• Resolved Bad_Egg

    (@bad_egg)


    Got this a few days ago from my host:

    This notice is to inform you that we have detected malicious code in your website files. We have compiled a list of compromised files on your account, as well as the code injected, below.

    In order to maintain a secure hosting environment, we will be automatically correcting these compromised files on your account; however, please be aware that you are responsible for verifying that the content hosted within your account is secure. We strongly advise that you update your installed scripts and software, as outdated scripts and software are the most frequently used method for accessing and gaining control of a targeted account.

    If you need assistance updating the software on your hosting account, please do not hesitate to contact our Support department.

    The compromised files detected are:

    /home4/mademer1/public_html/globalindieauthor/wp-includes/js/tinymce/utils/ossdl-cdn.php

    The malicious code detected is similar to:

    Files with the following contents or MD5SUMs, which contain malicious code:
    \$default_action\s*=\s*[‘”]FilesMan[‘”]\s*

    When I check the directory, the ossdl-cdn.php is absent. So I cannot tell if my host removed it because “we will be automatically correcting these compromised files on your account” or because the files are hidden.

    I have looked this up and there are several examples of the same warning from one’s host provider but each time the alleged offending file is different.

    Any ideas as to how I can verify and remove this code?

    Thanks.

Viewing 15 replies - 1 through 15 (of 36 total)
  • Moderator James Huff

    (@macmanx)

    Hm, that seems odd, we have not heard of any such vulnerabilities in that file, so either the host is wrong, or the file was modified. It’s probably safest to replace all of the core files.

    Try downloading WordPress again and delete then replace your copies of everything except the wp-config.php file and the /wp-content/ directory with fresh copies from the download. This will effectively replace all of your core files without damaging your content and settings. Some uploaders tend to be unreliable when overwriting files, so don’t forget to delete the original files before replacing them.

    Thread Starter Bad_Egg

    (@bad_egg)

    Hi James,

    I’m not a programmer, so please bear with me. I installed WP originally via my site host, Just Host. I have three WP sites attached to my main website, which is not WP. The allegedly infected site is http://www.mademers.com/globalindieauthor.

    In my file manager on Just Host, when I look in the folder globalindieauthor, I can see the wp-config.php in the root directory, and I can see the subfolder wp-content. Are you saying I should delete the wp-includes and wp-admin folders, as well as all files in the root except for the wp-config.php?

    If so, when I download WP again through Just Host, will it not simply create yet another WP site? Do I have to do this through FTP instead?

    Thanks.

    P.S. It gets weirder. Just Host told me to check my site at sucuri.net. When I did, nothing in WP came up as infected. But two others did:

    http://mademers.com/404testpage4525d2fdc

    http://mademers.com/404javascript.js

    malware-entry-mwhjck3123?se1

    Malware entry: MW:HJCK:3123

    A hidden and suspicious javascript (or iframe) was found on the site. It is loaded from a blacklisted (and malicious domain) and used to steal information from site visitors and/or infect them. Loads malware from multiple locations:

    http://dsnextgen.com/?a_id=10636..
    http://perfumefrosty.org/nnc0xazxwahh5ifg/
    http://www.paid-to-promote.net/
    http://www.777seo.com/pop.php?username=..
    (and many other domains).</p>

    This malware is generally hidden on .js or .php files without heavy encoding.

    And of course to clean the site costs $99.00 I’m beginning to think I’m being had.

    Moderator James Huff

    (@macmanx)

    Are you saying I should delete the wp-includes and wp-admin folders, as well as all files in the root except for the wp-config.php?

    Yes.

    If so, when I download WP again through Just Host, will it not simply create yet another WP site?

    No, as mentioned, you will download WordPress from https://wordpress.org/download/ and upload the files via FTP.

    Sucuri is very trustworthy, so if they say you’ve been infected, it’s pretty definite you have.

