Solved

wordpress hacked - pharma links in all posts

Posted on 2011-03-18
8
717 Views
Last Modified: 2012-05-11
hi

a customer has his wordpress blog hacked and small links to pharma sites in all posts.

I have found a lot of articles by searching for "wordpress pharma hack" - but I dont find any hacker php files (backdoors) they mention in the wordpress folders, also not the database entries that these articles mention (in wp_otptions table). So no trace at all.... except all these links in every post.

There are no additional plugins installed, so they must have gotten through the wordpress core.

Any input on what hack that could be (and how to fix it)

Thanks
0
Comment
Question by:netslt
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 70

Accepted Solution

by:
Jason C. Levine earned 500 total points
ID: 35169816
Hi netsit,

Most likely the server itself was hacked and then a script is run to modify the WordPress files and insert the content.  

You need to contact the hosting provider and get thm to fix it.  
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 35172555
Maybe too weak password ? Chenge it now if you haven't done it yet. Make an upgrade.
Does the code appear only AND ONLY in posts ?
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 35172558
0
 
LVL 31

Expert Comment

by:gwkg
ID: 35173873
Which version of Wordpress?
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 

Author Comment

by:netslt
ID: 35174902
it was 3.0
0
 
LVL 31

Expert Comment

by:gwkg
ID: 35176842
Here is a scanning plugin: http://wordpress.org/extend/plugins/exploit-scanner/

Here is help from the Codex: http://codex.wordpress.org/FAQ_My_site_was_hacked

Here is a guide to securing Wordpress: http://codex.wordpress.org/Hardening_WordPress

0
 
LVL 31

Expert Comment

by:gwkg
ID: 35176874
3.0 or 3.0.5?  To stop it from happening in the future might be as simple as keeping Wordpress updated.

Check the database and see if the links are actually saved with the post, or if they are being added from somewhere else.  If they are mixed into the post via the database and you don't have a backup to restore to, you will have to remove them with search and replace tool.
0
 

Author Closing Comment

by:netslt
ID: 35249981
I think it must have been a hole on the server because it turned out other wordpress installations on the server where also affected.

Also I did not find any known exploits for the Wordpress Version I used.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

WordPress is constantly evolving, and with each evolution appears to get better and better.  One of the big drawbacks prior to version 3 was that there was no way to be able to set up a custom menu from the backend. The Old Way Adding menus is…
Utilizing an array to gracefully append to a list of EmailAddresses
The purpose of this video is to demonstrate how to make a WordPress Site faster and smaller in size by cleaning up the database. This will be demonstrated using a Windows 8 PC. Plugin WP Optimize will be used. Go to your WordPress login page. T…
The purpose of this video is to demonstrate how to reset a WordPress password if you are locked out and cannot reset the password. A typical use would be if you cannot access the email to which WordPress would send the password recovery email to…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now