Blog Mastermind Forums RSS Feed
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 9th June 2008, 09:28 AM
Blaine Moore's Avatar
Mentor
 
Join Date: Jan 2006
Location: Vacationland
Posts: 2,219
Send a message via AIM to Blaine Moore Send a message via Skype™ to Blaine Moore
Default WORDPRESS VULNERABILITY: Have you been hacked yet?

There is a hack going around that may or may not affect wordpress 2.5.1 blogs, but definitely affects all older versions. (There are known 2.5.1 blogs that are infected, but the general consensus is that they got hacked before being upgraded and carried the upgrade through.)

It is a very tricky problem. Basically, if somebody gets a search result in google and clicks through to your site, they are immediately forwarded to a spammer's site instead. A cookie gets dropped in the process, though, so that it doesn't happen a second time. This prevents site owners from noticing anything strange or troubleshooting it other than that google traffic begins to dry up. It can also lead to your site being temporarily delisted.

To see if your site has been hacked, clear the cookies on your blog (or use a computer that has never visited your blog) and do a search that returns a result that links to your page. Click the link. Did you wind up on your site? If so, you aren't being exploited right now and may not have been hacked. (Then again, you may have been.) If you do go to a scammer's site, you've definitely been hacked.

JD Roth has put up some good instructions for fixing your site, which you can read here:
Patching the WordPress AnyResults.Net Hack ∞ Get Rich Slowly

There is also a video that you may find helpful on YouTube:
YouTube - Remove Wordpress Spam Redirect
__________________
www.Run To Win.com
Reply With Quote
  #2 (permalink)  
Old 9th June 2008, 11:25 AM
Blaine Moore's Avatar
Mentor
 
Join Date: Jan 2006
Location: Vacationland
Posts: 2,219
Send a message via AIM to Blaine Moore Send a message via Skype™ to Blaine Moore
Default

Here's another good article on the exploit:

Did your WordPress site get hacked?
__________________
www.Run To Win.com
Reply With Quote
  #3 (permalink)  
Old 3rd July 2008, 02:41 AM
Beginner Blogger
 
Join Date: Jul 2008
Location: Bristol, UK
Posts: 4
Send a message via Skype™ to The Blogging Queen
Default I've been hacked twice

My membership site, which is run via WordPress was hacked about 4 months ago but more recently I discovered that an unused html page on my site had been hacked too ... seems it's not just wordpress.

Trish
Reply With Quote
  #4 (permalink)  
Old 3rd July 2008, 07:16 AM
Blaine Moore's Avatar
Mentor
 
Join Date: Jan 2006
Location: Vacationland
Posts: 2,219
Send a message via AIM to Blaine Moore Send a message via Skype™ to Blaine Moore
Default

Quote:
Originally Posted by The Blogging Queen View Post
My membership site, which is run via WordPress was hacked about 4 months ago but more recently I discovered that an unused html page on my site had been hacked too ... seems it's not just wordpress.

Trish
There are plenty of exploits out there. I was just pointing out one specific one that is easy to prevent as long as you upgrade before you are hacked or else clean up the hack and upgrade so that you don't get hacked again.
__________________
www.Run To Win.com
Reply With Quote
  #5 (permalink)  
Old 15th October 2008, 12:46 AM
Beginner Blogger
 
Join Date: Oct 2008
Location: Columbus, Georgia
Posts: 11
Default

I actually got hacked a few weeks ago as they put thousands of words under my header all leading to some site. It sucks because I work so hard on my blog and stuff like that sets me back. It really is quite sad.

Joshua Houghton
Certified Hypnotist & Blogger
__________________
Reality is only a illusion of perception
Online Hypnosis Community
Reply With Quote
  #6 (permalink)  
Old 17th October 2008, 06:05 AM
Beginner Blogger
 
Join Date: Jul 2007
Posts: 8
Send a message via MSN to quentin Send a message via Skype™ to quentin
Default The Secret

It is not just wordpress getting hacked but all manner of websites but especially those that us php source files.

The best thing to do is always keep your site updated and lock dit down with your HTACESS file.

Just do a search for your particular program and what it suggests for your htaccess file.

Quentin
__________________
Streaming media for your website.
http://www.beststreamingmedia.com
Reply With Quote
  #7 (permalink)  
Old 20th October 2008, 06:55 AM
mintblogger's Avatar
Beginner Blogger
 
Join Date: Oct 2008
Location: New Delhi, India
Posts: 22
Default

We can avoid most of the hacking attempts by doing a secure installation of Wordpress. Check out this excellent post to secure your Wordpress installation.

Fighting Blog Hacks: Preventing And Eliminating Intruders | Lost Art Of Blogging
Reply With Quote
  #8 (permalink)  
Old 9th December 2008, 05:23 AM
CodrutTurcanu's Avatar
Blogger
 
Join Date: Jun 2008
Location: Romania
Posts: 35
Default It sucks to get hacked...

I never been... I make sure I keep my wp blog up to date and back-up everything... I use all kinds of plugins to save me time and avoid the hacks...

what about you?
__________________
<a href=http://www.web-traffic-club.com>Get FREE Web Traffic Tips</a>
Reply With Quote
  #9 (permalink)  
Old 16th December 2008, 03:43 AM
Blogger
 
Join Date: Nov 2008
Posts: 31
Default

I have been a victim of Wordpress traffic redirection in one of my Blog . My blog's traffic was redirected to another site using a code execution in header.php . This happened when i changed my wordpress theme . Later , i shifted myself to Blogger . Now there's less hacking attempts .
__________________
I write about blogger tips and tricks & blogger templates .I also blog on seo related issues on my blog techknowl.com
Reply With Quote
  #10 (permalink)  
Old 26th January 2009, 04:49 PM
tmarek's Avatar
Recent Blog:
Moderator
 
Join Date: Mar 2007
Location: Milwaukee, WI, USA
Posts: 140
Send a message via Skype™ to tmarek
Default

Haven't had my site hacked yet, but I have been able to crash it pretty good at times. :P

Thanks for the post Blaine, I'll keep those links in mind.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -5. The time now is 08:08 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0