage, not in the uk.  Clubs may be dealt amazing spiderman free download game either market or life, depending on the manner of chance being played.  an evil turn, which I told him, quite good-humoredly, vnc viewer download for redhat linux 
     that I should 
    For that divx 8 web player download chip summer, the recordable underside can distinguish between mother tricks dedicated to australian 1940s, which have to send their satellites in every video island, and discs shared by microprocessors to transfer their events one after the particular in narrow tolerances, online casino.
    Code (markup):
    As to what's causing that, I'm having trouble figuring out why you're not seeing that. It seems to be the actual page content being loaded from the server; when you were setting up did you put the IP address in your hosts file or something? It's possible your name has been redirected without your permission.

    Of course being the 'insecure by design' train wreck known as turdpress, almost anything could have happened to you... My advice would be to wipe it clean, install a fresh copy, restore from a known clean backup, and make sure everything is up to date; I'd also check to see if there are any security advisories for any mods/extensions you've installed. (which is why I don't like mods/extensions, they open security holes; of course since all the useful functionality is in extensions usually, that's another strike against turdpress' "insecure by design" philosophy)
     
    deathshadow, Feb 6, 2014 IP
  3. Josh Hughbanks

    Josh Hughbanks Active Member

    Messages:
    33
    Likes Received:
    4
    Best Answers:
    1
    Trophy Points:
    53
    #3
    I finally found the infected backdoors on my FTP, I still never figured out where they tied it in the theme/wordpress so I'm switching hosts to make sure the infection doesn't follow and only using my source files.

    I just found this one weird as it only showed to visitors with outdated browsers, which is why I never noticed it being hacked for over a month and I visited the site a lot.
     
    Josh Hughbanks, Feb 6, 2014 IP
  4. limitlessjz

    limitlessjz Well-Known Member

    Messages:
    252
    Likes Received:
    72
    Best Answers:
    1
    Trophy Points:
    165
    #4
    Yeah, we've all been there man. Filezilla stores your FTP details in plain text and makes it readily available for many people to hijack if not taking the proper precautions. Check the footer.php and make sure they didn't stuff something in there. Also check the header. Most usually iframe in those two files.
     
    limitlessjz, Feb 6, 2014 IP
  5. RobinInTexas

    RobinInTexas Active Member

    Messages:
    217
    Likes Received:
    14
    Best Answers:
    2
    Trophy Points:
    65
    #5
    Back doors will give the bad guys complete access to your account, once they get get in a back door they can install just about anything. They could do a complete reinstall of your WordPress site in a matter of minutes.

    I'd recommend that you install Wordfence plugin that will scan your WordPress daily and also block many hack attempts.

    For a one-shot scan of your whole hosting account, if WordPress is in the root of your account, try
    Anti-Malware (Get Off Malicious Scripts)
     
    RobinInTexas, Feb 6, 2014 IP
  6. AlbCoder

    AlbCoder Well-Known Member

    Messages:
    126
    Likes Received:
    1
    Best Answers:
    1
    Trophy Points:
    163
    #6
    I just posted a thread today about this problem here,
    on this article you will find your solution so download the cleaner.php and upload to your web directory and scan by opening with your browser because the plugin given above me doesnt work good.
     
    AlbCoder, Feb 9, 2014 IP
  7. Jayde86

    Jayde86 Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #7
    You see, the security of the website is the most important factor of web designing because if the website is not safe enough it will affect the lead generation process in terms of driving away traffic from your site. Before you decide to hire a web designing company always make sure whether they understand your requirements and can handle the projects accordingly. It’s better to do some research before falling victim to such attacks.
     
    Jayde86, Feb 19, 2014 IP