Girlfriend’s website hacked :(

See screenshots and help! It is in version 2.1 of WordPress (latest version). This is the warning dialog box that appears onLoad.

hacked-website-2.gif

And this one is the actual page:

hacked-website-1.gif

  • Twitter
  • Tumblr
  • StumbleUpon
  • Sphinn
  • Reddit
  • NewsVine
  • Google Reader
  • Facebook
  • Digg
  • BlogMarks
This entry was posted in Blogging, Btard, Web. Bookmark the permalink.

6 Responses to Girlfriend’s website hacked :(

  1. Pete says:

    Did you get any closer to the truth on this one? You can’t be that scared of K2 being hacked as you are still running it here and on your GF blog

  2. carlo says:

    [quote comment="250"]Did you get any closer to the truth on this one? You can’t be that scared of K2 being hacked as you are still running it here and on your GF blog[/quote]

    I know how to fix it now so I just upload a replacement of the file. I also have a cron which uploads the files every 6 hours just in case. I can’t move away from K2 – I like it WAY too much.

  3. Pete says:

    Hmm, but if there is a vulnerability with K2, shouldn’t we be looking to fix that rather than replacing the files every so often to cover it up?

  4. carlo says:

    [quote comment="254"]shouldn’t we be looking to fix that rather than replacing the files every so often to cover it up?[/quote]

    Quite possibly. This said, I have implemented this measure as a safeguard. One thing I would suggest is the CHMOD the files in /wp-content/themes/k2/ so that it is unable to be written to.

    I personally enjoy CHMOD’ing all my files to 777 so I can make edits from inside WordPress, however, this is going to open these files up to attack.

    FYI, the files on the girlfriends website were NOT 777 (RWX all). Weird!

  5. Zeo says:

    Wow! Is this for real?

  6. carlo says:

    [quote comment="268"]Wow! Is this for real?[/quote]
    Yeah this is real and a little sad. I can see why these people can try to hack a major blog but my girlfriend’s is a teeny lil site that’s brand new. Kinda lame huh?

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>