Here’s the story:
So, there I was, checking to see if any new posts were on the site, and man, the login page looked pretty weird. Strange. Then the admin page for the site was also pretty screwed up: weird layout, missing pictures, missing buttons, etc.
What could it be? Did I screw something up? Was it the fault of my ISP? Hmmm…
Anyway, I replaced a few files from a backup I had (a few .php files were oddly only 200 bytes, BYTES, mind you, not KB) and all SEEMED well.
So, forgive my being busy, I thought all was well, and even my STUPID CHEAP anti-virus program (more on that later) wasn’t really raising any red flags, so…hmmm.
Then after a day or so, Randy, bless you, sir, sent me email reporting that there was indeed a virus trying to be loaded from my page.
Oh.
Crap.
A more in depth perusal of things revealed that somehow, somehow, (more later), every folder had a new index.html inserted into it, and almost all the .php pages were changed. (And obfuscated, so I couldn’t clean them up…clever, clever, hackers. Not.)
So, yes. Every folder on the site had been infected, along with all the header and footer php pages. A quick search revealed that there as an “IFrame” embedded in them all which, when loaded, tried to redirect the browser to a some scammer shit site. Happy Happy Joy Joy.
The clean up was fairly easy: Just download and replace the corrupted files. But how did this happen? I got a copy of the FTP logs and it was my work IP that was recorded as the “sinner” that uploaded the pages. (I thought I could blame WordPress for this, but the infiltration was much more comprehensive than that…I mean, EVERY folder on the site, even old, forgetten non-Word Press folders were infected…)
To make a long story short…I’m guess that, as mentioned before, the fact that FileZilla, by default (!!!), saved FTP user names and passwords in CLEAR TEXT on the computer may have had something to do with it. Who knows…the Internet is truely the Wild, Wild West.
So a quick change of the FTP password, a cleanup of ALL infected files, and all seems well.
A HUGE thank you to Randy for bringing this to my attention. Yes, I would have noticed eventually (real life and all), but who knows how much damage could have been done.
With that in mind, I end this post with a humble request: Please, do not hesitate to contact me if something seems strange on this site. (Besides my reviews, of course.)
It will take much, much more than gutless hackers to bring down this site.
I promise!
Latest buzz