Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Our site is infected with Exploit Blackhole - What should we do?

Posted on 2011-03-04
9
Medium Priority
?
737 Views
Last Modified: 2012-05-11
See screenshot. This is coming from OUR website which is 100% legitimate and wordpress-based. What would be the first step to fixing this?

Screenshot of Exploit Blackhole
0
Comment
Question by:freshjuice
9 Comments
 
LVL 70

Accepted Solution

by:
Jason C. Levine earned 1200 total points
ID: 35037912
Hi fresh juice,

Get your hosting provider on the phone immediately.  They should have the tools and expertise to deal with this.  Unless you know server security backwards and forwards, you are out of your depth.

Generally this happens because the server has been compromised and not because of WordPress, assuming you are running a relatively recent version.
0
 
LVL 16

Assisted Solution

by:sjklein42
sjklein42 earned 400 total points
ID: 35037932
Your site IS infected!

It looks like the infection is at the Web Server level not in your own scripts.

Who is your ISP?  Where is your site hosted?  Do you host it yourself?  The server is infected.

Are there other sites on the same server?  Can you check if they are infected, too?
0
 
LVL 80

Expert Comment

by:arnold
ID: 35038005
The issue is with one of your advertisers who has some of their stuff on IP 195.80.151.171.
If you can determine which advertiser of yours has this IP, you should notify them and until they fix their site suspend them from the ad rotation.
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 
LVL 80

Expert Comment

by:arnold
ID: 35038026
One other thing, currently your site is down with a PHP error.
The notice can be seen in a cached copy of the site.
0
 

Author Comment

by:freshjuice
ID: 35038041
1and1

All wordpress sites appear to be broken.

I'm on hold with 1and1 abuse support right now. :-(
0
 

Author Comment

by:freshjuice
ID: 35038052
@arnold - we have no advertisers. Everything we promote is self-contained. We do have an ad-rotation plugin that we run, however...
0
 

Author Comment

by:freshjuice
ID: 35038183
Okay, so 1and1 told us that one of our web developers had a virus on the machine that allowed someone from the Czech republic to steal our webmasters pass and login through the FTP front door to upload Perl scripts.
0
 
LVL 80

Assisted Solution

by:arnold
arnold earned 400 total points
ID: 35038272
The ad-rotation is it one of your own or do you generate references to other people?
Currently, your site has a PHP error.
index.php line 1
referencing wp-includes/pluggable.php line 890

if you have access to the server, while it is not necessarily dis-positive, you can search your files for modification after a known last modify date.

I.e. you have not made changes to the site since December 2010. But now you have files within the web root that were modified 10 days ago.
The other issue as others and I pointed out to have the server scanned 1and1 should be contacted to see whether the issue is within one of the systems that provides services for your domain.
0
 

Author Comment

by:freshjuice
ID: 35038390
Hi Arnold. Don't know if you missed my reply, it was a hacked password used for a front-door attack to our FTP.

I'll divvy some points for everyone's help.
0

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A while back, I ran into a situation where I was trying to use the calculated columns feature in SharePoint 2013 to do some simple math using values in two lists. Between certain data types not being accessible, and also with trying to make a one to…
The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask.
The purpose of this video is to demonstrate how to automatically show related posts at the bottom of a blog post in WordPress. This will be demonstrated using a Windows 8 PC. Plugin “Yet Another Related Posts Plugin” will be used. Go to your…
The purpose of this video is to demonstrate how to manually back up a WordPress Database. This will be demonstrated using a Windows 8 PC. The Host used will be IPage.com Log into your Hosting account. IPage will be used for demonstration : Locat…

972 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question