Site Hacked - Need Help

Discussion in 'Security' started by glenv, Jan 20, 2009.

  1. #1
    I have a site that is based on Wordpress. It has been working fine. This morning I had added my Google Analytics code to the footer and decided then I would update some plugins. Anytime I clicked on the settings of a plugin I had added it took me to:

    http://example.biz/

    I have disabled all plugins and added then back in one at a time and it still does it no matter how few I have and when I change up the order I reload them.

    I had someone looking at it and he is giving up after working hard trying to figure it out. He did discover the hacker is somehow loading an iframe to facilitate promoting his url.

    If anyone is willing to take a look I would sure appreciate it. Let me know by PM and I will send you ftp, wp-admin etc.

    The other member has done this:

    -checked all plugins for malicious code, and deactivated them
    -checked .htaccess in root + subfolders

    -installed a fresh copy of WP 2.7.

    -checked database for noscript, display,...

    Also see image attachment below for more information he provided.

    Thanks so much.
     

    Attached Files:

    glenv, Jan 20, 2009 IP
  2. ahbuneh

    ahbuneh Active Member

    Messages:
    204
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    58
    #2
    Ok now? If not, drop me a pm so i can check out.
     
    ahbuneh, Jan 23, 2009 IP
  3. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Ground rule if you use popular CMS

    1. Always check updates once a week or 2 weeks
    2. Always use trusted/tested plugins.

    There appear vulnerabilities in Joomla! plugins every week or so.

    However, we, web developers, have the risk of being attacked/hacked.
    If your PHP is php 5.2 at least, you can try PHP IDS at http:\\php-ids.org
     
    justdoit1, Jan 25, 2009 IP
  4. glenv

    glenv Peon

    Messages:
    930
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #4
    It appears a theme I had developed by some friends in India was very vulnerable. I ended p having to replace the theme. Also, the culprit was a dirt bag from China that placed a redirect script on my domain.
     
    glenv, Jan 25, 2009 IP
  5. flamer

    flamer Peon

    Messages:
    757
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #5
    1. Always keep backup.
    2. If you get hacked, dont try to remove the hacked attempt codes as the codes of hacking are spread all around the site which will surely make your site more vulnerable to any other hack in future.
    3. Get the backup up and running. If you have different roles in your site with different permissions of admins/mods etc, reset them all.
     
    flamer, Jan 25, 2009 IP
  6. justdoit1

    justdoit1 Peon

    Messages:
    100
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Please don't keep hacked backup !!!!
    I've seen a friend who backups from the server.
    He kept regular backups. He didn't even know when his site was hacked.
    When he came to know, he restored. He RESTOrEd the hacked backup.
    Never finished!
     
    justdoit1, Jan 25, 2009 IP