your website is compromised
-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
your website is compromised
http://www.vagtechnik.co.za/
view-source:http://www.vagtechnik.co.za/ <- copypasta in your browser
Top left corner: http://co09778.wix.com/bet365 <- link in which spammers uses to funnel traffic through.
open the website: top right corner is the link
Update the CMS to the latest and i think one of your plugins might be the hole.
Alternatively check users and go in editor and remove the code.
cheers
view-source:http://www.vagtechnik.co.za/ <- copypasta in your browser
Top left corner: http://co09778.wix.com/bet365 <- link in which spammers uses to funnel traffic through.
open the website: top right corner is the link
Update the CMS to the latest and i think one of your plugins might be the hole.
Alternatively check users and go in editor and remove the code.
cheers
Thupercharged S4
- Sinbad
- Post Whore
- Posts: 20514
- Registered for: 17 years 8 months
- Car Make: Mercedes
- Car Model: R170 AMG Hairdryer
- Membership No: 1152
Re: your website is compromised
Have mailed this to them as well. Thanks for pointing it out 

-
- VAG Cafe
- Posts: 19036
- Registered for: 20 years 5 months
- Car Make: Audi
- Car Model: RS3
- Membership No: 675
- Location: Centurion
- Contact:
-
- Cadet
- Posts: 451
- Registered for: 19 years 5 months
- Membership No: 1106
- Location: PTA
Re: your website is compromised
Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.
Once again thanks for the assistance
Once again thanks for the assistance

Scirocco
13.5 Dragwars Tarlton 2011
Golf V Gti
14.1 Dragwars Tarlton 2010
ex Golf IV 132kw
14.8 @157kph Tarlton 2007
-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
Re: your website is compromised
i can still see it there...yes i have cleared my cache [NooB]sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.
Once again thanks for the assistance
others might confirm...

Thupercharged S4
-
- Cadet
- Posts: 158
- Registered for: 12 years 10 months
Re: your website is compromised
Confirmedyakuza racer wrote:i can still see it there...yes i have cleared my cache [NooB]sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.
Once again thanks for the assistance
others might confirm...

-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
Re: your website is compromised
its in your theme....
go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)
edit:
this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>
go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)
edit:
this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>
Thupercharged S4
- Black&White
- Lieutenant
- Posts: 1250
- Registered for: 15 years 6 months
- Car Make: VW
- Car Model: 7R
- Membership No: 1863
- Location: Vaaltriangle
Re: your website is compromised
I'm in here and it feels like aliens are trying to contact me
(noob I)



'15 Golf 7R
'13 6R CrossPolo TDI (Sold)
Polo 2.Slow (Sold)
'03 citi life 1.6 ( stolen & retrieved then sold)
'86 mk1 2door CTI (sold)
- Stompie
- Boostleak Guru
- Posts: 20203
- Registered for: 14 years
- Car Make: BMW
- Car Model: 2006 120D
- Membership No: 1843
- Location: East Rand
Re: your website is compromised
+1Black&White wrote:I'm in here and it feels like aliens are trying to contact me![]()
(noob I)

-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
-
- Cadet
- Posts: 451
- Registered for: 19 years 5 months
- Membership No: 1106
- Location: PTA
Re: your website is compromised
nothing much changed but I don't see it anymore checked myself now.

