Hacker News new | past | comments | ask | show | jobs | submit login

FWIW, I just visited your site and it contained some compressed JavaScript at the top and a broken link to http: // gsdgsd.freewww.biz/showthread.php?t=72881717 (slightly obfuscated to avoid accidential clicks). It was gone after a reload, so I can't give you any more information.



wow this is definitely a hint. The WPEngine guys are looking into it now.


Happened to seven WP sites I maintain. It's a script and someone got into an account. The script finds all .php and .htm files and adds stuff to the top. If you only have wordpress files, it's an easy fix - reset the password and get a different template.


What does the attack do for those who visited the site trying to figure out what was going on?


The malicious script only inserted an iframe with a broken link, so I wouldn't worry to much.


I would still worry a bit. Some hackers will show a broken link if you're accessing a page directly with no referrers, for example. But if you come in with a referrer or from a search engine, then they might return the malware payload.

If a site was showing up recently in our malware list, it's practically certain that an actual user downloaded malware via the site.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: