Live data from Hacker News

SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

blog.sucuri.net

1–10 of 18 posts

Re: SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

#3
i got hacked by something almost exactly like this like 3 months ago. They uploaded a folder called .files with about 2K html files there to each of my folders.

Probably a few million crap files all together. Was a huge pain in the ass to clear all that crap out. After that point I killed all wordpress installs, since it has such a huge target on it's back.

Re: SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

#5

Part of the problem is that a lot of security advisories basically say "run the latest version". Restricting access with .htaccess is a good idea; http://www.themepremium.com/wordpress-security-restrict-wp-c...

If you fail to upgrade immediately, malware is often installed and remains after an upgrade. I missed one site by a day and got infected. The default option to print the WP version in the of each blog would certainly lower the likelihood of a script finding an outdated site. Unfortunately once hacked, truly cleaning the site requires

1. Backing up theme, making list of plugins installed 2. Inspecting theme for any hacks. (difficult if you wrote your own) 3. Deleting _all_ files 4. Walking through the wp_options table for any leftover holes (very difficult) 5. Re-install WP 6. Re-install theme and plugins.

The WP team needs to work in something like you linked to into the core.

Re: SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

#8
post #3

i got hacked by something almost exactly like this like 3 months ago. They uploaded a folder called .files with about 2K html files there to each of my folders. Probably a few million crap files all together. Was a huge pain in the ass to clear all that crap out. After that point I killed all wordpress installs, since it has such a huge target on it's back.

This .files attack was common too. We posted about it a while ago:

http://blog.sucuri.net/2010/05/it-is-not-over-seo-spam-on-si...

Re: SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

#9
post #5

Part of the problem is that a lot of security advisories basically say "run the latest version". Restricting access with .htaccess is a good idea; http://www.themepremium.com/wordpress-security-restrict-wp-c...

If you fail to upgrade immediately, malware is often installed and remains after an upgrade. I missed one site by a day and got infected. The default option to print the WP version in the of each blog would certainly lower the likelihood of a script finding an outdated site. Unfortunately once hacked, truly cleaning the site requires 1. Backing up theme, making list of plugins installed 2. Inspecting theme for any ha…

I'm actively reviewing WordPress 3.0 beta for upgrade and plug-ins. Once I've got the .htaccess fix working in 3.0 beta I'll post the patch.

There are a few ideas I'm considering for securing and monitoring WP installations for intrusions.

Re: SEO SPAM network - Details of a mass attack (many .gov, .com and .edus hacked)

#10
post #8
post #3

i got hacked by something almost exactly like this like 3 months ago. They uploaded a folder called .files with about 2K html files there to each of my folders. Probably a few million crap files all together. Was a huge pain in the ass to clear all that crap out. After that point I killed all wordpress installs, since it has such a huge target on it's back.

This .files attack was common too. We posted about it a while ago: http://blog.sucuri.net/2010/05/it-is-not-over-seo-spam-on-si...

btw your blogsite is very scammy looking.

I got a message from my host with a link to your site, where you instructed to download and install a file...and I was 100% sure that it was just just a scam, where you sent out spam messages pretending to be hosts, with a link to the blog post where you were asking me to download malware.

In fact I was in the process of contacting customer support of my host, when I noticed the letter I got in recent history.

You should really spend a little time making it look more legitimate,

Post reply on HN