Scirocco
13.5 Dragwars Tarlton 2011
Golf V Gti
14.1 Dragwars Tarlton 2010
ex Golf IV 132kw
14.8 @157kph Tarlton 2007
- Sparkz0629
- Captain
- Posts: 2987
- Registered for: 14 years 1 month
- Car Make: VW
- Car Model: 2012 Polo GTI
- Membership No: 1768
- Location: Jhb
- Contact:
Re: your website is compromised
Nope. definitely still there. top left corner.
Current: 2012 Reflex Silver 6R Polo GTI
[url=http://www.vwclub.co.za/phpbb3/viewtopi ... ead#unread]
Ex Rides:
2006 1.9TDi Sportline - 158.7Hp & 413Nm at K.A.R 19-05-2012
[url=http://www.vwclub.co.za/phpbb3/viewtopi ... ead#unread]
Ex Rides:
2006 1.9TDi Sportline - 158.7Hp & 413Nm at K.A.R 19-05-2012
VWicked wrote: I could do 300km/h if I wanted but I don't trust my brakes stopping from that speed so as soon as i hit exactly 241km/h on my garmin i will tap off, generally it takes me me 6.9 sec to get there so I will just cruise the last 5 sec's to allow the car to cool down..
-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
Re: your website is compromised
sugen wrote:nothing much changed but I don't see it anymore checked myself now.
yakuza racer wrote:its in your theme....
go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)
edit:
this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>
Thupercharged S4
- MeanTdi
- The Imposer Mod-whore-rator
- Posts: 18554
- Registered for: 19 years 4 months
- Car Make: Subaru
- Car Model: WRX
- Membership No: 1153
- Location: JHB
Re: your website is compromised
Checked from another device - still there.
Marco
Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v
Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v
ALFAHOLIC wrote:What can go wrong, jarre you guys sound like you are describing an Alfa here...
My Corsa OPC wrote:Its not an oil leak, its just an Opel marking its territory
-
- Cadet
- Posts: 968
- Registered for: 14 years 1 month
- Membership No: missing
Re: your website is compromised
It's in your CSS stylesheet file gents:
innerHTML: "<a href="http://co09778.wix.com/bet365">http://c ... /bet365</a>"
innerText: "http://co09778.wix.com/bet365"
isContentEditable: false
to be more specific, it's linked to <p></p>
innerHTML: "<a href="http://co09778.wix.com/bet365">http://c ... /bet365</a>"
innerText: "http://co09778.wix.com/bet365"
isContentEditable: false
to be more specific, it's linked to <p></p>
'11 MK6 GTi DSG - Unitronic 2+
-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...
Re: your website is compromised
still not resolved and is now showing another link....
Thupercharged S4
-
- VAG Cafe
- Posts: 19036
- Registered for: 20 years 5 months
- Car Make: Audi
- Car Model: RS3
- Membership No: 675
- Location: Centurion
- Contact:
Re: your website is compromised
I have asked Sugen to contact the dude thats busy with our site. Hopefully that will be fixed soon.
-
- Enlisted
- Posts: 1
- Registered for: 11 years 10 months
Re: your website is compromised
The link is caused by a malicious WordPress plugin downloaded directly from wordpress.org. The attacker just keeps creating new plugins after they get banned. However, if you use any of the following plugins;
seo-cheese
g-translate (note the hyphen - other versions are fine)
seo-interlinking
return-to-top
google-maps-by-daniel-martyn
I would strongly recommend they should be removed immediately as they are all operated by the same hacker and insert these dodgy links to the top of your page. If not - I would love to know which plugins you have so I can investigate and report the malicious plugin to wordpress.org.
Useful reading for information about the same attack
http://wordpress.org/support/topic/strange-link-to-casino-online-appeared-at-the-top-of-my-blog
http://wordpress.org/support/topic/random-casino-link-has-appeared-on-my-wordpress-site
http://www.techyduck.com/web-design-developments/wordpress-site-hacked-showing-httponline-casino-blog-ca-in-header/
Malicious code (this is normally found in plugin directory -> setup.php or install.php)
Sites that are linked to the same hacker
The following sites are linked to the same hacker and listing them here will hopefully help other people who have the same issue.
bet.sitonline.it/
co09778.wix.com/
honline-casino.en.softonic.com/
online-casino.blog.ca/
online-casino.us.org/
onlinecasino-games.com/online-roulette/
onlinecasino-games.com/
http://www.bettingwebs.co.uk/
http://www.concierto92uno.com/
http://www.games-casino.us/
http://www.happy-wheels.me/
http://www.templatewordpress.org/bet365-uk/
http://www.tumeplaiscoco.com/
http://www.bingo-sites.org.uk
skybet.webeden.co.uk
