Page 1 of 1

your website is compromised

Posted: Thu Aug 15, 2013 2:37 pm
by Yakuza Racer
http://www.vagtechnik.co.za/
view-source:http://www.vagtechnik.co.za/ <- copypasta in your browser

Top left corner: http://co09778.wix.com/bet365 <- link in which spammers uses to funnel traffic through.

open the website: top right corner is the link

Update the CMS to the latest and i think one of your plugins might be the hole.
Alternatively check users and go in editor and remove the code.

cheers

Re: your website is compromised

Posted: Thu Aug 15, 2013 2:42 pm
by Sinbad
Have mailed this to them as well. Thanks for pointing it out :)

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:17 pm
by Rabbit222
Thanks guys :)

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:38 pm
by sugen
Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:50 pm
by Yakuza Racer
sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance
i can still see it there...yes i have cleared my cache [NooB]

others might confirm...
Image

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:52 pm
by JuST170
yakuza racer wrote:
sugen wrote:Thanks gents looks like it was a simple injection attack. We have cleaned it up, can you please re-visit our site and let us know if you pick anything else up.

Once again thanks for the assistance
i can still see it there...yes i have cleared my cache [NooB]

others might confirm...
Image
Confirmed

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:56 pm
by Yakuza Racer
its in your theme....

go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)

edit:

this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>

Re: your website is compromised

Posted: Thu Aug 15, 2013 3:59 pm
by Black&White
I'm in here and it feels like aliens are trying to contact me :troll: :lol: (noob I)

Re: your website is compromised

Posted: Thu Aug 15, 2013 4:04 pm
by Stompie
Black&White wrote:I'm in here and it feels like aliens are trying to contact me :troll: :lol: (noob I)
+1 :twisted:

Re: your website is compromised

Posted: Thu Aug 15, 2013 4:13 pm
by Yakuza Racer
im out soon, if you need help shoot me a PM....

Re: your website is compromised

Posted: Thu Aug 15, 2013 4:54 pm
by sugen
nothing much changed but I don't see it anymore checked myself now.

Re: your website is compromised

Posted: Thu Aug 15, 2013 5:37 pm
by Sparkz0629
Nope. definitely still there. top left corner.

Re: your website is compromised

Posted: Thu Aug 15, 2013 6:31 pm
by Yakuza Racer
sugen wrote:nothing much changed but I don't see it anymore checked myself now.
yakuza racer wrote:its in your theme....

go into editor and go to header.php - control + f and find the code and delete it
also check in the other files in the editor (located on the APPEARANCE dropdown)

edit:

this code: <p align="left"><a href="http://co09778.wix.com/bet365">http://c ... 365</a></p>

Re: your website is compromised

Posted: Thu Aug 15, 2013 9:18 pm
by MeanTdi
Checked from another device - still there.

Re: your website is compromised

Posted: Thu Aug 15, 2013 10:14 pm
by NeoSA
It's in your CSS stylesheet file gents:

innerHTML: "<a href="http://co09778.wix.com/bet365">http://c ... /bet365</a>"
innerText: "http://co09778.wix.com/bet365"
isContentEditable: false

to be more specific, it's linked to <p></p>

Re: your website is compromised

Posted: Wed Aug 21, 2013 7:46 am
by Yakuza Racer
still not resolved and is now showing another link....

Re: your website is compromised

Posted: Thu Aug 22, 2013 9:02 am
by Rabbit222
I have asked Sugen to contact the dude thats busy with our site. Hopefully that will be fixed soon.

Re: your website is compromised

Posted: Wed Aug 28, 2013 4:08 pm
by markieee7
The link is caused by a malicious WordPress plugin downloaded directly from wordpress.org. The attacker just keeps creating new plugins after they get banned. However, if you use any of the following plugins;

seo-cheese
g-translate (note the hyphen - other versions are fine)
seo-interlinking
return-to-top
google-maps-by-daniel-martyn

I would strongly recommend they should be removed immediately as they are all operated by the same hacker and insert these dodgy links to the top of your page. If not - I would love to know which plugins you have so I can investigate and report the malicious plugin to wordpress.org.

Useful reading for information about the same attack

http://wordpress.org/support/topic/strange-link-to-casino-online-appeared-at-the-top-of-my-blog
http://wordpress.org/support/topic/random-casino-link-has-appeared-on-my-wordpress-site
http://www.techyduck.com/web-design-developments/wordpress-site-hacked-showing-httponline-casino-blog-ca-in-header/

Malicious code (this is normally found in plugin directory -> setup.php or install.php)

Code: Select all

<?php
if (is_user_logged_in()) { $loggedin = 'yes'; } else { $loggedin = 'no'; }
if ($loggedin == 'no') {
$ip = $_SERVER['REMOTE_ADDR'];
$filename = $_SERVER['DOCUMENT_ROOT'] . '/wp-content/plugins/seo-cheese/created.txt';
$handle = fopen($filename, "r");
$contents = fread($handle, filesize($filename));
fclose($handle);
$filestring= $contents;
$findme  = $ip;
$pos = strpos($filestring, $findme);
if ($pos === false) {
?>
<p align="center"><a href="http://online-casino.blog.ca">http://online-casino.blog.ca</a></p>
<?php //
} else {
echo '';
}}
?>
Sites that are linked to the same hacker

The following sites are linked to the same hacker and listing them here will hopefully help other people who have the same issue.

bet.sitonline.it/
co09778.wix.com/
honline-casino.en.softonic.com/
online-casino.blog.ca/
online-casino.us.org/
onlinecasino-games.com/online-roulette/
onlinecasino-games.com/
http://www.bettingwebs.co.uk/
http://www.concierto92uno.com/
http://www.games-casino.us/
http://www.happy-wheels.me/
http://www.templatewordpress.org/bet365-uk/
http://www.tumeplaiscoco.com/
http://www.bingo-sites.org.uk
skybet.webeden.co.uk
betfree.oneminutesite.it
http://bet365.bestonlinecasino.pw
bonus.uk.net

Other information about this hack

The trick works well because as you have found, the link itself is not visible to the site owner as firstly, it doesn't show if you are logged in to your own site, and secondly it also keeps a log of all past IP addresses that successfully logged in before and hides the link (read source code above for details on this).

Hack prevention

Be very cautious of new plugins on wordpress.org as it seems they are not adequately checked (perhaps initially but the plugin creator can easily modify the code with new versions). Trust only plugins that have more popularity and read though the comments and ratings.

If you think you have this issue on your site, a very quick way to find out is to try running you site in safe mode to temporarily disable plugins (just add '?safe_mode=1' to your URL while logged in).

Re: your website is compromised

Posted: Wed Aug 28, 2013 8:30 pm
by MeanTdi
Give this man a Bells! :hurray:

Re: your website is compromised

Posted: Thu Aug 29, 2013 8:35 am
by dood786
Its a spam bot by the looks of it

Re: your website is compromised

Posted: Mon Oct 07, 2013 8:18 pm
by Yakuza Racer
bump...

site is still in its dinges