Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-30-2022, 07:10 PM   #1
femdomdestiny
Confirmed User
 
femdomdestiny's Avatar
 
Industry Role:
Join Date: Apr 2007
Posts: 5,112
somoene inserted links on my site

Hmm...I've discovered unwanted links on one of my wordpress blogs. It seems they are placed in footer.php. Below is a print screen of the code.

Does anyone have an idea how this was done and how to protect it in the future?
The theme is Generate Press and they are not having a real answer, denying it was a problem with a theme.

This site has no Wordfence plugin installed,but the other one with it, had the same problem.

thanks



<div style="display:none">
<p>Are you looking for free Arab porn websites? The Internet is full of porn sites but what's the difference between porn and porno sites? Here are a few things to look out for.
Porn sites feature girls and women that are mostly dressing up to look like women and for men. They are not dressed sensuously or they are not made to look like they are being intimate with their partners.Not only are the girls dressed in something other than a short skirt, they are also often younger than the man who is watching them. And there are times when the young woman in the videos could be his girlfriend.</p>
<p><a href="*ttps://xnxxarabsex.com/categories/سكس-عربي/">arab sex</a></p>
<p><a href="*ttps://sexe-libre.org/pokimane-sex-tape-nudes-twitch-streamer">pokimane nudes</a></p>
<p><a href="*ttps://sexsaoy.com/">arab sex stories</a></p>
<p><a href="*ttps://aflamaljins.com">aflamaljins.com</a></p>
<p><a href="*ttps://russiainporn.com">russiainporn.com</a></p>
<p><a href="*ttps://afdalsex.com/">afdal sex</a></p>
<p><a href="*ttps://overpic.com/">mature sex</a></p>
__________________
Femdom Destiny


--------------------------------------------
ICQ: 463-630-426
email: webmaster(at)femdomdestiny.com
femdomdestiny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2022, 08:01 PM   #2
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,407
Wordfence might be able to clear that up , I woild sugges you update all your plugins and change all your passwords also.
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-30-2022, 11:52 PM   #3
zerovic
Confirmed User
 
zerovic's Avatar
 
Industry Role:
Join Date: Apr 2010
Posts: 1,017
Hi,

Make sure your Wordpress and plugins are up to date. Not only the site that got injected but all sites on the server.

I would also suggest listing all newly edited files on your host, to find all affected files.

Here's a script that will do this for you

Quote:
<?php

function aasort (&$array, $key) {
$sorter=array();
$ret=array();
reset($array);
foreach ($array as $ii => $va) {
$sorter[$ii]=$va[$key];
}
asort($sorter);
foreach ($sorter as $ii => $va) {
$ret[$ii]=$array[$ii];
}
$array=$ret;
}

function rglob($pattern, $flags = 0) {
$files = glob($pattern, $flags);
foreach (glob(dirname($pattern).'/*', GLOB_ONLYDIR|GLOB_NOSORT) as $dir) {
$files = array_merge($files, rglob($dir.'/'.basename($pattern), $flags));
}
return $files;
}

$dev = array();

$result = rglob('../*.php');
foreach($result as $file) {
$dev[] = array("file" => $file, "date" => date("Y-m-d H:i:s", filemtime($file)));
}

aasort($dev,"date");

foreach($dev as $test) {
// add a date here, let's say, 2022-04-20 to list the files modified after the 20th of April
if($test['date'] > "2022-04-20") {
echo "<div id=\"line\"><div id=\"file\">" . $test['file'] . "</div><div id=\"date\">" . $test['date'] . "</div></div><br />";
}
}

?>
Sorry, it's a bit messy, but it will do the job.

Cheers,
z
__________________
php, html, jquery, javascript, wordpress - contact me at contact at zerovic.com
zerovic is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-01-2022, 07:12 AM   #4
Denny
Too lazy to set a custom title
 
Denny's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 17,070
https://www.malcare.com/blog/spam-li...ion-wordpress/
__________________
Denny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-01-2022, 10:29 AM   #5
jscott
jscizzle
 
jscott's Avatar
 
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 23,166
I've had that before, for me it was some old outdated plugins that were exploited.
Goodluck fixing, it sure sucks these hacker/scammers stealing space on your sites
__________________
“If you think tough men are dangerous, wait until you see what weak men are capable of.”
—Jordan B. Peterson

Listen to Pomp tell why is Bitcoin important
jscott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-01-2022, 11:38 AM   #6
hausarzt
Confirmed User
 
hausarzt's Avatar
 
Industry Role:
Join Date: Jan 2011
Location: Somewhere in Germany
Posts: 815
Also make sure not to use any nulled themes and plugins. Only buy software from verified sources.
__________________
I know, my english is bad. But your german might be even worse
hausarzt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-01-2022, 12:28 PM   #7
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,383
It is likely malicious code in little bits of Javascript. WordFence may be able to tell you the specific files, but, to keep them from coming back, you need to update everything, delete unused themes like old exploitable default themes, and upgrade to current php. And report whatever affiliate is doing this to any program where you see the affiliate ID.