    Given when you just mentioned above, I’d suspect that something has opened a backdoor in your hosting account and is infecting other files.

    When you’re done, you may want to implement some (if not all) of the recommended security measures, though that won’t protect the non-WordPress things.

    Thread Starter Bad_Egg

    (@bad_egg)

    Thanks, James. Will do as directed.

    The weird thing about the sucuri result is that I have never been notified of any infections on my main site (which gets only a fraction of the visits that my globalindieauthor site gets) from either my host or Google. And, as indicated, sucuri found nothing wrong with WP but Just Host did, while Just Host found malicious files on WP but nothing on my main site. How is one supposed to respond to that?

    Moderator James Huff

    (@macmanx)

    The weird thing about the sucuri result is that I have never been notified of any infections on my main site (which gets only a fraction of the visits that my globalindieauthor site gets) from either my host or Google.

    It’s not really your host’s job or Google’s job to notify you about malware, I just think your host is watching all of their WordPress installations more closely.

    And, as indicated, sucuri found nothing wrong with WP but Just Host did, while Just Host found malicious files on WP but nothing on my main site.

    Sucuri can only scan what it seems publicly. The file your host found would only be used in the Dashboard. Your host has access to all of your files, which is why they found it.

    Thread Starter Bad_Egg

    (@bad_egg)

    I see.

    I’ve been told that WP is having problems with malware-infected plugins. Is this why my host would be watching WP sites more closely?

    Moderator James Huff

    (@macmanx)

    Probably, there have been a few plugins recently which weren’t coded too securely and were then exploited.

    Thread Starter Bad_Egg

    (@bad_egg)

    Thanks for your help, James. I appreciate it.

    Moderator James Huff

    (@macmanx)

    You’re welcome!

    Thread Starter Bad_Egg

    (@bad_egg)

    Hi James,

    Went online this evening to execute said upload only to notice several files in my current WP directories that do not exist in the downloaded ZIP file. My suspicion is that these are related to the theme I am using. I suspect havoc will ensue if I delete these files. Then again, they could be malicious files; I wouldn’t know. Specifically, these are the files that are in my WP directory that do not exist in the ZIP file:

    root directory (/home4/mademer1/public_html/globalindieauthor):
    fantversion.php
    wp-atom.php
    wp-commentsrss2.php
    wp-feed.php
    wp-pass.php
    wp-rdf.php
    wp-register.php
    wp-rss.php
    wp-rss2.php
    wp-xmlrpc.php

    wp-admin:
    ajax-upload.php

    wp-admin/includes:
    install.php
    options-reading.php

    wp-admin/js:
    default_folder.php

    wp-admin/network:
    details_up.php

    wp-includes:
    class-wp-smtp-bar.php
    class.wp-dependencies.php
    class.wp-scripts.php
    class.wp-styles.php

    wp-includes/certificates:
    patfactory.php
    tdomf-upload-functions.php

    wp-includes/css:
    mod_search.php
    themes.php

    wp-includes/js/crop:
    default_ftp.php

    wp-includes/js/jquery/ui:
    jquery.ui.accordion.min.js
    jquery.ui.autocomplete.min.js
    jquery.ui.button.min.js
    jquery.ui.core.min.js
    jquery.ui.datepicker.min.js
    jquery.ui.dialog.min.js
    jquery.ui.draggable.min.js
    jquery.ui.droppable.min.js
    jquery.ui.effect-blind.min.js
    jquery.ui.effect-bounce.min.js
    jquery.ui.effect-clip.min.js
    jquery.ui.effect-drop.min.js
    jquery.ui.effect-explode.min.js
    jquery.ui.effect-fade.min.js
    jquery.ui.effect-fold.min.js
    jquery.ui.effect-highlight.min.js
    jquery.ui.effect-pulsate.min.js
    jquery.ui.effect-scale.min.js
    jquery.ui.effect-shake.min.js
    jquery.ui.effect-slide.min.js
    jquery.ui.effect-transfer.min.js
    jquery.ui.effect.min.js
    jquery.ui.menu.min.js
    jquery.ui.mouse.min.js
    jquery.ui.position.min.js
    jquery.ui.progressbar.min.js
    jquery.ui.resizable.min.js
    jquery.ui.selectable.min.js
    jquery.ui.slider.min.js
    jquery.ui.sortable.min.js
    jquery.ui.spinner.min.js
    jquery.ui.tabs.min.js
    jquery.ui.tooltip.min.js
    jquery.ui.widget.min.js

