Author Topic: Help! Site being Hacked!  (Read 2205 times)

0 Members and 1 Guest are viewing this topic.

Offline NeoFur

  • Hero Member
  • Species: Wolf
  • Such is Life.
  • *****
  • Male
  • Posts: 1088
    • Furaffinity Page
Help! Site being Hacked!
« on: May 14, 2009, 02:13:42 pm »
I need my ftp user name and password changed.

I've changed my passwords, changed themes, put in WP firewall and it happen again.
Some hacker is adding this code to the end of my index.php files >:(
It's an IFrame Hack, lucky my anti virus found it.

If possible I need the file permissions changed to.



Offline Kobuk

  • The "Malamute Dewd"
  • Hero Member
  • Species: Anthro Alaskan Malamute (Husky)
  • #1 Dew drinker.
  • *****
  • Male
  • Posts: 28546
Re: Help! Site being Hacked!
« Reply #1 on: May 14, 2009, 02:41:30 pm »
I just called WS. So he'll take a look as soon as he can. ;)

Offline NeoFur

  • Hero Member
  • Species: Wolf
  • Such is Life.
  • *****
  • Male
  • Posts: 1088
    • Furaffinity Page
Re: Help! Site being Hacked!
« Reply #2 on: May 14, 2009, 02:54:20 pm »
Ok great. :D

 I fixed it again, but these attacks are getting on my last nerve.
Fur crying out loud I just got the blog up and this happends.
>:(

Offline NeoFur

  • Hero Member
  • Species: Wolf
  • Such is Life.
  • *****
  • Male
  • Posts: 1088
    • Furaffinity Page
Re: Help! Site being Hacked!
« Reply #3 on: May 14, 2009, 03:10:28 pm »
Did some searching on it.
I'm getting some more WP security pulg ins.
Anyone using Wp needs to check their site.
:o

Hackers continue to subvert hundreds of thousands of Web pages with IFrame redirects that send unwary users to malware-spewing sites. It was apparently reported that these IFrame redirects have slowed, but they’re still occurring at an alarming rate. A friend of mine, who owns the blog called YourSEOSucks, was recently exposed to the IFrame hack using WordPress 2.7.1.

How it works:

Hackers are likely relying on an automated tool to do the dirty work, the hackers add IFrame code to the saved search results on the sites. The next visitor that uses the search tool is then redirected to another Web site by the IFrame code. The second site in turn puts up a message telling the user that a new codec (coder/decoder) needs to be installed. Accepting the codec takes the user to still another site, which actually hosts the malware — a new variant of the Zlob Trojan horse — and installs it on the victim’s PC.

How to secure your WordPress:

Download Secure plug-in: Remove Error information on login page; adds index.html to plugin directory; removes the wp-version, except in admin area.

Download Security Scan plug-in: Scans your WordPress installation for security vulnerabilities and suggests corrective actions.

If you are using an unsecured FTP client, you are in danger of exposing your passwords to hackers because the passwords are passed between your FTP client and your website in plain text. Use a program like WinSCP, or a FTP client that allows you to connect to your site using SFTP, SCP. Both of these methods encrypt your user name and password, making it much more difficult for a hacker to discover them, even if they intercept them with some sort of packet sniffer.

Lock her down!

Offline WhiteShepherd

  • furtopia.org Sysop!
  • *
  • Male
  • Posts: 4842
    • http://www.whiteshepherd.furtopia.org
Re: Help! Site being Hacked!
« Reply #4 on: May 14, 2009, 04:02:15 pm »
Your ftp password has been changed.  It is possible but unlikely that they edited your PHP via FTP.  More likely they could of exploited a flaw in a PHP program you have?  Hackers can scan the web for old/vulnerable PHP applications and apply their hack that way.  Make sure all your PHP programs are up to date to the latest versions and or patches.
IRC quotes:

[05:01] <Kai_Misou> We cats sleep when we want and where we want.
[05:01] <WhiteShep> We dogs sleep WHEN we can. :/
<!--QuoteEnd--></td></tr></table><span =''><!--Quot

Offline NeoFur

  • Hero Member
  • Species: Wolf
  • Such is Life.
  • *****
  • Male
  • Posts: 1088
    • Furaffinity Page
Re: Help! Site being Hacked!
« Reply #5 on: May 14, 2009, 04:45:54 pm »
Thanks a lot. :D
I've added even more defense to the WordPress parts.

I think it was the FTP because they got to my Photoframe Galleries PHP.
Avast scanner is what found the Iframe hacks in my Firefox cache BTW.

I'll keep checking to see if they try again.


Offline WhiteShepherd

  • furtopia.org Sysop!
  • *
  • Male
  • Posts: 4842
    • http://www.whiteshepherd.furtopia.org
Re: Help! Site being Hacked!
« Reply #6 on: May 14, 2009, 06:40:49 pm »
If they exploit a php application on your website it's often possible for them to hit any of your other files in the same website.  But your password has been changed as well just in case.  If this happens again PM me ASAP.
IRC quotes:

[05:01] <Kai_Misou> We cats sleep when we want and where we want.
[05:01] <WhiteShep> We dogs sleep WHEN we can. :/
<!--QuoteEnd--></td></tr></table><span =''><!--Quot