Watch Out for statcounter.php …
… and other files called from wordpress.net.in in your WordPress files. There is a spam injection hijack that attacks vulnerabilities in WordPress and its plug-ins.
Somehow it got into my blog on Friday, but I removed it as soon as it was spotted. I didn’t have any call to statcounter.php nor had I installed any malware plug-ins (none of the usual offenders were detected). The malicious code had been inserted in a way that differs slightly from the ways I’ve read about.
What you can do if your blog is affected is to search your files for typical spam words (such as Viagra), id=”goro”, Uo=p23ik, cssf1x, and wordpress.net.in.
Read more about the wordpress.net.in hijack
Posted in Getting smarter |
Subscribe to RSS feed
Subscribe by email



