Forum Replies Created

Viewing 5 replies - 1 through 5 (of 5 total)
  • Thread Starter danimal423

    (@danimal423)

    I found quite a few php files that had been added to the directory that did not belong there. They all had similar “fishy” code. I’m assuming these were the hacker’s “backdoors”. I can’t tell for sure if I have found all malicious code, but for now I’ll mark this as resolved.

    Thread Starter danimal423

    (@danimal423)

    My apologies.. Just trying to include as much information as possible to get this resolved.

    Spam code can be found be found here: http://pastebin.com/BL79Ce5Y

    Thread Starter danimal423

    (@danimal423)

    Now onto trying to find and remove the backdoor codes…

    I’ve identified a few files that look fishy, but I am not an experienced developer. Files that have the fishy code include:
    wp-admin/includes/class-wp-media.php
    wp-content/plugins/akismet/api.php
    wp-admin/js/utils.js
    wp-content/plugins/jetpack/api/php

    These files were not updated when WP was updated, do not include any comments that I usually see in standard WP files and well, some of the variables say “door”.

    Sample code (sorry in advance if not appropriate to post):

    [Code moderated. Please do not post hack code blocks in the forums. Please use the pastebin]

    Thread Starter danimal423

    (@danimal423)

    esmi,
    Thank you so much for these resources. The “How to find a backdoor” article is a great help.

    JarretC,
    Thank you so much for this specific example of what the malicious code might look like and where it could be found. I found something very similar in my functions.php file. Once removed, the spam content disappeared.

    I’m having the same issue! Is there a plan for this to be fixed / updated? If so, any general timeline we can look forward to? I would hate to have to switch to a different theme.

Viewing 5 replies - 1 through 5 (of 5 total)