- This topic has 3 replies, 2 voices, and was last updated 16 years, 10 months ago by .
Viewing 4 posts - 1 through 4 (of 4 total)
Viewing 4 posts - 1 through 4 (of 4 total)
- You must be logged in to reply to this topic.
Home › Forums › Archives › Community Center › Forum Support › Bug Reports › Squashed Bugs › Staff Room › WordPress Hacked at BBB! Help!
Several times in the past week, the header template of the WordPress section of BBB has been hacked. They are adding some encrypted javascript which displays a long list of links in an hidden iframe. You may not notice anything different unless you view the source of any of the WordPress powered pages of the site.
I’m trying to track down the cause and see what I can do to resolve this. There are a LOT of WordPress sites getting hacked like this (try this Google search: “The TUBA Incision Site” wordpress – Google Search). I’m not sure how it’s happening, or how to stop it.
If anyone has any bright ideas, I’m all ears!
1 – Remove the Footer Credit
2 – Remove the Meta Generator Tag
3 – Remove the Generator Tag in the RSS Feed
4 – Remove Other Footprints
5 – Disabling Indexes
6 – Blocking Server-side Directories
7 – Hiding the Admin
8 – Move the Config Data
9 – Database Encoding
10 – File Permissions
I found the above information from this site(more info on the steps 1-10 is there).
Not sure if this will help…but it’s something I found.
Thanks for looking. I got it all fixed up last week. I had upgraded to the latest version (which protects against that exploit) but apparently the site was already “infected.” I had to delete all the files, do a fresh install of WordPress, reinstall the plugins, etc.
It’s all good now.
No problem, I’m just glad everything is better now. 🙂