Watch Out for statcounter.php …

January 23rd, 2008 by Lars


… and other files called from wordpress.net.in in your WordPress files. There is a spam injection hijack that attacks vulnerabilities in WordPress and its plug-ins.

Somehow it got into my blog on Friday, but I removed it as soon as it was spotted. I didn’t have any call to statcounter.php nor had I installed any malware plug-ins (none of the usual offenders were detected). The malicious code had been inserted in a way that differs slightly from the ways I’ve read about.

What you can do if your blog is affected is to search your files for typical spam words (such as Viagra), id=”goro”, Uo=p23ik, cssf1x, and wordpress.net.in.

Read more about the wordpress.net.in hijack

Posted in Getting smarter |




Leave a Comment




Please note: Comment moderation is enabled and may delay some comments. There is no need to resubmit your comment. We use spam protection to filter out comment spam.


Internet Marketing Conference (including web analytics)







WebAnalysts.Info

Blogroll


Feedback Form
Close
Powered by ShareThis