[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 483: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/bbcode.php on line 112: preg_replace(): The /e modifier is no longer supported, use preg_replace_callback instead
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3824: Cannot modify header information - headers already sent by (output started at /includes/functions.php:3247)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3826: Cannot modify header information - headers already sent by (output started at /includes/functions.php:3247)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3827: Cannot modify header information - headers already sent by (output started at /includes/functions.php:3247)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3828: Cannot modify header information - headers already sent by (output started at /includes/functions.php:3247)
View topic - WP Hackers Hit Me - Warning Upgrade to 2.5 • SSWT Internet Marketing Forum •

 

This Forum Has Been Archived
*Click Here To Visit The NEW Forum*

 

 


WP Hackers Hit Me - Warning Upgrade to 2.5

All about blogging, bloggers, how to blog, platforms and themes and templates, blog promotion, working with RSS feeds, and more...

Moderators: angienewton, tknoppe, terrapin719, lisamariemary, MommyEnterprises, Mike Paul

WP Hackers Hit Me - Warning Upgrade to 2.5

Postby Alan Petersen » Thu Apr 17, 2008 2:28 pm

I was on WP 2.2 and my blog was hacked. It's very subtle because they don't want you to notice. They slipped in a plugin that deactivates all my plugins. The goal being to deactivate Askimet and my other anti-spam plugins.

Luckily I moderate all comments even though I use anti-spam plugins so they never were posted but I noticed I was getting a lot of spam comments that were getting through before then Askimet always caught them and sent them to spam hell without me even looking at them.

These are obvious spam comments, you know the ones with a 100 links to ***** or rx sites.

I saw the spike of these spam comments in my moderation queue but I still didn't put 2 and 2 together. My site was still up (it's not like they plaster an "owned" sign on my blog). Like I said they don't want you to know.

I finally caught on when I went to use my SLM plugin to add an affiliate link and it was gone. I was very confused about that So I went to my site and paid a close look and noticed some of the sidebar stuff (which is powered by plugins) were gone.

So I went to check and sure enough all my plugins were deactivated. I re-activated them. I changed my password and sent a support ticket to my host.

Support suggested upgrading to 2.5 which he says prevents these type of hacks. During that time the hacker plugin did it's thing again. So I had to re-activeate all of them again.

My host support finally found the hacker plugin. It's not just listed on your plugin menu they hide it. So he deleted and now I'm back to normal.

Side effect is while that plugin was running I couldn't post. Instead of publishing my post it would just save it as a draft. I also had my about page deleted. Now things are back to normal.

I don't know if v 2.5 would help against this or not but you might as well as upgrade to the latest version since they address these type of vulnerabilities.

Keep an eye on your blog and always moderate your comments even if you have anti-spam plugins activated.
User avatar
Alan Petersen
Elite Member
 
Posts: 911
Joined: Thu Sep 21, 2006 12:10 pm

Postby TorontoCarol » Fri Apr 18, 2008 12:23 pm

Thanks for the heads up Alan. I want to upgrade, but am afraid that I might lose my content. Should I worry, or is it easy?
User avatar
TorontoCarol
Elite Member
 
Posts: 427
Joined: Wed May 28, 2003 11:07 pm
Location: Toronto, Canada

Postby Alan Petersen » Fri Apr 18, 2008 1:42 pm

It was very easy. I clicked a button. :lol:

I use Dream Host and Host Gator and both have an easy upgrade link. I just made sure my can't live without plugins would be fine. No issues from upgrading content wise or anything else.

Double check that your theme and plugins have been updated to 2.5 and you should be fine.
User avatar
Alan Petersen
Elite Member
 
Posts: 911
Joined: Thu Sep 21, 2006 12:10 pm

Postby JosephRatliff » Fri Apr 18, 2008 8:07 pm

There is also an Automatic WP Version Upgrade Plugin that upgrades and makes a nice, clean database backup and such.

Works flawlessly for now ;)
User avatar
JosephRatliff
Elite Member
 
Posts: 588
Joined: Fri Jun 02, 2006 4:53 pm
Location: Lacey, WA

Postby angienewton » Mon Apr 21, 2008 2:12 pm

User avatar
angienewton
Elite Member
 
Posts: 1132
Joined: Sun Oct 12, 2003 9:11 pm
Location: IL


Return to Blogs, Bloggers & Blogging

Who is online

Users browsing this forum: No registered users and 9 guests

cron