• Home
  • Blog
  • Archives
  • Links
  • About
  • Guest Blogger
  • Contact

Tricia's Musings

Random Thoughts about life in general, living in the big city of Toronto

  • Home and Lifestyle
  • Recreation
  • Health Fitness and Beauty
  • Entertainment
  • Web and Technology


WordPress and PHP based sites have altered and extra files – check yours!

May 8, 2008 by Tricia

If you use WordPress or any other website platform that used PHP you should take a look at your files to see if any changes have been made to them in the last month.

A month or so ago I noticed that three of my WP sites suddenly said that they were using version 2.5 … heck they really weren’t even using 2.3.3 yet! Remember I was behind in my updates. So I decided to use my FTP program in order to take a look at the files on my server and much to my amazement I found that a lot of files had the date 10/4/2008 as the last time they were modified. Oddly enough I noticed the change to wp 2.5 on a few of my sites prior to all the file changes on the 10th of April. I wrote a post about it (see link above) on the 8th of April.

In addition to file date changes I found extra files some with PHP extensions, others with pngg and jpgg extensions.

I also found that a line of code had been added to the top of many of my files. Just go to your WordPress theme editor and take a look at each file for the current theme you are using to see if there is code with MD5 and debugger in it at the top. If there is you can remove the code with ends at exit >.

I went to WordPress.org to see if I could find anything about sites getting hacked or attacked and the first time I searched wordpress.org and did a Google search I didn’t find much, but last weekend I found lots of info. You can learn more by reading this WordPress security issue discussion.

Apparently a number of sites have been hit. That’s why I’m urging you to take a good look at your files to see if code has been added or if new files created.

Like I said I discovered changes on my sites shortly after they were hit – maybe April 12th or so, but I didn’t realize how widespread the problem was until I started digging deeper and got more information. I’ve basically spent a good portion of the last two weeks going over EVERY file on my web hosting server – even the /TMP directory.

It took me so long because I’ve got a lot of sites.

I even went through my Joomla CMS sites directories as well as my HTML based websites directories and I found extra and altered files there too, so if you run a few different kinds of sites don’t forget to check everything.

I also changed the passwords on all my sites as well as my server password. Every password for each of my sites is different.





Filed Under: Blogging, Internet, Web and Technology, Wordpress, Wordpress Plugins Tagged With: affected site, altered files, amazement, CMS, computer, debugger, discussion, errors, extra files, ftp program, google, google search, heck, hosting server, Internet, MD5, PHP, php extensions, security issue, Technology, tmp directory, update, web, Wordpress, wordpress discussion, wordpress theme, wrong version

Comments

  1. Roxiticus Desperate Housewives says

    May 10, 2008 at 1:29 am

    Ugh. Sounds like a nightmare. Tired/fearful of being at Google’s whim, I’ve been starting to slooooowwwly migrate over to a self-hosted WordPress blog from Blogger/Blogspot, but have found working with WordPress a lot tougher than I expected…I haven’t even started figuring out how to put widgets and photos up, nevermind having to worry about someone messing with the code. I did read about this problem on someone else’s blog — the person was offering to “check the code and fix the problem” for $15…all you had to do was send him/her your login info and password!! I think there was also some ocean-view real estate in Arizona available.

    Have a terrific weekend!

  2. Keiron @ Full-Time-Blogger says

    May 22, 2008 at 2:08 pm

    This is why it’s so, so important you keep on top of your updates!

    I was looking today at the WordPress Automatic Upgrade Plugin – I’ve just run it on one blog and got it backed up and updated in circa 3 minutes!!!

Connect with Us

  • Facebook
  • Flickr
  • Instagram
  • RSS
  • Twitter

Categories

Sites of Interest

Useful Links

Eavestrough Cleaning Toronto

Shopping

Gifts, Gadgets,
Books and More!

Recent Posts

  • Is your home well insulated or do you have energy leaks?
  • Pet Safety Tips
  • Top 10 Most Fundamental Yoga Poses For Beginners
  • Will My Interior Décor Stand The Test Of Time?
  • Outdoor Furniture- Spicing Up Your Backyard
  • Ensuring You Have A Good Experience Staying At Hotels With Children
  • Mother’s Day Cookies

Recent Comments

  • Bill on Top 10 Most Fundamental Yoga Poses For Beginners
  • [bonus]old school new body-f4x workout on Why does my husband always bring home the wrong stuff?
  • Rodhe Stevens on 5 Little Known Secrets To Finding Cheap (But Durable) Furniture
  • Julia Carlson on How To Install A Mosaic Tile Kitchen Backsplash
  • Humane Raccoon Deterrent Idea on Helped save a baby raccoon last night

Subscribe


Subscribe to our RSS Feed It's FREE!

Subscribe to Tricia's Musings by Email It's FREE!


Follow me on TWITTER

Find us on Google +



Find us on Facebook



I have two mottos-
1. Live life to the fullest; and
2. Don't have any regrets.

Get More Traffic

Visitors since 2006

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Search this site

Tags

blog blogs camera Canada Chris computer crohns dinner dog Family flower flowers Food friends funny garden Gardening Green Thumb Sunday Health and Fitness Health Fitness and Beauty holiday home Home and Lifestyle house husband IBD Inflammatory bowel disease Internet Music neighbors pain photo photos plants puppy Shopping sick sleep spring Toronto TV Video visit website Wordless Wednesday

Blogs I Visit

  • Organic Gardening Tips
  • Table For Five
  • Get WebStyle
  • Rainydazeee.com
  • Ah Ok Lah

Copyright © 2026 · Lifestyle Pro Theme on Genesis Framework · WordPress · Log in