As Activerain'ers know, a web presence is the future. The future does not live in Mordor, protected by Orcs and scary creatures of the dea, but in the real life. As the we all blog are hearts out, work endlessly to give our consumers the greatest presence online there is a evil lurking that is out to destroy us all. No it's not Sauron and his minions but other online users seek to destroy a good that we all cherish.

Today I found out that my marketing website, along with friend's sites, have been compromised. The hack inserted footer links into the website. Retailers of Calais, Viagra and all that trash were now at the bottom of the homepage. The links erorred the credibility and integrity of the site. It's not a power house per say but it did do some good localized traffic.

As online marketers (every ActiveRainers is one) it is imperative that hackers do not infiltrate the purity of a trusted and established website. I took some actions and ran some tests (link is my other blog) and if you are running a Wordpress blogsite then you may wanna check it out the cached text of your site. The tool easily shows the bogus links.

This is not limited to sites running older versions of WP. My marketing website is running the latest version and it was still on it. Check it out!!

 
Post is included in group: Blogging & SEO

11 Comments on Don't get your website hacked

SEP
15
2008
279,959 Points 15 Featured Posts Outside Blog

Worth looking into. Have not seen you in a long while.

10:10pm • #1
136,447 Points 17 Featured Posts Outside Blog

Hola Eric, it has been awhile but seen your websites on Facebook :)

Hi Karen, I am anxious to see if other bloggers are talking abou tthis. If you find drop us a link.

10:17pm • #3
261,746 Points 26 Featured Posts Outside Blog

My wordpress blog was hacked this winter - it took us months to find the links - it was a nightmare - stoping this is a good thing

10:17pm • #4
208,471 Points 7 Featured Posts Outside Blog

I know quite a bit about this subject.

One they wouldnt bother unless it was an easily compromised "hack" or security hole.

Something not necessarily WP wasnt up to date because "hackers" dont just spend countless hours trying to compromise a site. They go after easy targets. Usually this type of stuff is a patch that just was not implemented. It could be on the server level I dont know where the leak is but thats most likely the case.

Two I would hope that is the case because they are not necessarily targeting just your site. Most likely they are sniffing out sites near them that might all have the same hole. If this is not the case then you might be looking at a whole other set of issues.

Thirdly they really arent trying to trash you personally they are exploiting a known security gap. Unfortunately there is no real cure for this. Anyone who has a lot of bandwith is a target because you have a lot of bandwith. It might not have even been a targeted attack and might have well been an attack that was sent out in the form of a worm or virus. Again I dont know but most likely they did not attack you personally it just seems that way.

Fourth Unfortunately since you are not a software developer you cant really do much about this except hope your host has preventive measures. The best thing you can hope for is that either they dont do it again, or you have a solid backup, or whoever owns the software you use removes the security leak or patches it.

Fifth Most likely this attack is quite old and is well known. Very few attackers are on the up and up when it comes to these sorts of attacks. They merely exploit people who dont update their software ( again I know you say WP is up to date but I dont think this has anything to do with WP itself) or just plain dont know any better. There is no cure to this problem unless you are entirely proactive and are a security expert. The only thing you can do is make sure you have a good backup and store that in a safe place and make sure your backup is always up to date.

I realize this is no solution other than making sure you backup but I am just trying to say how this type of this is usually performed and why. There is a lot of money in compromising peoples security.

Just thank god they didnt backdoor your computers. You would not want your pc a part of a botnet. You can wiki that if you want.. but trust me you are lucky. There are much worse things.

10:18pm • #5
208,471 Points 7 Featured Posts Outside Blog

Here is something to back up what I am saying.

I googled word press and back door.

http://www.webappsec.org/projects/whid/list_id_2007-08.shtml

http://www.sitepoint.com/blogs/2007/03/07/news-wire-cracker-adds-backdoor-to-wordpress/

That attack was in 2007 and you can see by reading that the software itself was compromised. Once software becomes populare it makes it a target.

wordpress backdoor 2008

http://newsworldwide.wordpress.com/2008/05/02/microsoft-discloses-government-backdoor-on-windows-operating-systems/  << thats just plain scary

http://www.keithgoodrum.com/can-somebody-drive-a-truck-through-the-back-door-of-your-wordpress-blog/ 

That one above there might add some insight into this. It really is about knowing security. I cant claim I am a WP expert I dont know anything about it. But in general terms.. be careful what you are doing out there.

Actually that last link I think describes what most likely happened to you.

5. Protect your wp-admin folder - This folder has some php files that are vulnerable. Just like the folders above you don't want anyone gaining access to this folder. There is a plugin called AskApache Password Protect. It adds a 2nd layer of security to your blog by requiring a username and password to access anything in the /wp-admin/ folder. You can get the plugin here: http://wordpress.org/extend/plugins/askapache-password-protect/#post-2892

6. Consider changing your login username - By default the username for the administrator is admin. If you are worried that someone might be able to crack your password, then changing the administrator username could stop them

I bet this is it.

10:22pm • #6

Toby, I hope Gimli takes them out at the knees with his axe!

10:24pm • #7
119,343 Points 2 Featured Posts Localism Sponsor Outside Blog

Toby.....I have had my website hacked and compromised a little over a year ago.  It was a pain to clean up.  thanks for the tips.

10:26pm • #8
231,655 Points 1 Featured Post Outside Blog

I am not a fan of hackers!!! Last year someone hacked my email addresss!  Took me a week to notify all customers of my new email ,etc!!

Thanks

Tom Davis

World Class DE Realtor

11:07pm • #9
SEP
16
2008
136,447 Points 17 Featured Posts Outside Blog

Hola everyone; thanks for the response. After double checking the WP version I found it wasnt currently running the version but 2.5. So far so good after remvoing it and going to have my IT buddy look through my pcs for trojans.

Shane thanks for the links and details. I doubt it was an intentional but still all the same it sucks.

10:11pm • #10
OCT
07
2008

Toby - really great post and good for you to make others aware of this issue.

2:07pm • #11

Leave a response…



(optional)
What does the graphic say?
 
Toby_009 Rainmaker_large

Toby Barnett

Marysville, WA

More about me…

Barnett Associates Real Estate, LLC

Address: 1704 Grove Street Unit # B, Marysville, WA, 98270

Office Phone: (360) 658-6077 x 28

Cell Phone: (425) 210-0709

Email Me

Welcome to my ActiveRain real estate blog and profile. I am the Business Development Manager for Barnett Associates Real Estate, LLC, a Snohomish County real estate firm located in Marysville, Washington. We are a family owned and operated business that has a team of professional REALTORSĀ® to help guide you through the sometimes stressful real estate transaction.


Links

Archives

RSS 2.0 Feed for this blog

Find WA real estate agents and Marysville real estate on ActiveRain.