GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   warning to wordpress users (https://gfy.com/showthread.php?t=976463)

fris 07-04-2010 05:35 PM

warning to wordpress users
 
do not install any themes from

http://www.themes2wp.com/

i just finished cleaning up a clients wordpress multisite, pain in the ass, each theme when activated, adds nasty code to your themes functions file, not just the activated one, but it cycles through every theme you have in your wordpress folder, so even if you remove the code from one, once you activate another theme it will repeat the process over and over.

just a tip, when downloading any theme, check the header footer and functions file for anything nasty.

hope this saves some people from headaches.

PGR 07-04-2010 05:49 PM

Crap... I use them. Main reason is they usually include .PSD file for logo.

JBlack 07-04-2010 05:50 PM

Oh I hearya! .... I've dealt with shit like this before. Shady encoded shit in the footer or header... the next thing you know u have to throw away your dedicated box... nahh kidding but seriously, the thing here is to get in the habit of scrutinizing theme files before they are used.

Cyber Fucker 07-04-2010 05:52 PM

No worries, I make all themes by myself for every script but thx anyway! :pimp

PGR 07-04-2010 05:54 PM

Fris: Can you tell me what I should be looking for? An example of this "nasty code" would be very helpful.

PGR 07-04-2010 06:04 PM

Just found a hidden link in one. Motherfucker. Thanks for the heads up fris

bloggerz 07-04-2010 06:07 PM

:disgust

fris 07-04-2010 06:07 PM

Quote:

Originally Posted by P.G.R. (Post 17308058)
Fris: Can you tell me what I should be looking for? An example of this "nasty code" would be very helpful.

check your themes functions file the very bottom, if you activated one theme, then it will add it to every theme you have in your themes dir, as it cycles through them, so you will need to manually edit every functions.php file in every theme in that current installation.

http://pastebin.com/j3uVF6u1

fris 07-04-2010 06:11 PM

it goes through all your comments and adds him as the owner ([email protected])

PGR 07-04-2010 06:30 PM

Going through themes right now and deleting code, but even after doing so, the hidden links are still there near the bottom of the page when I view source. They all go to pirated movie sites like this : http://www.alfamovie.com/download-fu...ies/years/2009

Highest Def 07-04-2010 06:33 PM

Thanks for the info. I'm surprised this isn't a much larger problem with so many fly-by-night free theme sites out there. Almost 40K downloads of malicious themes from that site. Geez

AdPatron 07-04-2010 06:52 PM

Hack the planet!

slayer69 07-04-2010 06:52 PM

thanks for the heads up. Was about to use them

PGR 07-04-2010 06:57 PM

Hidden links are in sidebar.php at the bottom. Believe it's the same for each theme.

adult-help 07-04-2010 06:57 PM

thanks for this. Good to know to be more careful!

sortie 07-04-2010 07:03 PM

Free shit..................

devine 07-04-2010 07:09 PM

that's the cost of 'free'

PGR 07-04-2010 07:28 PM

Lesson learned

dav3 07-04-2010 07:55 PM

Thanks for the heads up.

cambaby 07-04-2010 07:59 PM

Say Fris you dont happen to know a plugin that will make custom seo urls for each media gallery image?

BigRod 07-04-2010 08:12 PM

Jesus... I guess thats what free gets

fris 07-04-2010 08:19 PM

Quote:

Originally Posted by cambaby (Post 17308195)
Say Fris you dont happen to know a plugin that will make custom seo urls for each media gallery image?

try this one http://wordpress.org/extend/plugins/seo-image/

EliteWebmaster 07-04-2010 10:07 PM

Thanks for the heads up Fris :) Any recommendations on some good sites for templates in terms of quantity and non messed up codes?

Nikitos 07-04-2010 11:31 PM

Thank for the heads up. I was about to use them. Now i won't.

Matyko 07-04-2010 11:54 PM

Thanks a lot for the warning.
Peace

raven1083 07-05-2010 01:14 AM

Thank you for sharing it here

pradaboy 07-05-2010 02:09 AM

Thanks for the heads up fris. Do you have any experience with WP Remix btw?

The Duck 07-05-2010 02:20 AM

Thanks for the heads up.

M0nk 07-05-2010 02:21 AM

Good info fris, thanx a lot!

babymaker 07-05-2010 02:52 AM

Thanx for the info :thumbsup

Dtothex 07-05-2010 02:54 AM

Thanks for tip! V useful.

Denny 07-05-2010 03:29 AM

Thanks for the heads up :disgust

seeandsee 07-05-2010 03:44 AM

397710 WordPress Themes was downloaded

Jesus, they can serve true that all the shit

ottopottomouse 07-05-2010 05:19 AM

Quote:

Originally Posted by devine (Post 17308141)
that's the cost of 'free'

Quote:

Originally Posted by sortie (Post 17308135)
Free shit..................

Quote:

Originally Posted by BigRod (Post 17308206)
Jesus... I guess thats what free gets

Not always, there are a lot of people that do a free theme and it's fine. It's really the cost of free themes from a site that has them all in one place. Funny thing too is quite often they have a quite strict license on not changing the code :upsidedow

Konkan 07-05-2010 05:51 AM

Thanks fris. This was very helpful !!!

Si 07-05-2010 06:46 AM

Thanks for the heads-up :thumbsup

fris 07-05-2010 07:12 AM

Quote:

Originally Posted by ottopottomouse (Post 17308751)
Not always, there are a lot of people that do a free theme and it's fine. It's really the cost of free themes from a site that has them all in one place. Funny thing too is quite often they have a quite strict license on not changing the code :upsidedow

just make sure you check your header footer and functions file for any nasty code, im not talking about encrypted footer links, im talking really nasty code like this one how it edits all your theme files and inserts his own email address in comments.

I know people dont think twice about downloading a good theme and activating it, nothing it stopping someone from adding code to the theme to send your mysql pass and admin user and pass to them on activation, its only about 5 lines of code, or even create an admin account and email it to them on theme activation.

so be careful what theme(s) you use.

pornguy 07-05-2010 08:01 AM

Now that really sucks.

Fris I believe you have put out some nice themes or someone here has.. I know Czarina does them as well.

Bump for good info.

fris 07-05-2010 11:25 AM

Quote:

Originally Posted by pornguy (Post 17309087)
Now that really sucks.

Fris I believe you have put out some nice themes or someone here has.. I know Czarina does them as well.

Bump for good info.

Ive not given away or sold any themes myself, most of the ones I do are for clients and arent publically available.

pradaboy 07-05-2010 01:35 PM

fris, any experience with wp remix?

fris 07-05-2010 07:12 PM

Quote:

Originally Posted by pradaboy (Post 17309977)
fris, any experience with wp remix?

ya ive used it, not my style though, other options available, depends what you need/want

evolmachine 08-24-2010 07:47 AM

this is why i look through the code to make sure nothing is in there that will screw everything up... first take a look at the functions.php file then cycle through all the other files... takes 5 mins and leaves me much more comfortable with pushing it to the blog.

V_RocKs 08-24-2010 11:21 AM

That sucks!


All times are GMT -7. The time now is 02:00 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123