As we figured out yesterday our Thai-Eyes Worldpress Blog
has been hacked by a hack,
which we call Magic Hack.
While we´ve been writing a new article
and wanted to save,
a login box, released by website “Magic” showed up.
We couldn´t login with our data.
We phoned a friend, who is quite good with coding work
and after a long research we´ve figured out,
that or blog has been hacked.
About 4-5 weeks ago our visitor numbers dropped by about 80%,
no google search queries at all, that´s possibly what the hack caused.

All in all, we can´t understand why insane people spreading viruses and
worms around the internet and why they hack websites.
In our opinion, this people should go to see a doctor at a mental hospital,
they seem to be very sick !

For us it was a 18 hour run to clear the problem
and for sure much, much fun.
To help other people which have the same problem,
we publish a short tutorial, how to get rid of the “Magic Hack”


The Magic Hack sems to use a backdoor in elder WordPress versions,
Thai-Eyes used a 2.3 version.
*First have a look at the editor of Your plugins.
If You??ll find a weird code, mostly in the bottom, with a lot of numbers and letters,
Your blog is infected.
What to do ???
* Go via FTP to Your server
and delete the malicious code in the vars.php (wp-includes).
* Check all Your plugins and delete the malicious code.
*Now You should be able to save Your work,
but don´t leave it like that !!!
The burglar could come back through the backdoor,
You need to close it.
*Change Your WP Login Password !
*Deactivate all plugins
*Update to the newest version of wordpress
*Update all Your plugins and check them before activation.

Now Your wordpress blog should be safe for a while.
Update to the newest version regularly !

If You have to update Your wordpress manually,
because there is no automated update available,
be sure Your MSQL is set to php5,
because a lot of updated plugins don´t work with php4,
which causes even more problems.

2leep.com

2 Responses to “Magic Hack WordPress Blog hacked”

  1. [...] upgedated w??re uns dies mit ziemlicher Sicherheit erspart geblieben. Lesen Sie hierzu: Magic Hack WordPress Blog hacked (engl) [...]

Leave a Reply

(required)

(required)

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

© 2011 thai-eyes Suffusion WordPress theme by Sayontan Sinha