3 ms·
FWIW, I just visited your site and it contained some compressed JavaScript at the top and a broken link to http: // gsdgsd.freewww.biz/showthread.php?t=72881717
by danielh 15y ago
FWIW, I just visited your site and it contained some compressed JavaScript at the top and a broken link to http: // gsdgsd.freewww.biz/showthread.php?t=72881717 (slightly obfuscated to avoid accidential clicks). It was gone after a reload, so I can't give you any more information.
- balsamiq 15y agowow this is definitely a hint. The WPEngine guys are looking into it now.
- bphogan 15y agoHappened to seven WP sites I maintain. It's a script and someone got into an account. The script finds all .php and .htm files and adds stuff to the top. If you only have wordpress files, it's an easy fix - reset the password and get a different template.
- DanielStraight 15y agoWhat does the attack do for those who visited the site trying to figure out what was going on?
- danielh 15y agoThe malicious script only inserted an iframe with a broken link, so I wouldn't worry to much.
- Matt_Cutts 15y agoI would still worry a bit. Some hackers will show a broken link if you're accessing a page directly with no referrers, for example. But if you come in with a referrer or from a search engine, then they might return the malware payload. If a site was showing up recently in our malware list, it's practically certain that an actual user downloaded malware via the site.