Share/Bookmark

Someone Hacked Me to Pieces

So far, the last few days have been really crappy. First, the medical bill came in for my 14-month old daughter's 30-minute surgery. It was over $10,000. The HMO will pay a good part of it, but the amount I owe will still be staggering. Kinda puts a damper on Christmas and Thanksgiving (yes, I am thankful my daughter is OK now).

The second reason why things are crappy is because Akismet does not appear to be working on my blogs. Every few minutes, I get an email to approve a comment that has about 100 links in it. This has been going for a few days now. And it is getting reaaaaallllly ANNOYING.

Then there's my daddy blog, which was hacked early Saturday morning. Somehow, a hacker was able to insert a script and a bunch of links above the WordPress template's code. The hacked stuff loads before <!DOCTYPE html section of each web page. I downloaded my templates and I didn't see any modifications to my templates. I deactivated all the plugins and selected the default WordPress theme. It didn't make a difference. I upgraded to WordPress 2.0.5 from 2.0.4 and the hack is still there. I couldn't figure out how to resolve the problem so I submitted a ticket to my web host. Seven and a half hours later, they reply with something like, "We don't support third party applications and perhaps your password has been compromised."

That was really helpful. It's possible my password was compromised, but I didn't see any tampering of any of my files. I really don't understand how the hacker was able to insert the extra code before the html header. Makes me wonder if the web host has some sort of WordPress related virus that was doing it. I created a non-WordPress page and it loaded without any additional code. So, the problem is WordPress related.

The next thing I did was uninstall WordPress. I didn't want to do this, but I didn't see how I had any choice (my content was not viewable). So, after uninstalling, I reinstalled the latest version. Then I restored the database from back-up. Guess what? I got the exact same result with the default theme. I didn't upload my plugins so the only ones enabled were the ones that came with WordPress (Akismet and Database Backup).

At this point, I was wondering if the hack occurred in the database. To test this, I restore the database to another site with a different web host (#2). This time, the hack was gone. The database was fine. Since my blog was now working correctly, I had web host #2 change the domain name to daddyforever.com and then I change the entries for the name servers to point to web host #2. The dns propagation could take up to 48 hours, but I saw the change in less than 24 hours. But it wasn't what I was expecting. I could no longer connect to my site at web host #1 or #2. I didn't want to be Chicken Little, so I waited several hours before asking web host #2 to recheck their work. Sure enough, they discovered they made a mistake in the dns setup on their end.

My daddy blog is now back online after two days. I still have no idea how the hack occurred. The morale of the post? Back-up often.

free Internet Retailer

This entry was posted in WordPress. Bookmark the permalink.

7 Responses to Someone Hacked Me to Pieces

  1. Pingback: iZachy

  2. snowgirl says:

    i hate hacker, one of my site is hacked too

  3. NRG Lab says:

    Well. I can help you find out. Go to my website:

    http://www.hz-ug.com

    visit the contact page (don't want to post it for indexing).

    Anyway..yeah.. Are you on a shared hosting plan? This type of stuff happens a lot with some shared hosting. If it was really, really, really important content on your site, you should probably get a dedicated server.

  4. NRG Lab says:

    http://www.hz-ug.com
    I wrote an article about how it's very easy for someone to hack you if you are on a shared hosting plan.

  5. Ni9htRider says:

    Was your site on a shared server? I bet you that's the reason why. Shared servers are much easier to hack. My website:
    http://www.nrglab.org
    is on a dedicated server because I can't risk it :O

  6. Ni9htRider says:

    NRG Lab

    I forgot to add this, but if you go to the contact us section on my website, I will be able to help you better from there.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

iZachy Newsletter

Don't have time to visit iZachy everyday? Then sign up for my free newsletter. I'll send you an email when I have something to share with you. Your email address will be kept confidential and I will not share, sell, or rent it to anyone. You can unsubscribe at any time by clicking a link in the email.

Enter your email address to sign up for my newsletter:
  

Or you can also sign up for our blog feed.