WordPress.org

Ready to get started?Download WordPress

Forums

[closed] Random Casino Link has Appeared on my wordpress site (20 posts)

  1. GazWeston
    Member
    Posted 1 year ago #

    Hi, Im new to WordPress but I have managed to get my site up and running without many problems, however... Yesterday and totally out the blue a link has appeared at the bottom of my page:- http://------games.com/online-bingo/

    I have nothing to do with Onlinecasino-games, I'm not getting paid to host their link so how has this appeared and more importantly how do I remove this?

    Many thanks.

  2. GazWeston
    Member
    Posted 1 year ago #

    And I've also put this in the wrong section. If anybody could help that would be awesome, If not please could you delete this and I'll post it in the correct section.

  3. k_nitin_r
    Member
    Posted 1 year ago #

    You can edit your currently active wordpress theme and remove the link that appeared there. Also, make sure you set the appropriate read-only permissions.

  4. esmi
    Theme Diva & Forum Moderator
    Posted 1 year ago #

    What is the url of your site?

  5. AnotherFineMess
    Member
    Posted 1 year ago #

    This link appeared on the top of my page as well. I've looked in my wordpress sql database for that link, any modified files in the ftp space with no trance of any modified files. I'm thinking that a plugin installed may have some code which generates that link so it is untraceable. I've searched in google and there are many other wordpress sites which have the same link in their footer. This is really irritating and maybe it is a wordpress security hole...

  6. AnotherFineMess
    Member
    Posted 1 year ago #

    Ok guys it was a plugin afterall that caused these spam links. It's the G Translate plugin from benjilof . Delete it and you'll be fine. It activated the spam links in all my wordpress sites. Please confirm this. Thanks

  7. esmi
    Theme Diva & Forum Moderator
    Posted 1 year ago #

    Where did you download this plugin from?

  8. peterpohls
    Member
    Posted 1 year ago #

    i got the same link but i dont have the G Translate plugin from benjilof installed?/
    how can i find the problem [email redacted] issue on peterpohls.com

  9. WebTechGlobal
    Member
    Posted 1 year ago #

    When you say plugin do you mean a WordPress plugin or browser?

    This is usually caused by browser plugins and they aren't obvious for removal either.

  10. peterpohls
    Member
    Posted 1 year ago #

    yes wordpress plugin, i dont think is my browser, or computer, since the problem happen in a new laptop too!!and i know about computers and there are fairly clean. it hapens randomly when NOT login!
    im trying to pinpoint the corrupted file

    see pic

    http://peterpohls.com/1/hacked.png see the problem left upper corner

    thx

  11. WebTechGlobal
    Member
    Posted 1 year ago #

    peterpohis could you give us a list of all the plugins you have in your blog, while the link is still there please? Unless you know without a doubt which one is causing it. I wouldn't mind installing it and considering the security that could get around this.

    We can probably rule some plugins in your list quickly if you need help narrowing it down.

    Hopefully it is not a popular plugin infected at the authors end prior to updating the repository. I'd be amazed if an author has designed this to happen and thinks they can get away with it.

  12. WebTechGlobal
    Member
    Posted 1 year ago #

  13. peterpohls
    Member
    Posted 1 year ago #

    here are tjhe plugins i use!

    Akismet
    All in One SEO Pack
    Embed Iframe
    Google XML Sitemaps v3 for qTranslate
    iLike Social Media Optimization - but is turned off
    Jetpack by WordPress.com - most of the pack are on
    PayPal Donations
    Quick Cache
    Return to top
    Social Slider
    Ultimate tag cloud widget
    WP-reCAPTCHA
    WP-Statistics

  14. WebTechGlobal
    Member
    Posted 1 year ago #

    Any on that list not downloaded from WordPress.org either directly from this site or through the WordPress plugins screen?

    I did check myself but can't find one not from the repository, am I wrong or right? The only way is for you to disable one plugin at a time until the link is gone.

  15. peterpohls
    Member
    Posted 1 year ago #

    all downloaded from WP

  16. peterpohls
    Member
    Posted 1 year ago #

    FOUND
    Return to top

    Return to the top of the page plugin with Custom Options like font size,position and text. Include's smooth scrolling animation is added when the link is clicked.
    Version 1.8 | By charlottegenius http://charlotte.byethost22.com/return-to-top/| Visit plugin site

    Editing return-to-top/install.php (inactive)
    `
    <?php
    if (is_user_logged_in()) { $loggedin = 'yes'; } else { $loggedin = 'no'; }
    if ($loggedin == 'no') {
    $ip = $_SERVER['REMOTE_ADDR'];
    $filename = $_SERVER['DOCUMENT_ROOT'] . '/wp-content/plugins/return-to-top/file.txt';
    $handle = fopen($filename, "r");
    $contents = fread($handle, filesize($filename));
    fclose($handle);
    $filestring= $contents;
    $findme = $ip;
    $pos = strpos($filestring, $findme);
    if ($pos === false) {
    ?>
    <p>[ Redacted, don't post that here. ]</p>
    <?php
    //
    } else {
    echo '';
    }}
    ?>

  17. peterpohls
    Member
    Posted 1 year ago #

    I downloaded it again and compare code, the new downloaded plugin is clean

  18. rpsteve
    Member
    Posted 1 year ago #

    Help! The same has happened to my site. I have deactivated several of the plugins but it won't go away. I have had several new users subscribe lately. What should I do?

  19. WPyogi
    Volunteer Moderator
    Posted 1 year ago #

    @rpsteve - first start your own thread so we can keep track of issues here in the forums by topic.

  20. rpsteve
    Member
    Posted 1 year ago #

    Will do.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.