![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Apr 2007
Posts: 5,169
|
somoene inserted links on my site
Hmm...I've discovered unwanted links on one of my wordpress blogs. It seems they are placed in footer.php. Below is a print screen of the code.
Does anyone have an idea how this was done and how to protect it in the future? The theme is Generate Press and they are not having a real answer, denying it was a problem with a theme. This site has no Wordfence plugin installed,but the other one with it, had the same problem. thanks ![]() <div style="display:none"> <p>Are you looking for free Arab porn websites? The Internet is full of porn sites but what's the difference between porn and porno sites? Here are a few things to look out for. Porn sites feature girls and women that are mostly dressing up to look like women and for men. They are not dressed sensuously or they are not made to look like they are being intimate with their partners.Not only are the girls dressed in something other than a short skirt, they are also often younger than the man who is watching them. And there are times when the young woman in the videos could be his girlfriend.</p> <p><a href="*ttps://xnxxarabsex.com/categories/سكس-عربي/">arab sex</a></p> <p><a href="*ttps://sexe-libre.org/pokimane-sex-tape-nudes-twitch-streamer">pokimane nudes</a></p> <p><a href="*ttps://sexsaoy.com/">arab sex stories</a></p> <p><a href="*ttps://aflamaljins.com">aflamaljins.com</a></p> <p><a href="*ttps://russiainporn.com">russiainporn.com</a></p> <p><a href="*ttps://afdalsex.com/">afdal sex</a></p> <p><a href="*ttps://overpic.com/">mature sex</a></p>
__________________
Femdom Destiny -------------------------------------------- ICQ: 463-630-426 email: webmaster(at)femdomdestiny.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
Wordfence might be able to clear that up , I woild sugges you update all your plugins and change all your passwords also.
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 | |
Confirmed User
Industry Role:
Join Date: Apr 2010
Posts: 1,084
|
Hi,
Make sure your Wordpress and plugins are up to date. Not only the site that got injected but all sites on the server. I would also suggest listing all newly edited files on your host, to find all affected files. Here's a script that will do this for you Quote:
Cheers, z
__________________
php, html, jquery, javascript, wordpress - contact me at contact at zerovic.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a custom title
Industry Role:
Join Date: Feb 2005
Posts: 17,229
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
So Fucking Banned
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 25,198
|
I've had that before, for me it was some old outdated plugins that were exploited.
Goodluck fixing, it sure sucks these hacker/scammers stealing space on your sites ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Industry Role:
Join Date: Jan 2011
Location: Somewhere in Germany
Posts: 817
|
Also make sure not to use any nulled themes and plugins. Only buy software from verified sources.
__________________
I know, my english is bad. But your german might be even worse ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Too lazy to set a custom title
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,522
|
It is likely malicious code in little bits of Javascript. WordFence may be able to tell you the specific files, but, to keep them from coming back, you need to update everything, delete unused themes like old exploitable default themes, and upgrade to current php. And report whatever affiliate is doing this to any program where you see the affiliate ID.
Hope this helps. Good luck.
__________________
![]() ![]() ![]() ![]() ![]() Blue Blood's SpookyCash.com Babe photography portfolio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Jul 2003
Location: Australia
Posts: 5,065
|
Wordpress is just non stop problem after problem. I like it as easy but always trashed by hackers.
__________________
Traffic.Tools - 40+ Free Tools Free.Marketing - 150+ Free Tools Submission.Tools - 20+ Free Tools |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed User
Industry Role:
Join Date: Sep 2013
Location: The Netherlands
Posts: 805
|
Quote:
h*ttps://stagepopkek.com/lv/esnk/1836018/code.js h*ttps://mafrarc3e9h.com/lv/esnk/1839026/code.js etc etc I think the number in the javascript url is the affiliate's website/domain ID (1836018, 1839026 etc). |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Nomad Land
Posts: 1,601
|
Would be interesting to know what other plugins you are running. I've seen similar issues in the past with certain cache plugins.
Do make sure your plugins are updated and Google each one of them to see if you find people with similar issues.
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Aug 2012
Posts: 929
|
its XSS injection. I've had this happen ACROSSS my network of adult porn blog sites.
I tried all the plugins, etc bs none will work Solution: GTFO of wordpress! I had a custom built script for myself. Fast, no updates required ever and open source. NO MORE worrying about XSS injections ever! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Too lazy to set a custom title
Join Date: Jan 2003
Location: Los Angeles
Posts: 10,522
|
Do you recall which cache plugins allowed the exploit or were the exploit files just hiding in the cache?
__________________
![]() ![]() ![]() ![]() ![]() Blue Blood's SpookyCash.com Babe photography portfolio |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Pay It Forward
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 76,891
|
secure your admin. there are files still that reveal info
__________________
TRUMP 2025 KEKAW!!! - Support The Laken Riley Act!!! END DACA - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Let's Make Money
Industry Role:
Join Date: Dec 2008
Posts: 8,784
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,171
|
Also make sure none of your files are set with 777 permissions.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Confirmed User
Industry Role:
Join Date: Jan 2003
Location: Nomad Land
Posts: 1,601
|
Quote:
The code was injected into cached files so luckily it was quite easy to turn off caching and clean those directories.
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |