Forums

Help tracing where I'm being hacked (6 posts)

  1. neatlysliced
    Member
    Posted 8 months ago #

    I've been hacked and certain things are redirecting to some place generation-internet.ru. I didn't see any evidence in my htaccess files so I removed some themes and plugins, installed fresh stuff, deleted offending files that were added.

    Now, it was fine for a couple weeks. But now the same place keeps popping up. Images are redirecting to this place. I delete them. Things seem fine.

    NOW, I look at one of the files that I had deleted (still getting referrer traffic to this page)

    http://yum.neatlysliced.com/wp-content/themes/bueno/yahoolink.php

    The styles are gone, and if you look at the Net tab in firebug, I have GET requests to this place. I've searched my whole database and my entire web project and I don't see evidence of where this redirect could be ANYWHERE.

    Any ideas? Please help!

  2. ensignkid
    Member
    Posted 8 months ago #

    How are you searching? Are you using a grep-like program to search within large groups of text files for certain words?

    I would download the database, download your entire directory via ftp and then use Windows grep (I'm assuming you are on windows) or another application to do this. It's much much faster.

  3. esmi
    Theme Diva & Forum Moderator
    Posted 8 months ago #

  4. neatlysliced
    Member
    Posted 8 months ago #

    deleted for silliness.

  5. neatlysliced
    Member
    Posted 8 months ago #

    @esmi http://sitecheck.sucuri.net/scanner/ is amazing. Thank you.

    And I feel ridiculous because of course it was an htaccess rewrite. Did not even look for the scroll bar. They had a zillion lines of whitespace and then their rewrites.

    Foolish me. Lesson learned: Look for line breaks in htaccess!!

  6. neatlysliced
    Member
    Posted 8 months ago #

    And also, note for future that eclipse did not search my hidden files (htaccess) and that file of course I eyeballed.

Reply

You must log in to post.

About this Topic

Tags