WordPress 2.8.4 Site Hacked
-
One of my domains was hacked while it was running version 2.8.4 are there any vulnerabilities I should know about?
The site has three Wp installations, 2x 2.8.4 and 1x 2.7. Interestingly both 2.8.4 installations was hacked (changed files), but the one running 2.7 which I forgot to update wasn’t affected (just updated to 2.8.4 now after recovering the other sites)!
https://www.free-recipes.co.uk/
https://www.free-recipes.co.uk/hair/
https://www.free-recipes.co.uk/store/ the 2.7 versionNot sure exactly when it was hacked, but know it was after the 25th of last month when I made the last dedicated server backup and no later than the 12th October as Google Cache confirms (hair site Google cache from 25th September is clean).
I’ve used the 25th of September server backup to fix the problems and changed all the passwords, deleted plugins not used, updated a few plugins so hoping it won’t get hacked again.
I only found the problem by luck, realised today an anomaly in how the template on the main WP installation was looking on the page (something was off), viewed source and found hundreds of links below the footer (lot of viagra links). If you look at the Google cache now from 12th October you can see the links.
So I’m confident those links was added after the 2.8.4 update.
The main index.php file had hidden content at the bottom. Also found it in an index.php file associates with the PHPBB forum (cleaned it now) at https://www.free-recipes.co.uk/forum/ (that forum gets the crap spammed out of it!! have not added the new MySQL password to the config file, so not working now), but I couldn’t see the links on the forum pages, so guess it was a script or something adding the links to index.php files, but not all of them as the blank index.php files in the plugins and theme folders are clean.
I noticed all files and folders I checked now have full write access.
This domain has not been hacked before, my son was running a few WordPress 2.5 sites that got hacked (different problem, had an iframe added to malicious content) a month or two ago, (too lazy to update) I cleaned them after finding the problem, those sites now running 2.8.4 and are clean.
I started cleaning the site and fixed the main installation (uploaded 2.8.4 again) before deciding to use the backup, I’ve made another backup of the hacked/partially cleaned Virtualmin server for the domain in case it’s useful for WordPress development to track down how the site was hacked. This hacked backup has whatever was changed to the hair installation by the hacker intact (I made no changes).
If access to this backup is any use to WordPress development let me know, I run over 50 WordPress installations so it’s in my best interest to help you guys out to keep WordPress secure ??
David Law
- The topic ‘WordPress 2.8.4 Site Hacked’ is closed to new replies.