349 posts
  • Bought between 100 and 499 items
  • Has been a member for 5-6 years
  • United Kingdom
kops says

Hi folks,

A site I built up from a theme has been compromised due to, I’m pretty sure, the timthumb script.

After I visited the site a few days ago, java tried installing itself on my machine and I got some message about ‘couldn’t generate a pdf’. Firefox then started redirecting me all over the place nad it’s taken a few days to get the laptop back on course.

I switched out the timthumb script on the website for the new version, deleted the generic ‘admin’ account, isntalled and configured Bulletproof Security and started seeing which files had been changed. As far as I can see, the only file changed was wp-config.php where some code has been added to the end with about 200 blank lines wither side of it. I’ve deleted that code and kept my fingers crossed.

The code keeps re-appearing though and I have no idea what to do apart from continually deleting it.

The code is 30 lines, beginning:

if (isset($_GET['pingnow'])&& isset($_GET['pass'])){

I’m buggered if I have to re-build the site from scratch as I’m tied up with other sites for weeks.

Any suggestions really appreciated as I’ve exhaused google search!

Jon.

147 posts
  • Bought between 10 and 49 items
  • Elite Author
  • Exclusive Author
  • Has been a member for 3-4 years
  • Referred between 10 and 49 users
  • Sold between 250 000 and 1 000 000 dollars
FlexiPress says

Jon,

have you checked this topic?

http://wordpress.org/support/topic/iframe-hack-3
by
by
by
by
by
by