Hope this helps. Good luck.
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2022, 05:30 AM   #8
lock
Confirmed User
 
lock's Avatar
 
Industry Role:
Join Date: Jul 2003
Location: Australia
Posts: 5,065
Wordpress is just non stop problem after problem. I like it as easy but always trashed by hackers.
__________________
Traffic.Tools - 40+ Free Tools
Free.Marketing - 150+ Free Tools
Submission.Tools
- 20+ Free Tools
lock is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2022, 10:09 AM   #9
zijlstravideo
Confirmed User
 
zijlstravideo's Avatar
 
Industry Role:
Join Date: Sep 2013
Location: The Netherlands
Posts: 805
Quote:
Originally Posted by AmeliaG View Post
report whatever affiliate is doing this to any program where you see the affiliate ID.
See Clickadu javascript embeds on those sites:
h*ttps://stagepopkek.com/lv/esnk/1836018/code.js
h*ttps://mafrarc3e9h.com/lv/esnk/1839026/code.js
etc etc

I think the number in the javascript url is the affiliate's website/domain ID (1836018, 1839026 etc).
__________________
Contact: email
zijlstravideo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2022, 11:13 PM   #10
natkejs
Confirmed User
 
Industry Role:
Join Date: Jan 2003
Location: Nomad Land
Posts: 1,554
Would be interesting to know what other plugins you are running. I've seen similar issues in the past with certain cache plugins.

Do make sure your plugins are updated and Google each one of them to see if you find people with similar issues.
__________________
natkejs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 11:37 AM   #11
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
its XSS injection. I've had this happen ACROSSS my network of adult porn blog sites.

I tried all the plugins, etc bs none will work

Solution: GTFO of wordpress!

I had a custom built script for myself. Fast, no updates required ever and open source. NO MORE worrying about XSS injections ever!
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 02:04 PM   #12
AmeliaG
Too lazy to set a custom title
 
AmeliaG's Avatar
 
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,383
Quote:
Originally Posted by natkejs View Post
Would be interesting to know what other plugins you are running. I've seen similar issues in the past with certain cache plugins.

Do make sure your plugins are updated and Google each one of them to see if you find people with similar issues.
Do you recall which cache plugins allowed the exploit or were the exploit files just hiding in the cache?
AmeliaG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 02:43 PM   #13
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 75,440
secure your admin. there are files still that reveal info
__________________
EMAIL ==>[email protected] ==> #NOBIDEN2024
TRUMP 2024!!! | END DACA!!!! | HCR2060 <= ILLEGAL ALIENS!!!!...👮
=> TRUMPS PAYDAY!!!!... - Support The Laken Riley Act!!! - Trump Nobel Prize...
brassmonkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 03:57 PM   #14
adultchatpay
Let's Make Money
 
adultchatpay's Avatar
 
Industry Role:
Join Date: Dec 2008
Posts: 8,784
Quote:
Originally Posted by hausarzt View Post
Also make sure not to use any nulled themes and plugins. Only buy software from verified sources.
Agree, they usually inject a lot of shits.
adultchatpay is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 04:33 PM   #15
RyuLion
 
RyuLion's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,058
Also make sure none of your files are set with 777 permissions.
__________________
RyuLion is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2022, 07:14 PM   #16
natkejs
Confirmed User
 
Industry Role:
Join Date: Jan 2003
Location: Nomad Land
Posts: 1,554
Quote:
Originally Posted by AmeliaG View Post
Do you recall which cache plugins allowed the exploit or were the exploit files just hiding in the cache?
Can't remember, was either WP Super Cache or W3 Total Cache. It was years ago and the problem was fixed in the next update, think 2016 or something like this.

The code was injected into cached files so luckily it was quite easy to turn off caching and clean those directories.
__________________
natkejs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
theme, site, links, press, future, real, generate, protect, installed, but, wordfence, plugin, denying, answer, wordpress, blogs, unwanted, discovered, inserted, hmm, footer.php, somoene, idea, print, screen, code



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.