• I have been battling link dropping on my site for months now. I have completely removed WordPress – Re-installed, updated, searched high and low. and yet again, I found a .ttf image in my theme. The footer of my page get bombarded with hidden link spam.

    The file is named ARLRDBD.TTF

    When I open it in Notebook, it looks like some foreign script not a true type font as it’s named.

    Could someone please direct me to a fix for this issue or anything close to this?

Viewing 8 replies - 16 through 23 (of 23 total)
  • Thread Starter Mobster

    (@mobster)

    No offense taken. It was complete a pain to find. Please excuse my frustration.

    Anyways, I guess finding how they got that on my server is the question?

    whooami

    (@whooami)

    .. like I said, uploaded.

    im sure those server logs are long gone. what the timestamp on the file? That will tell you how long its been there.

    Thread Starter Mobster

    (@mobster)

    I don’t know, I’ll have to look at it. Here is a similar post regarding this attack. It looks the same anyhow.

    https://www.ads-software.com/support/topic/157889?replies=17

    whooami – I found it myself, like I said in the beginning. Just about the time I gave up, I found it. That was my whole point. I prefer to find these things myself anyhow because If this EVER happens to me again, at least I’ll know were to start looking. ??

    Thread Starter Mobster

    (@mobster)

    Tue Feb 19 17:27:24 EST 2008

    C99madShell v. 2.0 madnet edition

    whooami

    (@whooami)

    Tue Feb 19 17:27:24 EST 2008

    10 months old. nice.

    Thread Starter Mobster

    (@mobster)

    I know crazy! Hey, thanks for all the input Whooami. I like your style!

    whooami

    (@whooami)

    oh, since youre still peeking in here, what directory did you find that in?

    Thread Starter Mobster

    (@mobster)

    It was in my theme. Believe it or not, if it were a falling brick, I’d be dead.

    It was named i_sidebar.php. I’m not sure that’s all there is to it. I still don’t understand how they can edit files on my server but this C99madShell v. 2.0 madnet edition is a pretty malicious looking script. (I know it was uploaded somehow) There’s even a feature that allows you to delete itself from any directory, among many other cracking tools.

    I’m wondering if the hack is still there and I just happened to find the tool (i_sidebar.php) they were using at the time?

Viewing 8 replies - 16 through 23 (of 23 total)
  • The topic ‘Ok… What and How? .TTF hacked and dropping link spam!’ is closed to new replies.