Wordpress blog Hacked!!!

speedy5044

Banned - Inappropriate behavior
Joined
Jul 29, 2008
Messages
944
Reaction score
1,673
Hi
I keep finding this iframe in my index page (not in the theme , but in the wordpress directory) i tried to remove the code but it keep getting back , i even searched for the link in the DB but without any luck , any idea how to fix that?
Thanks
 
Look inside your css files. Also, try to find how is your account being accessed (shell scripts, etc.).
 
Look inside your css files. Also, try to find how is your account being accessed (shell scripts, etc.).

Thanks , but can you please explain more :p im not good in programming , i have loked in the css files and everything is normal .
 
One of your plugins is not secure. I'd deactivate and remove them all and force wordpress update (even if there is no update so you get all the files replaced automatically).

This way you close the door for the malicious code (hopefully) then you get time to think which plugin is not reliable.
 
Last edited:
One of your plugins is not secure. I'd deactivate and remove them all and force wordpress update (even if there is no update so you get all the files replaced automatically).

This was you close the way for the malicious code (hopefully) then you get time to think which plugin is not reliable.

Thank you so much , it worked like a charm :D we have to be careful when installing some plugins :eek:
 
Last edited:
I'm glad to know you could solve your problem with Scripteen's help (awesome member, btw). If possible, could you let bhw members know what the malware ridden plugin was?. It may help more than one here.
 
I'm glad to know you could solve your problem with Scripteen's help (awesome member, btw). If possible, could you let bhw members know what the malware ridden plugin was?. It may help more than one here.

The plugin itself may not include malicious code but it is the reason why the hacker can insert the malicious code in the database or add it to template files.

Always make sure you download a plugin that has been there for few months. the more popular it becomes, the more it becomes updated and secure.
 
TBH, I usually see this type of iframe injection as a result of a keylogger on your local system hoovering up your ftp passwords. There is malware just for this purpose.
 
Back
Top