Wordpress Hack Is Stealing Google Traffic

Discussion in 'Google' started by eugene mallon, Nov 29, 2008.

  1. #1
    so everyone sees this.

    how to see if you are hacked:

    clear your broswer cache.

    google your site name or url and click it though google. if hacked it will redirect. it is a tricky hack as when you type the url in your browser it seems fine.

    google wp-info.txt to find out more and for a solution or check with the wp support forum.

    check out the traffic stats of the site it redirects to:

    alexa.com/data/details/traffic_details/sattan dot org

    probably hundreds of thousands of blogs are affected.

    looks like the hack began around the 24th according to alexa.
     
    eugene mallon, Nov 29, 2008 IP
    Lordo and NaughtyNeo like this.
  2. StarkReality

    StarkReality Peon

    Messages:
    210
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #2
    This hack (or better: vulnerability) is known for a few months already, affects older wordpress installations, but it looks like there is a new flood of exploiters again. You are absolutely right, especially if you have loads of sites it can stay undetected for quite a a time and really hurt your business.
     
    StarkReality, Nov 29, 2008 IP
  3. aman11dhanpat

    aman11dhanpat Peon

    Messages:
    52
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    lol nice :) :D
     
    aman11dhanpat, Nov 30, 2008 IP
  4. Shellerz

    Shellerz Active Member

    Messages:
    1,011
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    78
    #4
    Thanks for this one. I've heard a lot about wordpress hacks but not really sure how to tell if it was happening so cheers
     
    Shellerz, Nov 30, 2008 IP
  5. tattoos

    tattoos Prominent Member

    Messages:
    1,903
    Likes Received:
    150
    Best Answers:
    0
    Trophy Points:
    335
    #5
    tattoos, Nov 30, 2008 IP
    JohnS0N likes this.
  6. WeWatch

    WeWatch Active Member

    Messages:
    75
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    50
    #6
    This particular hack works by checking the referrer in the HTTP header. If it's from www.google.com then it runs it's code. Otherwise, if you just type in the URL, it displays what you want.

    From Google = what they want.
    From URL = what you want.
     
    WeWatch, Nov 30, 2008 IP
  7. Lordo

    Lordo Well-Known Member

    Messages:
    2,082
    Likes Received:
    58
    Best Answers:
    0
    Trophy Points:
    190
    #7
    OMG This is ganna hurt many people!
    Thank you for sharing that Eugene. Rep added.
     
    Lordo, Nov 30, 2008 IP
  8. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Hi,

    Except for this WordPress hack, there had been a surge of .htaccess exploits last week that redirected search engine traffic to fake anti-virus web sites. All sorts of web sites were affected (pure html, WordPress, Drupal, etc.)
     
    UseShots, Nov 30, 2008 IP
  9. mini speakers

    mini speakers Banned

    Messages:
    135
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #9
    good post.
     
    mini speakers, Nov 30, 2008 IP
  10. Shocka

    Shocka Well-Known Member

    Messages:
    577
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    108
    #10
    Thank you for this post. My blogs have been hacked and I'm working on the solution right now. I'll let you guys know.
     
    Shocka, Nov 30, 2008 IP
  11. Shocka

    Shocka Well-Known Member

    Messages:
    577
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    108
    #11
    Here's a fix that I did to one of my sites that got it back going...

    Went into my PHPMyAdmin and deleted values in my wp_options that were similar to 'rss_867bd5c64f85878d03a060509cd2f92c' ... there were a couple of values similar to this.

    Next, I went to wp_users and deleted the additional invisible user that was created. The login name for this user was 'Wordpress'

    Then I upgraded to the latest version of Wordpress.

    This fix has worked so far. I am now recieving Google traffic once again. I'm not so sure its the "correct" fix but it's okay for now.
     
    Shocka, Dec 1, 2008 IP
  12. tattoos

    tattoos Prominent Member

    Messages:
    1,903
    Likes Received:
    150
    Best Answers:
    0
    Trophy Points:
    335
    #12
    Well it certainly seems to have made a fair impact on the blogging community.

    6 month Alexa spike
    [​IMG]

    7 Day spike.
    [​IMG]

    The graphs have not been updated since the 28th November. Wonder where it will stop..

    This is how widespread it has become in such a short time.
    [​IMG]

    Not sure how they plan to benefit from the traffic, if they try to monetize it, wouldn't that lead the authorities straight to them?

    Cheers
    James
     
    tattoos, Dec 1, 2008 IP
  13. JohnS0N

    JohnS0N Notable Member

    Messages:
    1,581
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    210
    #13
    Ouch, is the security breach fixed in the latest wordpress update?

    Thanks tattoos for the parasite scanner url.

    Nasty but very clever. If this guys monetization skills are as good as his hacking skills are, he will soon be taking a bath in a sea of gold.
     
    JohnS0N, Dec 1, 2008 IP
  14. NaughtyNeo

    NaughtyNeo Peon

    Messages:
    829
    Likes Received:
    41
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Dman.. almost all my blogs at Hostmonster are hacked. Thanks to the original poster for bringing this up.
     
    NaughtyNeo, Dec 1, 2008 IP
  15. flatroxs

    flatroxs Banned

    Messages:
    396
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Thanks for update
     
    flatroxs, Dec 1, 2008 IP
  16. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #16
    You know what is ever lamer and make problem for people it is the That just give you the same answer what ever link you put in so they can scare you and click some links.... sucks !

    thanks tattoos you sucx! YEAH it was me that gave you RED!!
     
    TheSyndicate, Dec 1, 2008 IP
  17. UseShots

    UseShots Peon

    Messages:
    244
    Likes Received:
    16
    Best Answers:
    0
    Trophy Points:
    0
    #17
    UseShots, Dec 1, 2008 IP
  18. JohnS0N

    JohnS0N Notable Member

    Messages:
    1,581
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    210
    #18
    w3 is written many times if you want to prevent the link benefit. (eg. you don't want the domain owner to find the referral url, or if you simply don't want to pass any value to that website)
     
    JohnS0N, Dec 1, 2008 IP
  19. pachecus

    pachecus Well-Known Member

    Messages:
    1,841
    Likes Received:
    62
    Best Answers:
    0
    Trophy Points:
    110
    #19
    pachecus, Dec 1, 2008 IP
  20. shipit

    shipit Active Member

    Messages:
    64
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    91
    #20
    That sucks, probably because it's so boring and slow to update wp.
     
    shipit, Dec 1, 2008 IP