Solved

wordpress hacked - pharma links in all posts

Posted on 2011-03-18
8
736 Views
Last Modified: 2012-05-11
hi

a customer has his wordpress blog hacked and small links to pharma sites in all posts.

I have found a lot of articles by searching for "wordpress pharma hack" - but I dont find any hacker php files (backdoors) they mention in the wordpress folders, also not the database entries that these articles mention (in wp_otptions table). So no trace at all.... except all these links in every post.

There are no additional plugins installed, so they must have gotten through the wordpress core.

Any input on what hack that could be (and how to fix it)

Thanks
0
Comment
Question by:netslt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1
8 Comments
 
LVL 70

Accepted Solution

by:
Jason C. Levine earned 500 total points
ID: 35169816
Hi netsit,

Most likely the server itself was hacked and then a script is run to modify the WordPress files and insert the content.  

You need to contact the hosting provider and get thm to fix it.  
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 35172555
Maybe too weak password ? Chenge it now if you haven't done it yet. Make an upgrade.
Does the code appear only AND ONLY in posts ?
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 35172558
0
The Orion Papers

Are you interested in becoming an AWS Certified Solutions Architect?

Discover a new interactive way of training for the exam.

 
LVL 31

Expert Comment

by:gwkg
ID: 35173873
Which version of Wordpress?
0
 

Author Comment

by:netslt
ID: 35174902
it was 3.0
0
 
LVL 31

Expert Comment

by:gwkg
ID: 35176842
Here is a scanning plugin: http://wordpress.org/extend/plugins/exploit-scanner/

Here is help from the Codex: http://codex.wordpress.org/FAQ_My_site_was_hacked

Here is a guide to securing Wordpress: http://codex.wordpress.org/Hardening_WordPress

0
 
LVL 31

Expert Comment

by:gwkg
ID: 35176874
3.0 or 3.0.5?  To stop it from happening in the future might be as simple as keeping Wordpress updated.

Check the database and see if the links are actually saved with the post, or if they are being added from somewhere else.  If they are mixed into the post via the database and you don't have a backup to restore to, you will have to remove them with search and replace tool.
0
 

Author Closing Comment

by:netslt
ID: 35249981
I think it must have been a hole on the server because it turned out other wordpress installations on the server where also affected.

Also I did not find any known exploits for the Wordpress Version I used.
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you think that WordPress is just for blogs?  Think again!  WordPress is really a fantastic all around platform that you can use to develop websites on.  Integrated into its basic functionality is the ability to create pages using your choice of a…
WordPress is constantly evolving, and with each evolution appears to get better and better.  One of the big drawbacks prior to version 3 was that there was no way to be able to set up a custom menu from the backend. The Old Way Adding menus is…
The purpose of this video is to demonstrate how to manually back up a WordPress Database. This will be demonstrated using a Windows 8 PC. The Host used will be IPage.com Log into your Hosting account. IPage will be used for demonstration : Locat…
The purpose of this video is to demonstrate how to set up basic WordPress SEO. This will be demonstrated using a Windows 8 PC. The plugin used will be WordPress SEO by Yoast. Go to your WordPress login page. This will look like the following: myw…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question