WordPress Hacked with Infestation of Random PHP files
-
Hi,
I have what seems to be an infestation of ‘hack / backdoor?’ files on my iPage server which hosts several WordPress installations acting principally as static CMS websites. These files exist in every single one of my WordPress installations. I have no idea what they do nor how they got there and I can’t find anyone with a similar problem through by Googling. My current strategy is to delete them and install hardening / security plug-ins for each domain – also to change passwords on my FTP server. I’d love to hear from anyone else if they’ve experienced similar, and if anyone can offer any further insight.
I’ve written .php script which searches for these files, which appear to have a characteristic size of between 5KB and 6.5KB, and dated 2012, even for recent installs. This is an example of the files found in just one of my installations…
../wp-content/plugins/mojo-marketplace/classlocale.php
../wp-content/plugins/mojo-marketplace/updater/wraplocale.php
../wp-content/plugins/w3-total-cache/classgeneral.php
../wp-content/plugins/w3-total-cache/lib/Minify/Solar/wrapperlocale.php
..gpm/wp-content/plugins/appointment-booking-calendar/TDE_AppCalendar/light/classlocale.php
../wp-content/plugins/appointment-booking-calendar/wrappergeneral.php
../wp-content/plugins/appointment-calendar/wrapperlocale.php
../wp-content/plugins/appointment-calendar/menu-pages/font-awesome-assets/fonts/wrappergeneral.php
../wp-content/plugins/appointments/loadlocale.php
../wp-content/plugins/appointments/includes/support/classapi.php
../wp-content/plugins/birchschedule/assets/js/jscolor/wrapgeneral.php
../wp-content/plugins/birchschedule/wraplocale.php
../wp-content/themes/twentytwelve/entry-archive.php
../wp-content/themes/twentytwelve/css/content-nav.php
../wp-content/themes/twentyfourteen/sidebar-nav.php
../wp-content/themes/twentyfourteen/languages/content-archive.php
../wp-content/themes/twentythirteen/content-meta.php
../wp-content/themes/twentythirteen/css/entry-archive.php
../wp-content/themes/gpm/content-funcs.php
../wp-content/themes/gpm/images/sidebar-nav.php
../wp-includes/js/tinymce/plugins/paste/wp-locale.php
../wp-includes/js/tinymce/plugins/image/ms-meta.php
../wp-includes/SimplePie/func-general.phpYou can see that they are quite randomly distributed and often buried deep in the directory structure.
[hacked code removed – please don’t post that here]
- The topic ‘WordPress Hacked with Infestation of Random PHP files’ is closed to new replies.