    wp-includes/js/tinymce/langs:
    wp-langs-en.phtml

    wp-includes/js/tinymce/plugins/colorpicker:
    strspn.php

    wp-includes/js/tinymce/plugins/compat3x/css:
    folder.php

    wp-includes/js/tinymce/plugins/fullscreen:
    pdf.php

    wp-includes/js/tinymce/plugins/tabfocus:
    zip.php

    wp-includes/js/tinymce/plugins/wpeditimage:
    defines.php

    wp-includes/js/tinymce/plugins/fullscreen:
    DB.php

    wp-includes/js/tinymce/plugins/wpgallery:
    BBCode.php

    wp-includes/js/tinymce/plugins/wplink:
    frontpage.php

    wp-includes/js/tinymce/plugins/wpview:
    move.php

    wp-includes/js/tinymce/skins/lightgray/fonts:
    tdomf-subscribe-to-comments-widget.php

    wp-includes/js/tinymce/skins/wordpress:
    directory.php

    wp-includes/js/tinymce/skins/wordpress/images:
    dashicon-no-alt.png

    wp-includes/SimplePie:
    index.php

    wp-includes/SimplePie/Content/Type:
    nav-menu.php

    wp-includes/SimplePie/HTTP:
    InputFilter.php

    wp-includes/SimplePie/XML/Declaration:
    details_img.php
    ms-users.php

    wp-includes/Text/Diff:
    admin.languages.html.php

    wp-includes/Text/Diff/Engine:
    xml_domit_xpath.php

    wp-includes/Text/Diff/Renderer:
    freesansbi.php

    wp-includes/theme-compat:
    string.php

    As you can see, there are dozens. Should I leave them in or remove them?

    Thanks.

    Moderator James Huff

    (@macmanx)

    Those should all be in the download. Did you get the download from https://wordpress.org/download/ ?

    It’s a .zip file, which you’ll expand, and it will then have all of those files.

    Thread Starter Bad_Egg

    (@bad_egg)

    I downloaded the archive (WordPress-4.1.zip) from the link you provided. When I compared the contents to what was in my WP folders on my website, the files I listed were on my website server but not in the zip file. I double-checked; if you unzip the archive and look in wp-includes/js/jquery/ui, for example, none of the jquery.ui files listed above are in there.

    Moderator James Huff

    (@macmanx)

    Hm, you’re right, sorry about that. Your theme shouldn’t be messing with core files anyway, so those were probably added by whatever black door was exploited.

    Go ahead and remove and replace the enter wp-includes and wp-admin directories, as well as the root-level core files, except wp-config.php and the wp-content directory.

    Thread Starter Bad_Egg

    (@bad_egg)

    Hi James,

    I did as directed and now my WP site does not work: http://www.mademers.com/globalindieauthor. At first glance it appears normal, but if one clicks on a blog post to read it, they get a 404 error. All my header links to my pages return 404 errors.

    I can log in and everything is still there: the posts, the comments, the pages, but the links have been broken somehow.

    Now what?

    Moderator James Huff

    (@macmanx)

    Try re-saving your permalink structure at Settings/Permalinks in your admin panel. If WordPress cannot automatically edit the .htaccess file, it will provide manual instructions after saving.

Viewing 15 replies - 1 through 15 (of 36 total)

The topic ‘Alleged malicious code’ is closed to new replies.