your website is compromised

For all your REVO software requirements
Post Reply
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

your website is compromised

Post by Yakuza Racer »

http://www.vagtechnik.co.za/
view-source:http://www.vagtechnik.co.za/ <- copypasta in your browser

Top left corner: http://co09778.wix.com/bet365 <- link in which spammers uses to funnel traffic through.

open the website: top right corner is the link

Update the CMS to the latest and i think one of your plugins might be the hole.
Alternatively check users and go in editor and remove the code.

cheers
Thupercharged S4
User avatar
Sinbad
Post Whore
Posts: 20514
Registered for: 17 years 8 months
Car Make: Mercedes
Car Model: R170 AMG Hairdryer
Membership No: 1152

Re: your website is compromised

Post by Sinbad »

Have mailed this to them as well. Thanks for pointing it out :)
Image

Image
katotter wrote:Geezus, I wanna be his girfriend.
Rabbit222
VAG Cafe
Posts: 19036
Registered for: 20 years 5 months
Car Make: Audi
Car Model: RS3
Membership No: 675
Location: Centurion
Contact:

Re: your website is compromised

Post by Rabbit222 »

Thanks guys :)
sugen
Cadet
Posts: 451
Registered for: 19 years 5 months
Membership No: 1106
Location: PTA

Re: your website is compromised

Post by sugen »

Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance
Image

Scirocco
13.5 Dragwars Tarlton 2011
Golf V Gti
14.1 Dragwars Tarlton 2010
ex Golf IV 132kw
14.8 @157kph Tarlton 2007
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance
i can still see it there...yes i have cleared my cache [NooB]

others might confirm...
Image
Thupercharged S4
JuST170
Cadet
Posts: 158
Registered for: 12 years 10 months

Re: your website is compromised

Post by JuST170 »

yakuza racer wrote:
sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance
i can still see it there...yes i have cleared my cache [NooB]

others might confirm...
Image
Confirmed
Image
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

its in your theme....

go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)

edit:

this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>
Thupercharged S4
User avatar
Black&White
Lieutenant
Posts: 1250
Registered for: 15 years 6 months
Car Make: VW
Car Model: 7R
Membership No: 1863
Location: Vaaltriangle

Re: your website is compromised

Post by Black&White »

I'm in here and it feels like aliens are trying to contact me :troll: :lol: (noob I)
Image
'15 Golf 7R
'13 6R CrossPolo TDI (Sold)
Polo 2.Slow (Sold)
'03 citi life 1.6 ( stolen & retrieved then sold)
'86 mk1 2door CTI (sold)
User avatar
Stompie
Boostleak Guru
Posts: 20203
Registered for: 14 years
Car Make: BMW
Car Model: 2006 120D
Membership No: 1843
Location: East Rand

Re: your website is compromised

Post by Stompie »

Black&White wrote:I'm in here and it feels like aliens are trying to contact me :troll: :lol: (noob I)
+1 :twisted:
Image
BMW 120D E87
Ex: 07' Polo GTI 1.8T Rides Thread Here
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

im out soon, if you need help shoot me a PM....
Thupercharged S4
sugen
Cadet
Posts: 451
Registered for: 19 years 5 months
Membership No: 1106
Location: PTA

Re: your website is compromised

Post by sugen »

nothing much changed but I don't see it anymore checked myself now.
Image

Scirocco
13.5 Dragwars Tarlton 2011
Golf V Gti
14.1 Dragwars Tarlton 2010
ex Golf IV 132kw
14.8 @157kph Tarlton 2007
User avatar
Sparkz0629
Captain
Posts: 2987
Registered for: 14 years 1 month
Car Make: VW
Car Model: 2012 Polo GTI
Membership No: 1768
Location: Jhb
Contact:

Re: your website is compromised

Post by Sparkz0629 »

Nope. definitely still there. top left corner.
Current: 2012 Reflex Silver 6R Polo GTI
[url=http://www.vwclub.co.za/phpbb3/viewtopi ... ead#unread]
Ex Rides:
2006 1.9TDi Sportline - 158.7Hp & 413Nm at K.A.R 19-05-2012
VWicked wrote: I could do 300km/h if I wanted but I don't trust my brakes stopping from that speed so as soon as i hit exactly 241km/h on my garmin i will tap off, generally it takes me me 6.9 sec to get there so I will just cruise the last 5 sec's to allow the car to cool down..
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

sugen wrote:nothing much changed but I don't see it anymore checked myself now.
yakuza racer wrote:its in your theme....

go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)

edit:

this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>
Thupercharged S4
User avatar
MeanTdi
The Imposer Mod-whore-rator
Posts: 18554
Registered for: 19 years 4 months
Car Make: Subaru
Car Model: WRX
Membership No: 1153
Location: JHB

Re: your website is compromised

Post by MeanTdi »

Checked from another device - still there.
Marco


Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v


ALFAHOLIC wrote:What can go wrong, jarre you guys sound like you are describing an Alfa here...
My Corsa OPC wrote:Its not an oil leak, its just an Opel marking its territory :lol:
NeoSA
Cadet
Posts: 968
Registered for: 14 years 1 month
Membership No: missing

