Wordpress hacked

by Bill Ferris on June 7, 2008 · 9 comments

in Blog Software

For those of you using Wordpress to power your blogs you need to be on the look out for some hacking which appears to be widespread.

If you’re looking at your site you won’t notice it, but if you look at your stats you may notice a dip in referral traffic. The hack redirects visitors to your site coming from Yahoo and Google to a site called anyresults.net.

Not being a techie I can’t fully explain what is going on, but somehow the hacker gets access to upload a file and register it as a plug-in. Fixing it is a pain, and there may be other solutions, but here is what I did:

  1. Look in the wp_options table for the record with active-plugins. If you look at the list of active plugins you’ll see a number of familiar names as well as other characters. But there will also be an image file (jpeg, png) that has a name similar to an image somewhere on your site. That file isn’t actually an image, but a file with a bunch of garbage in it. Note the name and location of the file.
  2. Using your FTP client find the malicious file and delete it.
  3. Going back into MySQL check the users table. I noticed that in each instance there was another user created that doesn’t show up when you go in through your blogs control panel. Delete the record for that user.
  4. Reinstall Wordpress. And don’t just do an overwrite, but delete all the files and reload them.
  5. Change your passwords.

This doesn’t seem to discriminate as to the version of Wordpress you’re using. I was already at the latest, 2.5.1, and still got hit. I also doubt that these changes will persist so you may have to go through the exercise again – at least until Wordpress offers a security update.

The wordpress support thread can be found here.

{ 6 trackbacks }

» More Info on the WordPress AnyResults.net Hack for Hijacking Search Traffic
06.07.08 at 10:44 pm
My Blog Was Hacked. Is Yours Next? Huge Wordpress Security Issues
06.11.08 at 4:31 pm
Is your Wordpress blog hacked? Why not upgrade to the latest version? | MyTestBox.com - web software reviews
06.12.08 at 1:42 am
Helping with WordPress » Blog Archive » WordPress Security
12.15.08 at 8:30 am
Freshly Pressed » Blog Archive » WordPress security
08.30.09 at 11:18 am
WordPress Security
01.07.10 at 9:03 pm

{ 3 comments… read them below or add one }

1 antiquarian books 12.11.08 at 8:10 am

Thank you for this information. :)

2 Peter 09.02.09 at 4:05 am

Thanks for the info. there is someone how place in my content links from websites !!

3 Techie Talks 11.21.09 at 1:14 pm

Well the good thing in it is that you can easily know the data via SQL statements. On thing I have here is one sad thing, I have tons of php files and almost all got hacked. One good things is that avast detected those scripts

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Previous post: Bob Costas joins ranks of ignorant MSM

Next post: Padres seem to get blogging