{"id":1706,"date":"2009-08-22T22:36:57","date_gmt":"2009-08-23T03:36:57","guid":{"rendered":"http:\/\/www.very-simple.com\/blog\/?p=1706"},"modified":"2013-01-26T22:07:05","modified_gmt":"2013-01-27T03:07:05","slug":"i-was-hacked","status":"publish","type":"post","link":"http:\/\/www.very-simple.com\/blog\/2009\/08\/22\/i-was-hacked\/","title":{"rendered":"I was hacked!"},"content":{"rendered":"<div style=\"margin-top: 0px; margin-bottom: 0px;\" class=\"sharethis-inline-share-buttons\" ><\/div><p>I didn&#8217;t think this blog was popular enough to actually get hacked, but I was apparently wrong.<\/p>\n<p>Evidence the first &#8211; For some reason it was taking a really long time to load, even though I had cleaned out a lot of extraneous crap code recently.<\/p>\n<p>Evidence the second (and, really obvious) &#8211; I was going through the source code because I wanted to add a graphic to my header, and I was trying to find the right spot. In doing so, I noticed a bunch of weird links to external sites that I certainly hadn&#8217;t put in there.\u00a0Online pharmacies and whatnot.\u00a0So I went into the header file in wordpress, and found extraneous code pointing to a .ru site.\u00a0yeah.\u00a0Not so much evidence as, well, concrete proof.\u00a0I also did a google search for the code, and discovered that it appears on many other sites.<\/p>\n<p>I don&#8217;t know how it got seeded (perhaps through a plugin?), but the code to search for in your header.php file in wordpress is &#8220;alkoltashov (dot) narod (dot) ru \/ sites.txt&#8221;.\u00a0This apparently pulls in the multiple http addresses.<\/p>\n<p>I&#8217;m off to go search for more strange code to make sure my site is actually clean.\u00a0I&#8217;ll post an update if I find anything else.<\/p>\n<p><strong>Update:<\/strong> Found another one &#8211; in the footer.php file, somehow the link to demus design, which designed my template, got switched to &#8220;elavil lab&#8221;, with another link to an online pharmacy. And the link to wordpress.org linked to some third-party site rather than the real wordpress.\u00a0I&#8217;m off to change my password as well!<\/p>\n<p><strong>Update further:<\/strong> from a little searching online, it appears to be a vulnerability of wordpress 2.8.1, which is the latest version available by my hosting provider (although the latest available overall is 2.8.4).\u00a0looks like I&#8217;m going to have to keep a close eye on things until they upgrade further over at network solutions.\u00a0I also found a few other small things.\u00a0My only advice is to go through all of your template files and look for code that doesn&#8217;t belong.\u00a0This is so annoying.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I didn&#8217;t think this blog was popular enough to actually get hacked, but I was apparently wrong. Evidence the first &#8211; For some reason it was taking a really long time to load, even though I had cleaned out a lot of extraneous crap code recently. Evidence the second (and, really obvious) &#8211; I was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[],"tags":[8,3,7],"class_list":["post-1706","post","type-post","status-publish","format-standard","hentry","tag-blogging","tag-technology","tag-wordpress"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p6ZBi-rw","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/posts\/1706","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/comments?post=1706"}],"version-history":[{"count":6,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/posts\/1706\/revisions"}],"predecessor-version":[{"id":1708,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/posts\/1706\/revisions\/1708"}],"wp:attachment":[{"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/media?parent=1706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/categories?post=1706"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.very-simple.com\/blog\/wp-json\/wp\/v2\/tags?post=1706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}