• A week ago one of my sites, no known vulnerable plugins, brute force security had the following code injected into header.php just after the <body> tag.

    It’s a site that had everything updated 7 days before and has brute force protection (no attacks in that time).

    <script type="text/javascript" src="https://xxxxxx/js/113925.js" ></script>
    <noscript><img alt="" src="https://xxxxxx/113925.png" style="display:none;" /></noscript>

    So this post is to serve two purposes;

    Anyone heard of it and know how it’s getting in?

    and look out for it yourselves.

    A google search shows no information but turns up a number of sites with the code embedded.

    The page I need help with: [log in to see the link]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Side note: Don’t put your URL in topic names. Use the link field, when you do what you did it looks spammy as all else. ??

    I’ve fixed your topic and put your URL in the link field as well as adjusted the slug.

    Edit: I’ve also moved this topic from Everything else WordPress to Fixing WordPress where it belongs.

    • This reply was modified 6 years, 10 months ago by Jan Dembowski.
    Thread Starter chrispink

    (@chrispink)

    It’s not my site.
    Do me the courtesy of reading the topic before being so rude.

    The reason for putting the url in the topic is that is what I searched for. This is the spurious link injected into my site. I have edited my post to make sense (to those who can be bothered to read it)

    I am scrupulous about security, updates and the use of secure plugins and code so that this was injected into my site should be of wider concern to the WordPress community.

    If you’re not interested, fine.

    Thread Starter chrispink

    (@chrispink)

    @jandembowski

    MY POST MAKES NO SENSE WHATSOEVER NOW. EITHER RESTORE THE EDIT OR DELETE THE POST.

    WHICHEVER YOUR INTERFERENCE IS IGNORANT AND RUDE

    YOU HAVE NOW PUT A KNOWN MALWARE LINK INTO A “Site I need help with”

    • This reply was modified 6 years, 10 months ago by chrispink. Reason: Because he's an idiot I should feel compassion rather than anger
    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    A few things.

    1. I’m not rude and I’m certainly not ignorant. Perhaps you should re-evaluate your behavior and have less coffee?

      You personally posted that link in the topic title and in the topic body. If you did not want that link there then you should not have posted it in the first place. That was your decision, take responsibility for your actions.

      This topic will not be edited BTW. I will delink the field though.
      https://www.ads-software.com/support/guidelines/#deleting-editing-posts

    2. I did remove the link from the topic body and the topic title. I also removed it from the topic slug. I specifically put it in a field that cannot be seen unless you are logged into the forums. Unlike where you posted it, it cannot be read by search engines. That’s not an accident BTW and I’d appreciate, but not expect, a “Thank you”. Your history here does not lead me to expect that behavior from you.
    3. Do not contact me again in Slack directly, or in anyway again. Your DM will be shared with the other moderators. Just like you, I am a volunteer. None of the moderators are here for your abuse and that is not long tolerated. If you have a problem with the moderators then consider posting to the #forums channel on Slack instead. If you do, remember your manners.
    4. Your account here is now on moderation watch due to your abuse.

      https://www.ads-software.com/support/guidelines/#being-mod-watched-or-banned

      When you’ve demonstrated that you can maintain a level of professionalism or at least good manners then the moderation flag will be reconsidered. If you do not correct your behavior then you may be banned.

    I’m closing this topic now. There just doesn’t seem to be any point to further continuing a support topic with you.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Security Issue on my site’ is closed to new replies.