Forum Replies Created

Viewing 10 replies - 1 through 10 (of 10 total)
  • Thread Starter mackhardcore

    (@mackhardcore)

    I gotcha! 🙂 Thank you!! :))

    Thread Starter mackhardcore

    (@mackhardcore)

    No miracles?

    Thread Starter mackhardcore

    (@mackhardcore)

    Ok, this is where I curl up into the fetal position and start to cry. Tonight, over 30 of my posts have “hidden” injection spam for every pill on the planet, and I have done the following:

    1. Printed off a list of all my users, and compared them to WP – nothing stood out, everyone matched up, no outsiders.

    2. The log file plugin gave me some errors, so that didn’t work – although it’s mainly because I am probably doing something majorly wrong.

    3. Most of my spam comes from particular (seemingly static) IP addresses…. namely this one:

    OrgName: NetNation Communications Inc
    OrgID: NNC
    Address: Bentall Tower 5, Suite 200
    Address: 550 Burrard Street
    City: Vancouver
    StateProv: BC
    PostalCode: V6C-2B5
    Country: CA

    64.40.96.0 – 64.40.127.255

    I have combed my template, and upgraded to 2.5.1, prayed to every God on the planet, sprinkled salt, holy water, and it’s like some magic Gremlin is getting in….

    The ads are changing, mainly just lines of text with pill names that are links – BUT – they are hidden, you can’t see them in the post, it’s in the HTML, and in the post when I view it from the Admin side.

    So, I see in Audit Trail that the post has been modified (or in my case 30 posts have been modified) – I click the link, I see my post, and down below is a bunch of hyperlinks that would make any pill popper happy.

    So then I go to the HTML viewer, delete the code, resave and it’s gone – until they re-inject it.

    The hyperlinks are NOT visible on my blog to the public, which is weird to me. I think they have hacked in to shove keywords into my blog, that would – if I had enabled – “sway” my google ads or something – I mean, I have no idea why?

    Ok, so I am at a loss. I have no idea what is going on, but I would like to remedy this – and I need help.

    Anyone have a miracle?

    Thread Starter mackhardcore

    (@mackhardcore)

    I am doing that now. I do have a question though, I also use a plug-in called “audit trail” and I am very surprised that it does not show the user name of the person by the post edits. It does show the posts that are edited, etc – and their IP, but it does not show the user name.

    Anyway I printed a list of users from my phpMyAdmin, and I am going to compare. It will take some time.

    I would also like to thank you Otto, and Whooami for your continued help and advice – it means the world to me! 🙂

    Thread Starter mackhardcore

    (@mackhardcore)

    I just noticed that someone deleted my link to the text page with the code the hacker person or thing left on my blog to “edit my posts” with ads about the “little blue pill” – this has not stopped.

    Did anyone see the code before it was removed (sorry if I violated something, I could not post it on here for some reason) – and did anyone have any suggestions on what it all meant?

    Thanks for your help in advance.

    Thread Starter mackhardcore

    (@mackhardcore)

    Thank you, did anyone look at the HTML code to see if it made any sense on where it was coming from? There are a lot of “forums” mentioned, and I don’t understand why.

    Thanks in advance for everyone’s help on this, I truly appreciate it! 🙂

    Thread Starter mackhardcore

    (@mackhardcore)

    I just found this in the source code of one of my hacked posts:

    http://streetblast.com/hackercode.htm

    What does it mean?

    Thread Starter mackhardcore

    (@mackhardcore)

    I just upgraded to 2.5 yesterday, and I just read about the i-Frames injection as well on the post link you gave me. I am going to go exploring and see what I can find…..

    Thread Starter mackhardcore

    (@mackhardcore)

    Thank you Whooami! I appreciate the logging plug-in, is there a collective group that is reviewing the log files in order to find the root cause? If so, I want to join! 🙂

    I am, but it is happening in my posts as “edits” with ads for the “little blue pill” which makes me want to all out sue Phizer for all this frustration.

    I have no idea how they are doing it…. (see my post for help on this issue with more details on this forum)

    – Mack

Viewing 10 replies - 1 through 10 (of 10 total)