betfree.oneminutesite.it
http://bet365.bestonlinecasino.pw
bonus.uk.net
Other information about this hack
The trick works well because as you have found, the link itself is not visible to the site owner as firstly, it doesn't show if you are logged in to your own site, and secondly it also keeps a log of all past IP addresses that successfully logged in before and hides the link (read source code above for details on this).
Hack prevention
Be very cautious of new plugins on wordpress.org as it seems they are not adequately checked (perhaps initially but the plugin creator can easily modify the code with new versions). Trust only plugins that have more popularity and read though the comments and ratings.
If you think you have this issue on your site, a very quick way to find out is to try running you site in safe mode to temporarily disable plugins (just add '?safe_mode=1' to your URL while logged in).
seo-cheese
g-translate (note the hyphen - other versions are fine)
seo-interlinking
return-to-top
google-maps-by-daniel-martyn
I would strongly recommend they should be removed immediately as they are all operated by the same hacker and insert these dodgy links to the top of your page. If not - I would love to know which plugins you have so I can investigate and report the malicious plugin to wordpress.org.
Useful reading for information about the same attack
http://wordpress.org/support/topic/strange-link-to-casino-online-appeared-at-the-top-of-my-blog
http://wordpress.org/support/topic/random-casino-link-has-appeared-on-my-wordpress-site
http://www.techyduck.com/web-design-developments/wordpress-site-hacked-showing-httponline-casino-blog-ca-in-header/
Malicious code (this is normally found in plugin directory -> setup.php or install.php)
Code: Select all
<?php
if (is_user_logged_in()) { $loggedin = 'yes'; } else { $loggedin = 'no'; }
if ($loggedin == 'no') {
$ip = $_SERVER['REMOTE_ADDR'];
$filename = $_SERVER['DOCUMENT_ROOT'] . '/wp-content/plugins/seo-cheese/created.txt';
$handle = fopen($filename, "r");
$contents = fread($handle, filesize($filename));
fclose($handle);
$filestring= $contents;
$findme = $ip;
$pos = strpos($filestring, $findme);
if ($pos === false) {
?>
<p align="center"><a href="http://online-casino.blog.ca">http://online-casino.blog.ca</a></p>
<?php //
} else {
echo '';
}}
?>
The following sites are linked to the same hacker and listing them here will hopefully help other people who have the same issue.
bet.sitonline.it/
co09778.wix.com/
honline-casino.en.softonic.com/
online-casino.blog.ca/
online-casino.us.org/
onlinecasino-games.com/online-roulette/
onlinecasino-games.com/
http://www.bettingwebs.co.uk/
http://www.concierto92uno.com/
http://www.games-casino.us/
http://www.happy-wheels.me/
http://www.templatewordpress.org/bet365-uk/
http://www.tumeplaiscoco.com/
http://www.bingo-sites.org.uk
skybet.webeden.co.uk
betfree.oneminutesite.it
http://bet365.bestonlinecasino.pw
bonus.uk.net
Other information about this hack
The trick works well because as you have found, the link itself is not visible to the site owner as firstly, it doesn't show if you are logged in to your own site, and secondly it also keeps a log of all past IP addresses that successfully logged in before and hides the link (read source code above for details on this).
Hack prevention
Be very cautious of new plugins on wordpress.org as it seems they are not adequately checked (perhaps initially but the plugin creator can easily modify the code with new versions). Trust only plugins that have more popularity and read though the comments and ratings.
If you think you have this issue on your site, a very quick way to find out is to try running you site in safe mode to temporarily disable plugins (just add '?safe_mode=1' to your URL while logged in).
- MeanTdi
- The Imposer Mod-whore-rator
- Posts: 18554
- Registered for: 19 years 4 months
- Car Make: Subaru
- Car Model: WRX
- Membership No: 1153
- Location: JHB
Re: your website is compromised
Give this man a Bells! 

Marco
Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v
Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v
ALFAHOLIC wrote:What can go wrong, jarre you guys sound like you are describing an Alfa here...
My Corsa OPC wrote:Its not an oil leak, its just an Opel marking its territory
-
- Post Whore
- Posts: 19397
- Registered for: 18 years 3 months
- Car Model: boat
- Membership No: 1133
- Location: Lenasia
- Contact:
-
- Voora Molester
- Posts: 12474
- Registered for: 14 years 11 months
- Car Make: VW
- Membership No: missing
- Location: Jou Ma Se...