Hacked by a Black Hatter!

istart

Junior Member
Joined
Oct 10, 2011
Messages
116
Reaction score
26
Just found out that all of my WordPress sites on one server have been hacked!

I noticed that all of my sites took forever to load this evening and even crashed the browser a few times. I saw a bunch of requests to directagain.com, adnoble.com etc. Looked at the source and found a bunch of iframes loading up through ignorelist.com.

I searched through the code and eventually found that the main index.php file had been changed to include the encoded hack:

PHP:
base64_decode('ZWNobyA...lots of characters etc...

Looks like they were doing fake clicks or impressions on a bunch of ads. Glad I didn't buy any of those ads!

I only found out because ignorelist.com was down for a bit tonight. I wonder how long this has been killing my rankings!!!
 
That sucks... This is one of the main reasons I stopped doing niche websites. I implemented a lot of security on my niche sites and they still get hacked. I guess atleast your hacker was trying to make money, most just deface it.
 
How exactly do you know that they were doing fake clicks or impressions on a bunch of ads? Is that what base64_decode's are for ? Sorry for the dumb questions , I had a bad experience just like your's . Never fully understood base64 codes. Just know their a pain in the ass to get rid of.
 
I had a similar experience a couple weeks ago... hoping nothing is hit too hard and you can recover quickly :)
 
Decode the Base64 and find out what it does
Code:
http://www.opinionatedgeek.com/dotnet/tools/base64decode/
 
Well OP is right, this is very dark and shady BH method. It redirects a % of the traffic to others websites, it can also only redirect the traffic from Google and also give backlinks.

Your logins has been compromised to your hosting more likely or you are using a nulled theme / plugin.
 
No offense meant to black hatters here. I just said black hatter because the hack was being used for IM.

Which could be considered a super duper black hat IM method lol.
 
How exactly do you know that they were doing fake clicks or impressions on a bunch of ads? Is that what base64_decode's are for ? Sorry for the dumb questions , I had a bad experience just like your's . Never fully understood base64 codes. Just know their a pain in the ass to get rid of.

I decoded their code and ours full of I frames displaying ads and sites. I couldn't get to many details on thus as their server was failing and I could only bring up the sites once. The links are all cloaked somehow too
 
No offense meant to black hatters here. I just said black hatter because the hack was being used for IM.

Which could be considered a super duper black hat IM method lol.

Is it just me or does the girl in your avatar look like she has a beard??? rofl
 
Is it just me or does the girl in your avatar look like she has a beard??? rofl

She's got a beard alright lol. That's Richard d from aphex twin. Just look up windowlicker on YouTube if you want to watch the best video of all time. :)
Trust me, you'll love it lol
 
Back
Top