My Wordpress is Hacked. (They are adding links in my content)

Discussion in 'Programming' started by konfuci, May 27, 2011.

  1. #1
    Hi


    I have three site on the ftp. All those three sites are on wordpress, they are getting hacked together.
    They are adding the links in my content. You can see it there:
    suntrustbanklocationscom.com

    amoxil online
    cheap Ampicillin Without Prescription buy online

    etc... Those links are added by hackers.

    That happens every 3-4 days. Links are added automatically, not by hand (manually).

    I have no idea what to do. changed passwords but they are still hacking my sites.


    Could you help me, have some of you the same problem?
     
    konfuci, May 27, 2011 IP
  2. Cash Nebula

    Cash Nebula Peon

    Messages:
    1,197
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Lots of people have the same problem. What template and plugins are you using?

    Free templates often have dodgy code in them. They could be getting in via a dodgy plugin.
     
    Cash Nebula, May 27, 2011 IP
  3. cmsexperto

    cmsexperto Peon

    Messages:
    11
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Hi,

    Very sad. You have to change the credentials (userid/password) of ftp and databases both. Also the same for admin panel of site.
    If possible change the name of database because default name is common or change the prefix of database.

    Also you are using plugins for advertisement and seo, so check its configuration.

    This solution will overcome the problem.
    Regards,
     
    cmsexperto, May 27, 2011 IP
  4. regdom

    regdom Peon

    Messages:
    38
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Usually this may occur when using unverified themes and /or plugins.Hackers often publish "nulled" expensive plugins with a lot of garbage inside,only for this kind of attacks.
    Use only certified source themes/plugins.
     
    regdom, May 31, 2011 IP
  5. ovalencia

    ovalencia Greenhorn

    Messages:
    42
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    16
    #5
    I had exactly the same problem.
    Right now is solved, I just reinstalled the WP last version, and using the same plugins. I changed the passwords, I hope this will be enough.

    My serp rakings lowered a lot, and the Google Webmasters account informed me that I had a lot of these garbage keyword into my wp website, and I got scared.
    Good luck!
     
    ovalencia, Jun 7, 2011 IP
  6. AppleH

    AppleH Peon

    Messages:
    73
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    1. You need zip your source and scan virus.
    2. Set password for dir admincp.
    3. Check you plugin and theme.

    Good luck!
     
    AppleH, Jun 11, 2011 IP
  7. Dhamodharan

    Dhamodharan Peon

    Messages:
    44
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    you can change your all details which is regarding your sites. like Domain name, personal information's, template design ,database name, passwords, clear all history with backup. make your each and every information as complicated.
     
    Dhamodharan, Jun 16, 2011 IP
  8. The Webby

    The Webby Peon

    Messages:
    1,852
    Likes Received:
    30
    Best Answers:
    1
    Trophy Points:
    0
    #8
    If they are just adding links, it is probably XSS injection. I'm not sure if wp is prone to XSS but as Cash Nebula pointed out, it could be due to a dodgy plug-in.
     
    The Webby, Jun 17, 2011 IP