WordPress.org

Support

Support » How-To and Troubleshooting » [Resolved] HELP: Spam Links In all My Posts, how the hell?

[Resolved] HELP: Spam Links In all My Posts, how the hell?

  • Hi there, can some one please help out, we found out in our HTML Source code there are several spam links (viagra etc..) in the page.

    I Tried searching in the theme files, but its no where to be found.. I Tried changin the theme it self but unfortunately still cant be found.

    Will be glad if someone helps out..

    Thanks

Viewing 15 replies - 1 through 15 (of 16 total)
  • 2.0.11 is a real old version of WP. I know they have fixed lots of security holes from then to the current 2.3.3 version. Maybe an upgrade will help for the future…

    I’m sure you have to find all the posts and comments that hold these links and edit them out.

    It has nothing to do with your theme files in away way, as far as I know.

    whooami

    @whooami

    Member

    mega_spak,

    the spam links are inside the posts. Edit the posts to remove them, then upgrade.

    I am curious, you indicate you are using 2.0.11…

    Clarification on that would be most helpful, because I dont think anyone is aware of a problem with WP 2.0.11 and it is supposed to be ‘safe’ and stable.

    thanks to you all 4 your concern..

    actually my version is 2.2, i couldn’t get that to choose from the drop down menu, thats why i chose 2.0.11..

    I DONT THINK THEY ARE IN THE INDIVIDUAL POSTS, cause if im to post a new post right now, these links will still follow..

    and they are hidden in the posts, can be viewed in the HTML source code as below:
    ======================

    <u style=”display: none;”>
    [THE LINKS ARE HERE (10 links, all about viagra, pills etc..)]
    </u>

    ======================
    this is pretty a bad sign.. any help, please?

    whooami

    @whooami

    Member

    well the good news is that you are not using 2.0.11 — that wouldnt be a good sign.

    if you are seeing them in immediate posts, then check the theme files. Take a look at things via FTP – pay close attention to timestamps that indicate a file was edited when other files were not.

    Im happy to help you in that regard but obviously I would need access to the files.

    Sorry if my comment was incorrect…(open mouth insert foot and run from WP support forums forever)…..

    You are right.. this same problem was found in the pages a couple of hours ago, we fixed it i hope and found out the pages in our cp management which has not been updated in months ago was updated 6 days ago, it all contained hidden spam links and we cleared it all.

    Now with that of the posts i dont have any idea, i tried changing themes (to verify if it was a prob in the theme), but still to same..

    any idea?

    echoca – no problem..

    even though u warent all that wrong, hope u ve now understood my hlp needed and im still waiting 4 someone to help me out..

    whooami

    @whooami

    Member

    mega_spak,

    if you still see the links after changing the themes, then it follows that the content might be being added via a plugin… since theyre inside a post, maybe something like one of those social bookmarking plugins?

    You just need to go through all the files.

    Its nearly impossible, and beyond my reasoning, that the spam is in your database.. getting it from your databse to a freshly created post, would still require a change to your files.

    thanks whooami.. done.. it was a ad plugin..

    man this means we are not even safe with plugins?

    I seem to have a similar problem with (hidden) spam links showing up on my – can mega_spak (or anyone) say which plugin it is/was which is causing it?

    e.g.

    <font style='position: absolute;overflow: hidden;height: 0;width: 0'> NEWS: <a href="http://blog.thinkfree.com/wp-content/themes/almost-spring/comments.php?blog=credit&name=2004-card-college-credit-debt-mae-nellie-statistics-student">2004 card college credit debt mae nellie statistics student</a> Canada credit card application

    I have the same issue as Dan Lockton. I am using WP 2.5.1. Here is the offending code minus the link:

    <font style="position: absolute;overflow: hidden;height: 0;width: 0"><a href="http://REDACTED/">office furniture in Bulgaria</a></font>

    This is not the first time I’ve had a similar problem, and I’ve been keeping up to date, changing my password when I see the problem, etc. But it keeps happening.

    No recent registrations.

    Shared hosting, so I can’t provide MySQL logs.

    Ditto, on WordPress 2.6: hidden spam text inserted in a post, naturally fully visible in the rss feed. Since the rss feed is emailed out to people with blog updates, this is not good.

    I’ve since deleted all inactive plugins and updated those that remain. Is there any way of telling whether this really is caused by a plugin – and if so, *which one*?

    By disabling all and see if the problem goes away? When you reanable them one by one, you can tell which one it was.
    On the other hand, there can be more things, such as your theme. That is was a plugin in this thread, doesn’t mean it always is.
    Btw. when did you upgrade to 2.6 and from what version did you come?

    Hi guys,

    Today I discovered I have the same problem… Some damned hacker got to insert a lot of hidden code in my WP 2.6 blog… I tried disabling all my plugins but no luck: the code is still there, which prevents my feed from processing at Feedburner….

    Any more ideas?

    Thanks!

    Done,

    The problem solved after an update to WP 2.61. I guess some of the core WP files got hacked…

Viewing 15 replies - 1 through 15 (of 16 total)
  • The topic ‘[Resolved] HELP: Spam Links In all My Posts, how the hell?’ is closed to new replies.
Skip to toolbar