SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    I guess I'm not busy enough. Someone hacked my site.
Go
New
Find
Notify
Tools
Reply
  
I guess I'm not busy enough. Someone hacked my site. Login/Join 
W07VH5
Picture of mark123
posted
I've used wordpress blogs as content management for a long, long time. I guess I do get a lot of traffic and still get some hits on old posts even though I don't post much any more.

Someone was able to brute force a password and create an administrator user. This allowed them to install plugins that don't show on the plugin list and put obfuscated malware scripts on each page. It was causing the links to be redirected.

I guess I just didn't have enough to do today.

I seem to have cleaned the garbage and I've password protected the admin directory, changed all passwords, everywhere.

There was really no gain to the hack that I could imagine. It's just malicious for being malicious. Jerks!

If you run a wordpress blog, check for injected scripts in the markup that shouldn't be there.
 
Posts: 45627 | Location: Pennsyltucky | Registered: December 05, 2001Reply With QuoteReport This Post
Drill Here, Drill Now
Picture of tatortodd
posted Hide Post
That sucks.

On a positive note, if you survive the snowpocalypse your website will be in great shape for spring.

Speaking of snowpocalypse. Were schools shutdown today. You mentioned it was malicious just for being malicious and it might be bored teens.



Ego is the anesthesia that deadens the pain of stupidity

DISCLAIMER: These are the author's own personal views and do not represent the views of the author's employer.
 
Posts: 23807 | Location: Northern Suburbs of Houston | Registered: November 14, 2005Reply With QuoteReport This Post
Member
posted Hide Post
Wordpress has long been notorious as full of holes. They found yours.

The point wasn’t to gain something from you directly, other than free malware hosting. Just another drone in the army.


--
I always prefer reality when I can figure out what it is.

JALLEN 10/18/18
https://sigforum.com/eve/forum...610094844#7610094844
 
Posts: 2410 | Location: Roswell, GA | Registered: March 10, 2009Reply With QuoteReport This Post
Nosce te ipsum
Picture of Woodman
posted Hide Post
Maybe its time I went to two-step authentication ...
 
Posts: 8759 | Registered: March 24, 2004Reply With QuoteReport This Post
Member!
posted Hide Post
Keylogger on Thousands of Infected WordPress Sites

https://blog.sucuri.net/2017/1...wordpress-sites.html
 
Posts: 4369 | Location: Boise, ID USA | Registered: February 14, 2003Reply With QuoteReport This Post
His diet consists of black
coffee, and sarcasm.
Picture of egregore
posted Hide Post
quote:
Someone was able to brute force a password and create an administrator user. This allowed them to install plugins that don't show on the plugin list and put obfuscated malware scripts on each page. It was causing the links to be redirected.

Confused

I'll take your word for it.
 
Posts: 28891 | Location: Johnson City, TN | Registered: April 28, 2012Reply With QuoteReport This Post
Info Guru
Picture of BamaJeepster
posted Hide Post
I had the same thing happen - after getting it back up and running I installed the free version of https://www.wordfence.com/ and haven't had any other issues since.



“Facts are stubborn things; and whatever may be our wishes, our inclinations, or the dictates of our passions, they cannot alter the state of facts and evidence.”
- John Adams
 
Posts: 29408 | Location: In the red hinterlands of Deep Blue VA | Registered: June 29, 2001Reply With QuoteReport This Post
Nosce te ipsum
Picture of Woodman
posted Hide Post
Is this associated with wordpress.org, self-hosted sites?

Or wordpress.com-hosted sites? The .com sites do not have great ability to manipulate code. Some, but not a lot.
 
Posts: 8759 | Registered: March 24, 2004Reply With QuoteReport This Post
W07VH5
Picture of mark123
posted Hide Post
quote:
Originally posted by BamaJeepster:
I had the same thing happen - after getting it back up and running I installed the free version of https://www.wordfence.com/ and haven't had any other issues since.
I came across that in the early morning and installed it on two sites so far. Thanks.

Oh, I also password protected the wp-admin directories.
 
Posts: 45627 | Location: Pennsyltucky | Registered: December 05, 2001Reply With QuoteReport This Post
blame canada
Picture of AKSuperDually
posted Hide Post
UGh. Been there. Still have 3 sites down that I don't have time to fix.

We're considering moving away from WP...and doing something simpler.

I've used securi, but honestly...its just a PITA, and costs money. The hackers still get through it. Our veterans outreach site was under constant attack, and we finally gave up and went back to facebook with it.


~~~~~~~~~~~~~~~~~~~~~~~~~
"The trouble with our Liberal friends...is not that they're ignorant, it's just that they know so much that isn't so." Ronald Reagan, 1964
~~~~~~~~~~~~~~~~~~~~~~~~~~
"Arguing with some people is like playing chess with a pigeon. It doesn't matter how good I am at chess, the pigeon will just take a shit on the board, strut around knocking over all the pieces and act like it won.. and in some cases it will insult you at the same time." DevlDogs55, 2014 Big Grin
~~~~~~~~~~~~~~~~~~~~~~~~~~

www.rikrlandvs.com
 
Posts: 13996 | Location: On the mouth of the great Kenai River | Registered: June 24, 2007Reply With QuoteReport This Post
Member
Picture of Sig M11
posted Hide Post
quote:
Originally posted by Woodman:
Maybe its time I went to two-step authentication ...


Yup!

https://en.support.wordpress.c...step-authentication/

You should have 2FA on ALL of your accounts.
 
Posts: 1407 | Location: Wilmington, Delaware | Registered: February 05, 2004Reply With QuoteReport This Post
  Powered by Social Strata  
 

SIGforum.com    Main Page  Hop To Forum Categories  The Lounge    I guess I'm not busy enough. Someone hacked my site.

© SIGforum 2024