Warning to wordpress webmasters - pharma hack

Rudyzplace

Regular Member
Joined
Aug 24, 2009
Messages
273
Reaction score
120
Hi,

Today I found that 2 of my wordpress blogs were infected with something which is called pharma hack - read more about it here http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html

apparently it is visible only to crawlers and injects links into your posts and pages.
I've been leaking for an unknown time now, updated wordpress to v3.9 in order to clear the hack.

Not sure if it will be enough, I've tried looking for the files which the article I linked refers to but didnt find them after the WordPress update.

Let me know if you encountered this hack before and you recommend more measures to be taken.

Thanks
 
Wordfence is free, and pretty good. I also use sucuri on some sites. Best way to avoid is to never use free plugins/themes, I have found even reputable members here sharing infected files -- not saying they knew about it, but a lot of nulled/shared files are infected by different hacks.
 
Free WP plugins are a security hazard. WP itself is pretty secure, but folks indiscriminately install 200 plugins per setup and so many plugins have security flaws.
 
Few days ago my website was also hacked. It started redirecting to a weird url and I was only using All in 1 SEO pack, statcounter and tinymce advanced plugin.
 
I used to have this hack on one of my site, too.

- I used Xenu to check external links & search through my DB for those terms and deleted them.

- Updating WordPress was not enough at least for me. Therefore, I installed new fresh WordPress.

- I accesses my WordPress files through ftp and sorted by newest to see if there were any suspicious files in all of my site's folders.

- I also replaced my old plugins to newer ones. In addition, I deleted all of the unused themes and plugins for my site completely.

- WordFence & Sucuri scan was not a big help for me at that time because it showed green while my site was infected. Yet, WordPress Exploit Scanner was helpful at that time.

- The infected also stayed inside 404.php as well as my htaccess file & others.

Hope it help!
 
Thanks for making everyone aware OP. How did you figure out you were infected?
 
Thanks for sharing. Have bunch of worldpress blogs to check!
 
Thanks for making everyone aware OP. How did you figure out you were infected?

I'm using serpbook, they have this little magnifying glass next to the keywords which shows you search results from their USA proxy crawler (which can see these spammy links as normal)
I looked into one of my sites just to see how it looks and saw tons of pharma links.

Pure luck
 
Last edited:
thanks for warning us, I always update my wordpress just in case.
 
This happened to me with lots of my old outdated blogs that I don't use anymore a long time ago. I ended up uploading a simple backdoor finder script to my server and using it to locate all the backdoor files and deleted them. Then I got rid of 100 or so old wordpress sites that I didn't use anymore. The last thing to do was to make sure the ones in use are updated regularly and have the Bulletproof Security plugin installed. This plugin and regular backups have never failed me since!
 
hey thanks for the tip, ive been slacking on the update on my sites, I'm going to go do that now.
 
Back
Top