Forum Moderators: phranque

Message Too Old, No Replies

Blog is hacked - need help

google cache shows spam words inside footer.php

         

Fernando

1:31 pm on Jun 23, 2008 (gmt 0)

10+ Year Member



Hope I am not posting at the wrong section. Writing here since my blog is developed with css.. here's the problem:

When I did a Google search for my name today, the first result was my blog, but after my footer text, I saw spammy keywords for pills.

I made some research as to what causes this and read in a blog that this is some kind of hack and the hacker possibly added code to the footer file in my theme that would add the spam links, but only for certain user-agents (i.e. Googlebot or Yahoo’s crawler). View-source with a normal web browser doesn't show the links. I followed advice and found the spam words using view source on the Google cache.

Here's the live view: <snip>
I check my footer.php but do not see any of these links. Does anyone know where I should look at? Many thanks in advance!
Cenk

[edited by: Fernando at 1:57 pm (utc) on June 23, 2008]

[edited by: engine at 1:59 pm (utc) on June 23, 2008]
[edit reason] no urls, thanks [/edit]

4css

1:48 pm on Jun 23, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi Fernando,

First let me say, if you can still edit your post, plese remove your links. I know it is difficult to post some types of information without links, but as per the forum charter [webmasterworld.com] links aren't permitted.

Second, your post most likely will be removed as this isn't the section for this as it isn't related to css.

Now your problem.

I'm so sorry that you have to deal with this.

I don't know what blog software you are using but there are plugins that you can get for your blog for spamers. Each blog has a different one that you can use, you just have to search your blogs site for plugins that you can install.

I'm sure that there are others who could give you more advice so keep an eye on your thread, also to check to see if and where it is moved. ;)

Good luck.

Fernando

1:59 pm on Jun 23, 2008 (gmt 0)

10+ Year Member



I removed three links but had to keep the one above since it is impossible to explain without the link. I'll try to find a better section. Thanks for your reply but I don't think this is related to plugins. Someone entered links into one of the php files and I don't know which..

4css

2:49 pm on Jun 23, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



When someone enters links to your blog through your software somehow, they are spamming it. Plus everyone that runs a blog will understand without your links provided.

If you view your plugins for your blog you will find something that will help you to keep this from happening. Each blog has their own plugin for this.

If you do a google on spaming blogs, you'll find a ton of information regarding this subject.

I would also be a bit concerned about the safety on your host, or how your files are set up. If someone can get into your files, something isn't right.

I'm sure that someone here can help you to remove what is there now if you don't know how to remove them.

edited by 4css entering different text

Fernando

3:02 pm on Jun 23, 2008 (gmt 0)

10+ Year Member



I looked at most of my php files in my theme folder but couldn't find it. Hope someone can help me locate them..

jatar_k

3:06 pm on Jun 23, 2008 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



what software does your blog use?

where does the footer content come from?

it could be right in your database somewhere, if your blog uses one.

Fernando

8:46 am on Jun 24, 2008 (gmt 0)

10+ Year Member



It uses wordpress and content comes from my database. I searched my database and wordpress theme folders for the spam words but they dont show up. Maybe it is hidden as javascript code? This sucks big time.

Rosalind

9:58 am on Jun 24, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Wordpress versions before 2.5.1 have a vulnerability. You need to upgrade to the latest version if you haven't already done so.

Fernando

10:02 am on Jun 24, 2008 (gmt 0)

10+ Year Member



I tried that yesterday and messed up my blog completely. For some reason, the widgets didn't work and error messages on top appeared. I spent 6 hours trying to restore it and it is finally back to normal. Even with the upgrade, I still need to find this spam code inserted somewhere in my blog..

phranque

12:10 pm on Jun 24, 2008 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



welcome to WebmasterWorld [webmasterworld.com], Fernando!

you might want to check out this CMS Forum thread about securing wordpress [webmasterworld.com]