Re: your website is compromised

Post by NeoSA »

It's in your CSS stylesheet file gents:

innerHTML: "<a href="http://co09778.wix.com/bet365">http://c ... /bet365</a>"
innerText: "http://co09778.wix.com/bet365"
isContentEditable: false

to be more specific, it's linked to <p></p>
'11 MK6 GTi DSG - Unitronic 2+
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

still not resolved and is now showing another link....
Thupercharged S4
Rabbit222
VAG Cafe
Posts: 19036
Registered for: 20 years 5 months
Car Make: Audi
Car Model: RS3
Membership No: 675
Location: Centurion
Contact:

Re: your website is compromised

Post by Rabbit222 »

I have asked Sugen to contact the dude thats busy with our site. Hopefully that will be fixed soon.
markieee7
Enlisted
Posts: 1
Registered for: 11 years 10 months

Re: your website is compromised

Post by markieee7 »

The link is caused by a malicious WordPress plugin downloaded directly from wordpress.org. The attacker just keeps creating new plugins after they get banned. However, if you use any of the following plugins;

seo-cheese
g-translate (note the hyphen - other versions are fine)
seo-interlinking
return-to-top
google-maps-by-daniel-martyn

I would strongly recommend they should be removed immediately as they are all operated by the same hacker and insert these dodgy links to the top of your page. If not - I would love to know which plugins you have so I can investigate and report the malicious plugin to wordpress.org.

Useful reading for information about the same attack

http://wordpress.org/support/topic/strange-link-to-casino-online-appeared-at-the-top-of-my-blog
http://wordpress.org/support/topic/random-casino-link-has-appeared-on-my-wordpress-site
http://www.techyduck.com/web-design-developments/wordpress-site-hacked-showing-httponline-casino-blog-ca-in-header/

Malicious code (this is normally found in plugin directory -> setup.php or install.php)

Code: Select all

<?php
if (is_user_logged_in()) { $loggedin = 'yes'; } else { $loggedin = 'no'; }
if ($loggedin == 'no') {
$ip = $_SERVER['REMOTE_ADDR'];
$filename = $_SERVER['DOCUMENT_ROOT'] . '/wp-content/plugins/seo-cheese/created.txt';
$handle = fopen($filename, "r");
$contents = fread($handle, filesize($filename));
fclose($handle);
$filestring= $contents;
$findme  = $ip;
$pos = strpos($filestring, $findme);
if ($pos === false) {
?>
<p align="center"><a href="http://online-casino.blog.ca">http://online-casino.blog.ca</a></p>
<?php //
} else {
echo '';
}}
?>
Sites that are linked to the same hacker

The following sites are linked to the same hacker and listing them here will hopefully help other people who have the same issue.

bet.sitonline.it/
co09778.wix.com/
honline-casino.en.softonic.com/
online-casino.blog.ca/
online-casino.us.org/
onlinecasino-games.com/online-roulette/
onlinecasino-games.com/
http://www.bettingwebs.co.uk/
http://www.concierto92uno.com/
http://www.games-casino.us/
http://www.happy-wheels.me/
http://www.templatewordpress.org/bet365-uk/
http://www.tumeplaiscoco.com/
http://www.bingo-sites.org.uk
skybet.webeden.co.uk
betfree.oneminutesite.it
http://bet365.bestonlinecasino.pw
bonus.uk.net

Other information about this hack

The trick works well because as you have found, the link itself is not visible to the site owner as firstly, it doesn't show if you are logged in to your own site, and secondly it also keeps a log of all past IP addresses that successfully logged in before and hides the link (read source code above for details on this).

Hack prevention

Be very cautious of new plugins on wordpress.org as it seems they are not adequately checked (perhaps initially but the plugin creator can easily modify the code with new versions). Trust only plugins that have more popularity and read though the comments and ratings.

If you think you have this issue on your site, a very quick way to find out is to try running you site in safe mode to temporarily disable plugins (just add '?safe_mode=1' to your URL while logged in).
User avatar
MeanTdi
The Imposer Mod-whore-rator
Posts: 18554
Registered for: 19 years 4 months
Car Make: Subaru
Car Model: WRX
Membership No: 1153
Location: JHB

Re: your website is compromised

Post by MeanTdi »

Give this man a Bells! :hurray:
Marco


Current: Subaru WRX
Ex: VW Polo 1.9 TDI Sportline
Ex: VW Golf VR6
Ex: VW Golf 1.8 GTi 16v


ALFAHOLIC wrote:What can go wrong, jarre you guys sound like you are describing an Alfa here...
My Corsa OPC wrote:Its not an oil leak, its just an Opel marking its territory :lol:
dood786
Post Whore
Posts: 19397
Registered for: 18 years 3 months
Car Model: boat
Membership No: 1133
Location: Lenasia
Contact:

Re: your website is compromised

Post by dood786 »

Its a spam bot by the looks of it
Noob
Yakuza Racer
Voora Molester
Posts: 12474
Registered for: 14 years 11 months
Car Make: VW
Membership No: missing
Location: Jou Ma Se...

Re: your website is compromised

Post by Yakuza Racer »

bump...

site is still in its dinges
Thupercharged S4
Post Reply