Hello everyone, I just put an end to one of the worst nightmares I've ever had in IM. I got my site's security compromised and got some bad code inserted in my website which costed me a lot of money and time.
I want to warn everybody using these plugins: WP Super Cache, W3 Total Cache, Digi...
THANK YOU EVERYONE WHO HELPED!!
Hey guys, the problem is finally cleared! I am now in the process of giving thanks to everybody who offered to help and who shared their experience!
It was a long 3 day battle that costed me more that I could have imagined, but its over. And we are victorious...
lagger: Thanks for your suggestions! I contacted bluehost to see if they would be so kind to search out that shit from my website. I am checking the header and sidebar, but can't find anything particularly
suicious like
eval($_POST['attacker_key']);
or
J3byJXZ"(edoced_46esab(laveAny encoded...
teamrecon: Thanks, I thought so too! So, delete it from my source code is easier said than done. I have no idea how I can edit the whole source. I am trying to find it in a separate .js file somewhere else, but if you can tell me where to find it and delete it, it would be awesome!
Some guys...
Hey Guys, I read everything you wrote, and I went to my site's source code and I found this: Can anybody Code-Savvy tell me two things - is this whats been killing me (I know some js but not that much) and where do I find it. I am currently scanning my scripts using the Chrome developer tools...
Skywalker:
Thanks for sharing your story. Can you recommend me a freelancer service like that please? Also, what hosting do you use for maximum protection, and do you use any security plugins?
I am really devastated by this whole happening, its cost me a lot of money, and it really is a shame...
I am now searching all my database tables with the keywords found here: http://stackoverflow.com/questions/465997/my-site-was-hacked-htaccess-file-compromised-what-should-it-look-like
So far haven't found anything, how do I find the bad code?
Ok guys, here is the HTACCESS code right here. Do you see anything strange?
# Use PHP5 Single php.ini as default
AddHandler application/x-httpd-php5s .php
# BEGIN W3TC Browser Cache
<IfModule mod_deflate.c>
<IfModule mod_setenvif.c>
BrowserMatch ^Mozilla/4 gzip-only-text/html...
So I can say for sure that Bluehost didn't give a shit about this problem, nor did they know what to do. I have been told they are crap, but now I know first hand. Which do you guys think is the safest *not cheapes* hosting? Maybe the one thepiratebay are on lol
ADHD-Dude & Fwiffo:
So I opened my Htaccess file (which was supposed to be protected by Bulletproff security) and I found some shady redirects and overwrites mixed in with my W3 Total Cache plugin's commands. Since I am not using the plugin anymore, I deleted everything.
Now I am waiting in...
Backberry: I flushed my DNS, still the same meta description. Thanks for your ideas
netpal: Which files exactly?
badman2: I am running the newest version of wordpress.. Do you say I should restore? Is there another solution?
Well guys I tried asking around on other forums too. All I get are some general assumptions.
Can anyone advise how I should proceed to handle this? What would you do if it happened to you?
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.