No code found in permalinks from possible worm attack
-
We have a wordpress site here at work that was recently reported to us by our IT security department as severing out spam pages. This does not appear to be the case anymore, however, searching google’s cache shows us that at some point in the past it was doing just that.
This lead us to the find that there had been a recent attack on older versions of wordpress. I quickly updated the site to the latest version and began to read up on how to clean out the database.
I did find a mysterious administrator account that is not listed under the users page. However, I did not find anything wrong with our permalinks or RSS feeds. The link below is what was reported as originally serving out the spam pages. It no longer servers out spam and you will now just get the home page if you open it.
https://sciencepolicy.colorado.edu/prometheus/?pilled=20100
Is this the same worm? Or a complete different problem? I’m not very knowledgeable with these sorts of attacks and I plan on exporting all the wordpress content and then reinstalling the site from scratch to clean out any hacks within the database. But I would like to have a better understanding what has actually happened.
Sorry if this is another post regarding this worm. I just felt that this situation might be different since I did not find the usual strange additions within the permalinks or RSS feeds as was reported by most of the sites I visited regrading this attack.
Any feedback or insight you can provide is appreciated.
- The topic ‘No code found in permalinks from possible worm attack’ is closed to new replies.