Link Jacked ! Strange Code Showing Up in my Template Files

Discussion in 'Security' started by hmansfield, Jan 18, 2009.

  1. #1
    Can anyone tell me how can someone else FTP access to install link codes into my template files ?

    Every now and then I notice strange link codes in the template files of my blogs.
    They are links to blogs that I don't know.

    It's starting to piss me off. Has anyone else experienced this ?

    I am the only one with access to FTP besides my host and I trust them wholeheartedly.
     
    hmansfield, Jan 18, 2009 IP
  2. PowerZ

    PowerZ Peon

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Perhaps theres a flaw in wordpress if your using that anyway. :)
     
    PowerZ, Jan 18, 2009 IP
  3. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #3
    It's not showing up on the blog, it's showing in the template files that you need FTP to access.
     
    hmansfield, Jan 18, 2009 IP
  4. Xtension

    Xtension Banned

    Messages:
    75
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    change password
     
    Xtension, Jan 18, 2009 IP
  5. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Most likely you are using an old and vulnerable version of blogging software. Security holes allow insert arbitrary code in any files without FTP access.

    Anyway, bad guy can simply steal your passwords if your local computer is indected, or just use a brute-force attack if your passwords are weak.

    However links in blog template files are usually caused by security holes in the blogging scripts. Upgrade as soon as possible.
     
    UseShots, Jan 19, 2009 IP
  6. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #6
    I am using the most updated version. I have already changed the password. Thanks for the tips.
     
    hmansfield, Jan 19, 2009 IP