Dealing with Trojan attacks via mysql and wordpress

My poor baby is sick again. Last month BloggerLUV went live with a blog and quickly added a still safe community and just as I had the design slightly PIMPING and the site was kicking ass on Alexa it was infected with some crazy powerful trojans.

What this did basically was rewrote the index.php files and had some javascript ENGINE pumping itself back EVERYWHERE, most times when you have some code problem you can switch the theme, if you have a real problem you can rename any theme or plugin in attempt to turn the LIGHTS off and go back to the defaults. So anyway it was very frustrating to not just edit a quick file/s and be on my way. One of the many reasons THIS BLOG is backed up and stored in many places  and I can easily just rewrite and upload any file is because I did all the right things in the beginning and VERY RARELY add any plugins or themes to this site now.

One interesting note is like a week before the attack I was on the site with a little netbook and thought I was SLICK adding some offbeat underground HACK plugins for a FREE directory etc you know trying to add and have something most blogs don’t. Well that effort cost me and I thought I removed the crap on the netbook until the screen went permenantly BLACK NICE :)

So Kristi was helpful in suggesting I run that Krapesky :) free for 30 days app and since I never download stuff I THINK isn’t safe I wasn’t to much worried about OUTSIDE threats.

When you DEMO a plugin it adds BLOCKS to your database, so when you install it its DONE when you uninstall or delete it’s STILL DONE :)

I could make a plugin that you loved make it some do follow thingy and it actually sends me your password and maybe if I’m feeling really spicy I could have to alter your Google PUB ID to mine :) But since I NEVER do stuff like that let’s move on .

How worried are you about your blog ? As a group blog BLOGGER LUV I’m pretty worried. I asked a few of my close blogging friends to join US on this project and I can’t even manage a wordpress install ? Makes you question your programming aptitude for sure.

Speaking of wordpress I constantly LOOK for something BETTER yes WP is pimping and FREE but it makes way to many database calls for me ;) So actually the limits of wordpress have inspired me to study Ruby on Rails, the programming language that built Twitter and many awesome sites and applications. Anyway why cry over spilled milk hey I’m learning more about databases and all that so have any cool tricks and tips to keep your site safe ? Be careful what you download as if we didn’t hear that before. Also I hope your database password isn’t the same as your blogs, emails password because I can see your database password ;)

Peace out and thanks for stopping by :)

Please feel free to take a REAL PEEK at http://bloggerluv.com code and let me know what you think I went back to the default theme for now Thanks :)   If you see anything pls let me know see I went MANY times deleting that script crap and damn that fucker is good and the reincarnating script returns :) Hey if it was easy it wouldn’t be BLOGGING :) Check YO self FEWL :) <<just wanted to say that sorry LOL

This entry was posted in bloggers, blogging, do follow blogs. Bookmark the permalink.

6 Responses to Dealing with Trojan attacks via mysql and wordpress

  1. John Sullivan says:

    @Karl Foxley: Not 100 % clear what you mean if your saying that it was wrong for me to say some nasty shit about that LAME OVER RATED GOOF Annn Smarty yeah your probably right
    but it just goes to show that if we shit on people and then think we’re all that it may come back to us
    I hope you not just taking her side out of money or anything because I seen that site and wouldn’t be involved if I owned it ;)
    We COOL :)

    • Karl Foxley says:

      Hi John,

      The email I sent you was regarding my site and nothing else. I may have read the comment you left there wrong but I read it and thought (maybe wrongly) you were referencing the fact we currently have the no follow attribute in place. I was just following up with you to say that it is a test I’m running for my site right now. That was it, oh and that we support the do follow movement, and our site will be that again as soon as the test period is out (‘our’ site being mine and Kelly’s FMS SEO).

      As for anything else, I can’t comment on, and haven’t, and no sides were taken in the making of this response (or any other). :)

  2. John Sullivan says:

    @Karl I would still like to add your site to my blogs I like page with some crafty SEO (YOUR PICK ) anchor text you don’t see any other seo people on there so I must like you ;) Thanks
    and Hey I was wrong to write that stuff I should of just kept it to myself
    my bad

    • Karl Foxley says:

      It’s all good John, I’ve been hanging around for a Blogger Luv invite but, hey, if I ain’t good enough. lol.

      SEO Company would be great as we are going to start targeting that soon, long road, but if you don’t start moving on something you’ll never get there. :)

      Oh, and to be the only SEO on there means I should have one of those arrows you’ve given to a few of your picks, something like <—- a half decent SEO (and blogger). lol

      Keep doing what you're doing John.

  3. Dan @ Blogs about everything says:

    I had the same thing happen to me, luckily I had everything backed up and was a matter of deleting and reinstalling the theme. I just don’t know how or where the attack came from. This is why it is so important to have all your stuff backed up.

  4. Pliggs says:

    I had this happen to a clients site, but it was the result of outdated insecure contact forms.

    We had to contact Google as they marked the site as dangerous, they quickly recrawled it and removed the label and confirmed all files were safe.

    Real pain though.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

*
= 3 + 6