{"id":2405,"date":"2012-04-06T19:50:07","date_gmt":"2012-04-07T02:50:07","guid":{"rendered":"http:\/\/www.eaf.net\/mvp\/?p=2405"},"modified":"2012-04-06T19:50:07","modified_gmt":"2012-04-07T02:50:07","slug":"hacked-by-tariq-sql","status":"publish","type":"post","link":"https:\/\/www.eaf.net\/mvp\/2012\/hacked-by-tariq-sql\/","title":{"rendered":"Hacked by Tariq SQL"},"content":{"rendered":"<p>The owner called me at 8:39 this morning, &#8220;My site&#8217;s been hacked.&#8221;<\/p>\n<p>I was surprised.<\/p>\n<p>I mean, it&#8217;s a WordPress-powered site, after all. And I try to run a tight ship security-wise.<\/p>\n<p>So I had a look: <!--more--><\/p>\n<div class=\"capt-pix\"><a href=\"\/mvp\/wp-content\/g-hacked-1.jpg\"><img decoding=\"async\" src=\"\/mvp\/wp-content\/g-hacked-1.jpg\" alt=\"hacked site image\" \/><\/a><br \/>\n<i>Not a good sight!<\/i><\/div>\n<p>Next I viewed the code for the hacked page. Surprisingly, I saw no indicators of this being a hack of the WordPress code. Rather, it just looked like that code had been utterly cleaned out and replaced:<\/p>\n<div class=\"capt-pix\"><a href=\"\/mvp\/wp-content\/g-hacked-2.jpg\"><img decoding=\"async\" src=\"\/mvp\/wp-content\/g-hacked-2.jpg\" alt=\"hacked site code\" style=\"border-bottom:1px solid #cccccc\" \/><\/a><br \/>\n<i>A peek at the hacker&#8217;s code: no WordPress stuff!<\/i><\/div>\n<p>Strange. Weird, actually. (That&#8217;s in addition to surprising, of course.)<\/p>\n<p>Well, first things first: Get something better showing up on the home page than the hacker&#8217;s mocking, foul message.<\/p>\n<p>So I uploaded the latest static HTML home page (from the pre-WordPress days). Then I uploaded a version of <i>.htaccess<\/i> without the special WordPress section.<\/p>\n<div class=\"capt-pix\"><a href=\"\/mvp\/wp-content\/g-hacked-3.jpg\"><img decoding=\"async\" src=\"\/mvp\/wp-content\/g-hacked-3.jpg\" alt=\"temporary replacement index and htaccess files\" \/><\/a><br \/>\n<i>Two temporary replacement files, uploaded via FTP<\/i><\/div>\n<p>That took care of that. Good!<\/p>\n<p>Now, before tinkering with WordPress stuff, it was time to get a fresh back-up copy of the WordPress database. Sure, it would be corrupted, but if I really messed something up, I could at least restore that portion of the site and try again. \ud83d\ude42<\/p>\n<div class=\"capt-pix\"><a href=\"\/mvp\/wp-content\/g-hacked-4.jpg\"><img decoding=\"async\" src=\"\/mvp\/wp-content\/g-hacked-4.jpg\" alt=\"getting a WordPress database back-up\" style=\"border-bottom:1px solid #cccccc\" \/><\/a><br \/>\n<i>Executing and downloading a database backup<\/i><\/div>\n<p>Good. Finally I was ready to go rooting around in the database itself. I launched the site&#8217;s cPanel in order to get at <i>phpMyAdmin<\/i> so I could browse through the sql database:<\/p>\n<div class=\"capt-pix\"><a href=\"\/mvp\/wp-content\/g-hacked-5.jpg\"><img decoding=\"async\" src=\"\/mvp\/wp-content\/g-hacked-5.jpg\" alt=\"launching phpMyAdmin via cPanel\" style=\"border-bottom:1px solid #cccccc\" \/><\/a><br \/>\n<i>Now to nose around inside the database&#8230;<\/i><\/div>\n<p>I made sure the hacker hadn&#8217;t added himself as a blog administrator.<\/p>\n<p>Nope. Neither had she &#8220;adjusted&#8221; my profile to make it her own.<\/p>\n<p>I also searched for <i>Tariq<\/i> to certify that name was nowhere in there. Clean.<\/p>\n<p>I simply saw nothing out of line.<\/p>\n<p>So I got out of there and decided to try logging into the site&#8217;s WordPress administrative section. My password no longer worked. \ud83d\ude2f<\/p>\n<p>Thankfully, I was able to reset that via WordPress instead of resorting to the more-cumbersome <i>phpMyAdmin<\/i> route.<\/p>\n<p>Again, I checked to be sure no intruding users had been added.<\/p>\n<p>To keep an already-long story from getting too long, I&#8217;ll just outline the main points of what I did next:<\/p>\n<ol>\n<li>Updated WordPress installation. I missed doing that after the last WP release. \ud83d\ude33<\/li>\n<li>Updated all plugins and themes.<\/li>\n<li>Installed and ran the <a href=\"http:\/\/wordpress.org\/extend\/plugins\/exploit-scanner\/\" title=\"Exploit Scanner for WordPress by Donncha\">WordPress Exploit Scanner<\/a> plugin.<\/li>\n<li>Checked (via FTP) the folder of the current WordPress theme and noticed right away that <i>page.php<\/i> had been replaced late last night. I looked at its code and, sure enough, it was Tariq&#8217;s handiwork. I uploaded a fresh, clean, original copy.<\/li>\n<\/ol>\n<p>And that, folks, took care of the problem. <img src=\"https:\/\/www.eaf.net\/mvp\/wp-includes\/images\/smilies\/mrgreen.png\" alt=\":mrgreen:\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/><\/p>\n<p>But how in the world did that character burrow his way to that level and replace that file with his own? ?:<\/p>\n<p>I don&#8217;t know. \ud83d\ude41<\/p>\n<p>I have my suspicions, but I don&#8217;t want to state them here. \ud83d\ude2e<\/p>\n<p>I&#8217;ll just say this:<\/p>\n<blockquote><p>Be careful of what sites you go to. And what sites you post comments on. And what kind of backlinks you provide at such sites.<\/p>\n<p>Furthermore, keep dependable and up-to-date security and firewall applications on your computer. Have them doing their thing in real-time. And also do thorough weekly scans of your machine.<\/p><\/blockquote>\n<p>In closing, these links should be helpful in the event your WordPress site is hacked:<\/p>\n<div style=\"margin-left:25px\"><a href=\"http:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked\">http:\/\/codex.wordpress.org\/FAQ_My_site_was_hacked<\/a><\/p>\n<p><a href=\"http:\/\/wordpress.org\/support\/topic\/268083#post-1065779\">http:\/\/wordpress.org\/support\/topic\/268083#post-1065779<\/a><\/p>\n<p><a href=\"http:\/\/smackdown.blogsblogsblogs.com\/2008\/06\/24\/how-to-completely-clean-your-hacked-wordpress-installation\/\">http:\/\/smackdown.blogsblogsblogs.com\/2008\/06\/24\/how-to-completely-clean-your-hacked-wordpress-installation\/<\/a><\/p>\n<p><a href=\"http:\/\/ottopress.com\/2009\/hacked-wordpress-backdoors\/\">http:\/\/ottopress.com\/2009\/hacked-wordpress-backdoors\/<\/a><\/p>\n<p><a href=\"http:\/\/www.jtpratt.com\/how-to-fix-a-hacked-wordpress-blog\/\">http:\/\/www.jtpratt.com\/how-to-fix-a-hacked-wordpress-blog\/<\/a><\/p>\n<p><a href=\"http:\/\/codex.wordpress.org\/Hardening_WordPress\">http:\/\/codex.wordpress.org\/Hardening_WordPress<\/a><\/div>\n<p>Now go do the right thing.<\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>The owner called me at 8:39 this morning, &#8220;My site&#8217;s been hacked.&#8221; I was surprised. I mean, it&#8217;s a WordPress-powered site, after all. And I try to run a tight ship security-wise. So I had a look:<!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[13,20],"tags":[424,909,716],"class_list":["post-2405","post","type-post","status-publish","format-standard","hentry","category-tech-stuff","category-youve-been-warned","tag-security","tag-tips","tag-wordpress"],"jetpack_publicize_connections":[],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/prJUJ-CN","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/posts\/2405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/comments?post=2405"}],"version-history":[{"count":0,"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/posts\/2405\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/media?parent=2405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/categories?post=2405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eaf.net\/mvp\/wp-json\/wp\/v2\/tags?post=2405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}