GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   So you like Wordpress... then you want to be careful (https://gfy.com/showthread.php?t=804620)

Dennis69 02-02-2008 08:44 AM

So you like Wordpress... then you want to be careful
 
It looks like somebody hacked wordpress on one of my blogs and put a script on the bottom of 1000s and 1000's of my pages on one of my dedicated servers, it will take me forever to remove it from all the pages... the script is redirecting all my traffic from free sites, gallery pages and so much more to this url.

http://jxp2dve.com/?prvtof=8b2VkUqfX...JePkd0tw%3D%3D

Miguel T 02-02-2008 08:51 AM

Might have been a host problem , not a wordpress problem.

Nicky 02-02-2008 09:37 AM

urgh, you sure it was wordpress? I don't like the sound of it, better try and up the security on it in some way

rowan 02-02-2008 09:38 AM

Probably not the best idea to be posting direct links to pages that were inserted by hackers, it's not hard to imagine what they might do to an unpatched/holy MSIE. :2 cents:

Do you run any other scripts on the server?

dstaff 02-02-2008 10:33 AM

there's pretty much a security hole in every version of wordpress...public and 0day..not much you can do...

anything helps though

www.grsecurity.net <- harden your kernel
http://www.modsecurity.org/ <- harden apache and php
:thumbsup

AliGbone 02-02-2008 12:19 PM

yea wordpress if full of vulnerabilities gots to lock it down if your going to use it

directfiesta 02-02-2008 12:28 PM

Quote:

Originally Posted by AbsolutePorn (Post 13731205)
Might have been a host problem , not a wordpress problem.

he is dedicated ....

HairToStay 02-02-2008 12:30 PM

What version of Word Press was "hacked?"

V_RocKs 02-02-2008 01:12 PM

You probably have an ancient form of wordpress unseen in years.

BlackCrayon 02-02-2008 01:19 PM

As long as you install updates right when they come out, you should be fine.

Pornopat 02-02-2008 03:06 PM

Quote:

Originally Posted by directfiesta (Post 13731829)
he is dedicated ....

It can still happen...:2 cents:

directfiesta 02-02-2008 03:28 PM

Quote:

Originally Posted by Pornopat (Post 13732273)
It can still happen...:2 cents:

:2 cents: then it is not the host fault, as the original poster implied ... people don't read here ... or what ?

u-Bob 02-02-2008 03:39 PM

Running wordpress is a disaster waiting to happen.

Dennis69 02-02-2008 03:46 PM

Quote:

Originally Posted by BlackCrayon (Post 13732000)
As long as you install updates right when they come out, you should be fine.

Best of luck with that... you almost need to be there hitting refresh because they are always updating the damn thing :mad:

BlackCrayon 02-02-2008 04:05 PM

Quote:

Originally Posted by Dennis69 (Post 13732385)
Best of luck with that... you almost need to be there hitting refresh because they are always updating the damn thing :mad:

There hasn't been an update in over a month.

Pornopat 02-02-2008 04:30 PM

Quote:

Originally Posted by directfiesta (Post 13732326)
:2 cents: then it is not the host fault, as the original poster implied ... people don't read here ... or what ?

It can be the hosts fault wheater or not he is dedicated. Several dedicated boxes can be connected to each other.
A piece of php on one of the boxes or an outdated piece of software (besides wordpress) can do the trick.

People dont think here or what? :2 cents:

directfiesta 02-02-2008 04:35 PM

Quote:

Originally Posted by Pornopat (Post 13732496)
It can be the hosts fault wheater or not he is dedicated. Several dedicated boxes can be connected to each other.
A piece of php on one of the boxes or an outdated piece of software (besides wordpress) can do the trick.

People dont think here or what? :2 cents:

fine, it is the host fault ... have to leave ... going to nightcourses ....

Pornopat 02-02-2008 04:36 PM

Quote:

Originally Posted by Dennis69 (Post 13731184)
It looks like somebody hacked wordpress on one of my blogs and put a script on the bottom of 1000s and 1000's of my pages on one of my dedicated servers, it will take me forever to remove it from all the pages... the script is redirecting all my traffic from free sites, gallery pages and so much more to this url.

http://jxp2dve.com/?prvtof=8b2VkUqfX...JePkd0tw%3D%3D


I have had a similar problem. The host helped me with a custom solution that repressed this code. So the code became useless. It was a temporary solution because the moment the hacker redirects it to another url you will have to change your costumsolution as well. It helps you buy time to find the security hole though.

papill0n 02-02-2008 04:39 PM

Uggg thats sucks Dennis. Good luck sorting that nightmare out mate.

mrkris 02-02-2008 04:48 PM

Wordpress is crap. The code base is clunky, the plugin architecture is sub par and its slow as sin. :2 cents:

BlackCrayon 02-03-2008 11:00 AM

Quote:

Originally Posted by mrkris (Post 13732541)
Wordpress is crap. The code base is clunky, the plugin architecture is sub par and its slow as sin. :2 cents:

Whats the alternative?

tony286 02-03-2008 11:16 AM

this is why Im thinking of getting a separate server or a virtual account to start to play with wp. To have my server that pays my mortgage fucked up wouldn't work for me.

Chio 02-03-2008 11:20 AM

Check the div for class=goro in your source or something like that. There are a number of ways to remove it (it's a single include file). Search google.

If you use autoblogger simply use rewriter to replace eveything within the goro div with a blank space.

Chio 02-03-2008 11:22 AM

Here's the link to remove the infection if it's the goro injection:

http://blog.kakkoi.net/wordpress/how...class-mailphp/


All times are GMT -7. The time now is 12:45 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123