jammer(six)

much ado about something…

Apparently the WordPress search redirect hack that I reported on the other day is fairly widespread. Moreover, it’s been taking down sites running WordPress installs as late as ver. 2.5.1, so upgrading won’t necessarily protect you (example).

sidebar: According to Donncha, 2.5.x is not vulnerable to this, but I’ve personally seen a number of 2.5.x sites that are afflicted. One commonality is that many (all?) of these sites are on DreamHost. I wonder if the hackers have somehow compromised DreamHost, and are attacking the 2.5.x installs from the inside (?). Or perhaps they were compromised before upgrading. Just musing — no evidence of that so far. /sidebar

While the nefarious code was, in my case, included in index.php, others are reporting that it may involve a corrupted image file set in the wp_options database table to act as a plugin.

Here are some related articles on the topic: link, link, link

Some DigitalPoint threads: link, link

And some WordPress support threads: link, link

And, finally, video on fixing the problem if you have the plugin version: link

(Thanks to Patrick for the video link.)

It’s still unclear how the affected sites were compromised.

To find out if you’re affected:

Clear cookies, run a Google search for your site, and then click through. If you wind up at your site you’re probably okay. If it redirects to (or through) anyresults.net, then you’ve been hacked. If I were you, I’d try this a couple of times as the cookie that hides the hack seems to stick in some browsers.

Update: Be sure to read the GRS post about getting rid of this thing. I just discovered that I had an extraneous user created at 00:00:00 on 0000-00-00. Unlike JD, however, I haven’t discovered any other database changes — perhaps because I was running an older version of WP (2.3.3) which was easier to take down (?).

Posted by nickel on Saturday, June 7th, 2008

7 Responses to “More Info on the WordPress AnyResults.net Hack for Hijacking Search Traffic” Add your own

Post A Comment

    Recent Articles From FiveCentNickel

    - Bank of America Online Banking Annoyance
    - 0% Balance Transfer Offers With No Tr...
    - Understanding the Licenses, Certifica...
    - Guest Post: Using an Allowance to Tea...
    - NCUA Insurance Coverage: Protecting Y...
    - Weekly Roundup - Credit Addict Faceli...
    - $25 FNBO Direct Online Billpay Promotion
    - Is Your Credit Union Safe?
    - A Peek Inside Our FNBO Direct Online ...
    - Qualifying for an FHA Home Loan

    Recent Articles From Credit Addict

    - Using 0% Balance Transfers to Dig You...
    - $50 Signup Bonus From Discover More Card
    - List of Frequent Flyer Credit Cards W...
    - No Fee 0% Balance Transfer Credit Car...
    - Earning Credit Card Miles in Unusual ...
    - Free Amazon Prime Trial Membership
    - Millions of Credit Card Numbers Compr...
    - Kiva Philanthropic Reward Credit Card
    - Frozen Credit and Using Debit Cards t...
    - Buying Cash With a Credit Card

    Recent Articles From Raising4Boys

    - Updating our Allowance System
    - The Boys of Summer Have Gone
    - Free Movie Tickets From Discover/Fand...
    - Books for Teaching Kids About Puberty...
    - Summer Movie Ratings (So Far…)
    - Happy Father’s Day!
    - How to Get Rid of Ants
    - Babies, Birth Control, and Too Much TV
    - Free Summer Movies for Kids - 2008 Ed...
    - Carnivals - Week of 05/19/08