Wordpress users on Rakspace cloud - check your themes for hacks

Discussion in 'WordPress' started by Benj Ash, Oct 3, 2010.

  1. #1
    The site i work on a lot at SelectProperty.com, recently suffered a security breach. This is probally old news for some of you, but i while back Rakspace cloud had a serious security breach. Resulting in large numebrs of wordpress site being infected with some very clever malicous code. Rakspace did warn me months ago, at which point i changed all my passwords etc. Sadly I wasnt made aware of how much of security breach this was, this was played down heavily by Rakspace. Even though it came from them using a version of MyPhpAdmin with a security hole. Leaving my database infected as well my themes and 404 redirects. Without my knowledge, months later the hackers strike. Leaving me indexed wrong and in an awkward position with my management.

    Now im left waiting for homepages to re-index without drug reference. At one point there where redirecting web traffic to drugs sites.

    Find out more here:

    http://blog.unmaskparasites.com/2010/06/14/attack-on-wordpress-blogs-on-rackspace/
    http://smackdown.blogsblogsblogs.com/2010/06/14/rackspace-hacked-clients-check-your-databases-wordpress-wp_optimize-backdoor-in-wp_options-table/

    I highly recomend anyone who is on Rakspace cloud, to audit there sites for security problems. Checking through the suggestions in the above articles.

    Thanks Rakspace.
     
    Benj Ash, Oct 3, 2010 IP
  2. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #2
    Thanks for the heads up. I had no idea Rackspace Cloud had been breached in this way.
     
    mcfox, Oct 19, 2010 IP