WordPress 2.3.3 Hidden Links Injection Exploit and How To Not Let It Happen To You

by Jeremy Schoemaker on March 21, 2008 · 23 comments

A friend yesterday running the latest version of wordpress had some hidden links injected in his blog. I know he is very technical and knows what he is doing so started making me a little paranoid. I started search for WordPress 2.3.3 hidden links injection and as you can see there is a ton of people claiming to be running the latest and greatest WordPress version yet getting hidden links inserted in there posts. People are also inserting iframes. Its actually pretty effective if you think about it… How would you notice hidden links in old posts?

First I want to say I have never seen any evidence of a fresh 2.3.3 install of WordPress.

The issue most likely comes from either a previous exploitable file still existing in your WordPress install directory or from someone who has already hijacked your admin cookie. You see there were some wicked exploits in earlier versions that allowed people to hijack your admin cookie which authenticates you (keep me logged in).

So what to do…. well if you have WordPress 2.3.3 and you are getting owned regularly here is what you need to do.

1) Make a new fresh install of WordPress and copy over your must have files… like themes, plugins (MAKE SURE THEY ARE UP TO DATE) , images, wp-config.php

2) change your password right away. In case someone has a old hash of your password.

If you have been following the proper upgrade instructions (minus changing the admin pass) on the WordPress you should have been doing this the whole time… ya I know I was not either.

If you are a nerd like me you might want to use SVN which is super dope and is a better and easier way to keep up to date if you know how to use SVN. Here are the instructions for that

Anyway security wise out of the box most web servers are not going to help you find out the root of the problem. Most of these are POST requests and unless you are specifically logging them of have mod_security installed …. there is no log anywhere of any POST request to your web server other then one happened.

Thanks to wordpress developer donncha ocaoimh for answering my twitter ;)

Hope this helps anyone who is having there wordpress 2.3.3 getting owned.

About the author...

– who has written 2412 posts on ShoeMoney.com.

Hi I am Jeremy Schoemaker and ShoeMoney.com is my blog. 99% of the post here are done by me but you will see others occasionally make guest posts. This blog is fun to write but for my day job I run several online companies.

Images provided by ShutterStock


Mark recommends you read these posts also:

  1. shutterstock_73217308 You’re Too Sensitive to Be on the Internet
  2. bad idea My Top 10 Worst Ideas To Make Money
  3. twitterrich-20091020-085652 How I made 15,000.00 In 1 Month Just By Tweeting

{ 6 comments… read them below or add one }

1 RaiulBaztepo March 28, 2009 at 5:41 pm

Hello!
Very Interesting post! Thank you for such interesting resource!
PS: Sorry for my bad english, I’v just started to learn this language ;)
See you!
Your, Raiul Baztepo

Reply

2 vetweb March 31, 2009 at 8:02 pm

Hi, thanks for the tutorial.
I have wp 2.6 installed, and got link injection in footer area. I’ve removed them but worry to see it again in the future. Any idea?
Thanks

Reply

3 Bilgi Yarışması June 1, 2010 at 3:20 am

its really important!

Reply

4 fransiska cute October 27, 2010 at 2:47 am

thanks for sharing jeremy. You made some good points there. its easy to learn.
your website is great. a lot information can i get from here :)

Reply

5 Cicely Swinford January 19, 2011 at 10:38 am

TY a lot for penning this, it was unbelieveably informative and helped me a great deal

Reply

6 Galina Wiatrek January 19, 2011 at 6:58 pm

Is it alright to post some of this on my page if I post a link for this page?

Reply

Leave a Comment

Previous post:

Next post: