blog.species5618.net

I got Hacked

by Species5618 on Feb.10, 2009, under General

No Gravatar

Well this is one very embarrassing day. Given my day job :-(

The brand new WordPress 2.7 instance I setup for my wife, got hacked
Still not sure how, the access logs are not very conclusive, but someone managed to edit every header.php file under the themes folder and inject a trojan “exploit-iframe.gen.c”

I found a similar story hear. http://photocritic.org/wordpress-exploit-iframe-gen-c/

Yes, I admit I allowed apache write access to the themes folder. which i have now fixed

The Code also included a refernce to “search_bot111″

The searchbot code seems to be a bit of PHP?? to hide the site/trojan from search engines

needless to say i am VERY annoyed

Bookmark and Share
:
2 comments for this entry:
  1. stymasterNo Gravatar

    Ooops

    [*goes off to check permissions for the shonky setup he's just done*]

Leave a Reply




This site is using OpenAvatar based on

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!