WTF My Website Got Hacked?

wannaknow

Registered Member
Joined
Sep 2, 2009
Messages
58
Reaction score
18
hacked.png
Just two Days back i installed wordpress for my new blog, Today i checked my site it says "Hacked by Tetova Hackers Team"
Could someone Tell me How did they do it?
 
Just check hack forums . net , there are 100 of guys doing it there just for fun.
 
they found and exploited a vulnerability in wordpress although it could have also been a plugin or something that you used.
 
Just check hack forums . net , there are 100 of guys doing it there just for fun.
I checked hack forums .net these guys are having there own forum t-h-teamdot7forumdotnet search google for techtova
they found and exploited a vulnerability in wordpress although it could have also been a plugin or something that you used.
I didn't install any plugins it was a standard install with default plugins but i did choose one theme(don't remember the theme name).
 
Also this can be a host problem, so they hack whole host and add index file to all domains on that host, don't matter if your site is 100% secure.
Btw, this skiddies are from my country. lol poor kids.

http://whois.domaintools.com/YOURSITE.COM please tell me how many sites are hosted on that host, check Reverse IP part.
 
Last edited:
Also this can be a host problem, so they hack whole host and add index file to all domains on that host, don't matter if your site is 100% secure.
Btw, this skiddies are from my country. lol poor kids.

http://whois.domaintools.com/YOURSITE.COM please tell me how many sites are hosted on that host, check Reverse IP part.
816 sites are hosted, i did Reverse IP and checked like 3 sites and they are working fine.
 
So you don't happen to remember the name of something you installed 2 days ago or have the files on your pc?

I believe it's the timthumb file that got the exploit, if there is a such one.
 
They use google dorks and stuff like that to find these sites. They don't really do it for fun as much as for reputation. You probably weren't singled out, and chances are they just got through someone on the shared hosting plan.
 
So you don't happen to remember the name of something you installed 2 days ago or have the files on your pc?

I believe it's the timthumb file that got the exploit, if there is a such one.
I don't know what is this tinthumb file but i think since i have like 4 more sites on the same hosting plan and i didn't do any installations in other domains just changed the Nameserver address.
They use google dorks and stuff like that to find these sites. They don't really do it for fun as much as for reputation. You probably weren't singled out, and chances are they just got through someone on the shared hosting plan.

probably you are right.
 
Here's the index page

Some more Info
<html> <title>| HACKED BY Tetova Hackers Team |</title> <body bgcolor="00000"> <br> <center><img src="http://img27.imageshack.us/img27/2640/logoavj.jpg" width="470px" /> <h4><font color="#d81126">Hacked By DJ-DUKLI ~ B4T1 ~ FUKKI ~ ACCDE ~ GHOST OF TUN</h4> <br><font color="#d81126">Your System is Owned ! <SCRIPT SRC=../wwwDOTotoelektronikDOTnet/yazciz/ciz.js></SCRIPT> <div> <script language="javascript" src="hxxp://pichakdotnet/blogcod/cod-music/player/?type=2&files=hxxp://skydailymusicdotcom/risi/-%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20HITET%20DHE%20ALBUMET%20E%20FUNDIT%20[PREMIER%20NE%20RISI-KS%202012]/-%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20Unikkatil%20ft%20Klepto%20-%20Kuq%20e%20Zi%20[Premier%202012]/Unikkatil%20ft%20Klepto%20-%20Kuq%20e%20Zi%20(RISI-KS%202012).mp3&start=1&random=0&replay=0&vol=100"></script><div style="display:none"><h1><a href="http://pichak.net"></a></h1><h1><a href="hxxp://pichakdotnet/blogcod/cod-music"></a></h1></div><script language="JavaScript" type="text/javascript" src= "hxxp://wwwdotpichakdotnet/p/js/web/46617182396019726201.js"></script> </div></div></body></html>
 
Very sad. How someone can hack the site? Wordpress are not safe now? I am really shocked. Anyone have the idea how to avoid hacking on the website?
 
replaced the index.php file of your theme again... it will be fine... once it happened to me... i did this...

Give a try
 
so much lack in wordpress last time i reached a articles world simplest site which can hack easily
 
I have been hacked a few times. Just call your host and ask them to reset it to when the last back up was. It sucks ass.
 
My guess for the vulnerability would be an old timthumb.php file in one of your downloaded themes. I'd also follow bigballin's advice. Hostgator removed all the malware from my hacked domains for free.
 
Just outta curiosity, what content did you have on the wordpress site?
 
LOL i can hack probably between 1 to 10% of all the wordpress sites population. Hehe. But of course i wont as i earn my money legal way.

Very sad. How someone can hack the site? Wordpress are not safe now? I am really shocked. Anyone have the idea how to avoid hacking on the website?

Especially this comment is lol.
 
lol it got again hacked by some pak army i did have a little conversation with my hosting provider after that they fix it up and asked me to regularly change FTP passwords and to stay away from shady looking wordpress plugins.
 
Back
Top