Forums

[resolved] Strange auto-re-directing (6 posts)

  1. ics2s3b
    Member
    Posted 9 months ago #

    Hi there,

    A site I look after (http://www.cornellschoolofdance.co.uk) is re-directing to seemingly random sites. It appears to be very clever at doing so as it will do it once every 24 hours from whatever IP address I'm using and then will behave normally.

    I think it might have come about due to Timthumb.php which I've now deleted. I've also deleted common.php, udp.php and a randomly titled PHP file in wp-admin/js.

    Now, when it tries to re-direct me, I get redirected to "http://www.upliftsearch.com/?keyword=arcade%20cellulare%20giochi&aid=1234&cid=2237&subid=3470726093" where it says
    "Database: Could not connect: Host 'smokescreen' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts'"

    There appears to be some rogue code in my site that is playing havoc still, but I've no idea what/where it could be.

    Please help!

    SB

  2. foobuilder
    Member
    Posted 9 months ago #

    It looks like your site has been hacked and is being redirected to a spam site (which just happens to be down at the moment). Here are steps to take to recover from the hacking. Good luck!

  3. ics2s3b
    Member
    Posted 9 months ago #

    Cheers pal, seems to be sorted now. Was a rogue piece of code in the index.php file which I deleted. Seems to be sorted.

    These hacker types are crafty sods aren't they!

  4. Ipstenu
    Half-Elf Support Rogue & Mod
    Posted 9 months ago #

    Remember to change your passwords, and if you're using TimThumb in your theme or as a plugin, there is a need to update to the 2.0 version as there's a security hole :(

  5. ics2s3b
    Member
    Posted 9 months ago #

    yep, have deleted it :)

  6. dd@sucuri.net
    Member
    Posted 9 months ago #

    This uplifesearch redirection is related to the "superpuperdomain" attack that has been happening against sites using the vulnerable timthumb:

    http://blog.sucuri.net/2011/08/wordpress-sites-hacked-with-superpuperdomain-com-attacking-timthumb-php.html

Reply

You must log in to post.

About this Topic