f13.net

f13.net General Forums => General Discussion => Topic started by: Kail on February 14, 2017, 10:23:33 AM



Title: Our WP sites including f13.net main page have been hacked
Post by: Kail on February 14, 2017, 10:23:33 AM
Is anyone else seeing a hidden link for "casino strategies" on the F13 front page, or am I sporting some weird virus?

Edit by Trippy: moved to own topic


Title: Our WP sites including f13.net main page have been hacked
Post by: Sky on February 14, 2017, 11:16:50 AM
What's a front page?


Title: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 14, 2017, 11:35:06 AM
Is anyone else seeing a hidden link for "casino strategies" on the F13 front page, or am I sporting some weird virus?
I see it in the source through Firefox. We've probably been hacked :awesome_for_real:

I won't be able to easily work on it until I get home.


Title: Our WP sites including f13.net main page have been hacked
Post by: Yegolev on February 15, 2017, 12:39:12 PM
Joke's on the hacker, no one reads the front page.


Title: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 15, 2017, 01:17:44 PM
It's a honey pot :awesome_for_real:


Title: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 15, 2017, 10:16:41 PM
Is anyone else seeing a hidden link for "casino strategies" on the F13 front page, or am I sporting some weird virus?
I see it in the source through Firefox. We've probably been hacked :awesome_for_real:

I won't be able to easily work on it until I get home.
Offending block of code removed. Don't know yet how it got there (so it may come back).


Title: Our WP sites including f13.net main page have been hacked
Post by: jth on February 16, 2017, 02:43:49 AM

Offending block of code removed. Don't know yet how it got there (so it may come back).


Looks like it did, and not so hidden this time.


Title: Our WP sites including f13.net main page have been hacked
Post by: Mandella on February 16, 2017, 07:47:53 AM
Time to change the password? Remember to use numbers and a special character!

 :why_so_serious:

But seriously, I tend to surf in past the front page, should I be worried about anything?

I also run browsers protected by noscript and have only clicked on the forum link in forever.


Title: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 16, 2017, 01:11:04 PM
Offending block of code removed. Don't know yet how it got there (so it may come back).
Looks like it did, and not so hidden this time.
Well WP had a huge hole in class-phpmailer.php which was made public in December last year which might be the way they are getting through.

Removed that file and one of the injected malware files that likely came through that exploit, removed the offending link (again), and am continuing to scan for other bad stuff.


Title: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 16, 2017, 01:13:31 PM
But seriously, I tend to surf in past the front page, should I be worried about anything?

I also run browsers protected by noscript and have only clicked on the forum link in forever.
As long as you didn't click the link you should be fine.


Title: Re: Our WP sites including f13.net main page have been hacked
Post by: HaemishM on February 16, 2017, 01:29:22 PM
The exploit only really allowed hackers to make new posts on the Wordpress site. It's more of a defacement kind of thing as opposed to a crack the user database thing.


Title: Re: Our WP sites including f13.net main page have been hacked
Post by: JRave on February 16, 2017, 05:21:17 PM
Is the double navbar something you caused or is the site still being screwed with?


Title: Re: Our WP sites including f13.net main page have been hacked
Post by: Sky on February 16, 2017, 08:39:21 PM
Well WP had a huge hole in class-phpmailer.php which was made public in December last year which might be the way they are getting through.

Removed that file and one of the injected malware files that likely came through that exploit, removed the offending link (again), and am continuing to scan for other bad stuff.

Godaddy (I know, shut up) just nuked a ton of shit from an old, unupdated test site I had hanging around. I ran the WP updater after getting the notification, but they seem to be on the ball about making sure that gets dealt with, whether you like it or not.


Title: Re: Our WP sites including f13.net main page have been hacked
Post by: Trippy on February 16, 2017, 09:36:40 PM
We use GoDaddy too but that's cause schild used to work there and we've too lazy to move off of them, though we did explore that option the last time around.


Title: Re: Our WP sites including f13.net main page have been hacked
Post by: Ironwood on February 17, 2017, 01:22:46 AM
Why am I now getting fucking e-mails from Russian Bots purporting to be from f13 ?

I think the PM system got a dick in it now.