wordpress hacked - pharma links in all posts

hi

a customer has his wordpress blog hacked and small links to pharma sites in all posts.

I have found a lot of articles by searching for "wordpress pharma hack" - but I dont find any hacker php files (backdoors) they mention in the wordpress folders, also not the database entries that these articles mention (in wp_otptions table). So no trace at all.... except all these links in every post.

There are no additional plugins installed, so they must have gotten through the wordpress core.

Any input on what hack that could be (and how to fix it)

Thanks
netsltAsked:
Who is Participating?
 
Jason C. LevineNo oneCommented:
Hi netsit,

Most likely the server itself was hacked and then a script is run to modify the WordPress files and insert the content.  

You need to contact the hosting provider and get thm to fix it.  
0
 
Lukasz ChmielewskiCommented:
Maybe too weak password ? Chenge it now if you haven't done it yet. Make an upgrade.
Does the code appear only AND ONLY in posts ?
0
 
Lukasz ChmielewskiCommented:
0
On-Demand: Securing Your Wi-Fi for Summer Travel

Traveling this summer?Check out our on-demand webinar to learn about the importance of Wi-Fi security and 3 easy measures you can start taking immediately to protect your private data while using public Wi-Fi. Follow us today to learn more!

 
gwkgCommented:
Which version of Wordpress?
0
 
netsltAuthor Commented:
it was 3.0
0
 
gwkgCommented:
Here is a scanning plugin: http://wordpress.org/extend/plugins/exploit-scanner/

Here is help from the Codex: http://codex.wordpress.org/FAQ_My_site_was_hacked

Here is a guide to securing Wordpress: http://codex.wordpress.org/Hardening_WordPress

0
 
gwkgCommented:
3.0 or 3.0.5?  To stop it from happening in the future might be as simple as keeping Wordpress updated.

Check the database and see if the links are actually saved with the post, or if they are being added from somewhere else.  If they are mixed into the post via the database and you don't have a backup to restore to, you will have to remove them with search and replace tool.
0
 
netsltAuthor Commented:
I think it must have been a hole on the server because it turned out other wordpress installations on the server where also affected.

Also I did not find any known exploits for the Wordpress Version I used.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.