No Gravatar

Well this is one very embarrassing day. Given my day job :-(

The brand new Wordpress 2.7 (may of had so,me 2.6.5 hanging around) instance I setup for my wife, got hacked
Still not sure how, the access logs are not very conclusive, but someone managed to edit every header.php file under the themes folder and inject a trojan “exploit-iframe.gen.c”

I found a similar story hear. http://photocritic.org/wordpress-exploit-iframe-gen-c/

Yes, I admit I allowed apache write access to the themes folder. which i have now fixed

The Code also included a reference to “search_bot111″

Needless to say i am VERY annoyed

Bookmark and Share