{"id":460,"date":"2008-06-14T01:28:37","date_gmt":"2008-06-14T05:28:37","guid":{"rendered":"http:\/\/tim.cexx.org\/?p=460"},"modified":"2008-06-14T01:28:37","modified_gmt":"2008-06-14T05:28:37","slug":"bloody-hack","status":"publish","type":"post","link":"https:\/\/tim.cexx.org\/?p=460","title":{"rendered":"Bloody hack!"},"content":{"rendered":"<p>So, for those (if any) who found several pages of visible Viagra links at the end of the last few posts, my apologies. A vulnerability in the version of WordPress I was running allowed a machine at <b>keymachine.de<\/b> [87.118.124.3] to directly inject spam links into posts using the attach\/edit features. (This site is apparently a <a href=\"http:\/\/www.hojohnlee.com\/weblog\/archives\/2008\/04\/02\/hacked-by-keymachinede\/\">regular<\/a> <a href=\"http:\/\/web-robot-abuse.blogspot.com\/2006\/11\/keymachinede-abuse.html\">offender<\/a>.) I knew there were a some exploits out for that version, but all the ones I knew of concerned already-registered users escalating their privileges (mine does not have other users or accept registrations), and I was holding off updating because one of the important plugins I use [which keeps the cexxy blog and LJ account synced] was known not to work with the newer versions.<\/p>\n<p>The spam link injections had the form<br \/>\n<tt><br \/>\n&lt;u style=display:none&gt;&lt;a href=\"http:\/\/www.example.com\/files\/phe\/Lowest-drugname-prices.html\"&gt;<br \/>\nLowest drugname prices&lt;\/a&gt;<br \/>\n[... pages more spam links ...]<br \/>\n&lt;\/u&gt;<br \/>\n<\/tt><\/p>\n<p>The &#8216;display:none&#8217; served to render them invisible*. I only noticed because I happened to try editing a recent post, and the spam links appeared in the edit box. Invisible links aren&#8217;t view\/clickable by readers of course, but Google et al use them to determine search result rankings (everybody links to you, viagrawarehouse.com guy! You must be a respected authority! *bump*), so these sites have great incentive to spam their links everywhere, whether viewable to humans or not.<\/p>\n<p>As for the logs, the alleged offender&#8217;s entries are here:<\/p>\n<p><tt><br \/>\n87.118.124.3 - - [11\/Jun\/2008:07:24:15 -0700] \"GET \/wp-admin\/edit.php HTTP\/1.0\" 200 534 \"https:\/\/tim.cexx.org\/wp-admin\/edit.php\" \"Opera\"<br \/>\n[...]<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:03 -0700] \"GET \/wp-admin\/edit.php HTTP\/1.0\" 200 19629 \"https:\/\/tim.cexx.org\/wp-admin\/edit.php\" \"Opera\"<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:05 -0700] \"GET \/wp-admin\/post.php?action=edit&post=453 HTTP\/1.0\" 200 69211 \"https:\/\/tim.cexx.org\/wp-admin\/edit.php\" \"Opera\"<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:10 -0700] \"POST \/wp-admin\/post.php HTTP\/1.0\" 302 0 \"https:\/\/tim.cexx.org\/upload.php?style=inline&tab=upload&post_id=-1\" \"Opera\"<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:11 -0700] \"GET \/wp-admin\/edit.php HTTP\/1.0\" 200 19629 \"https:\/\/tim.cexx.org\/wp-admin\/edit.php\" \"Opera\"<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:12 -0700] \"GET \/wp-admin\/post.php?action=edit&post=453 HTTP\/1.0\" 200 60074 \"https:\/\/tim.cexx.org\/wp-admin\/edit.php\" \"Opera\"<br \/>\n87.118.124.3 - - [10\/Jun\/2008:03:02:14 -0700] \"POST \/wp-admin\/post.php HTTP\/1.0\" 302 0 \"https:\/\/tim.cexx.org\/upload.php?style=inline&tab=upload&post_id=-1\" \"Opera\"<\/p>\n<p>[additional lines skipped]<br \/>\n<\/tt><\/p>\n<p>Anyway, all spam has been removed and blog is patched up to the latest version. As a bonus, both my must-have plugins (<a href=\"http:\/\/unknowngenius.com\/blog\/wordpress\/spam-karma\/\">SK2<\/a> and <a href=\"http:\/\/lj-xp.com\/\">ljxp<\/a>) now appear to work with the current versions.<\/p>\n<p>* no pun int&#8230;technically, this is&#8230;whatever you would call an anti-pun, because the code serves to prevent them rendering at all.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So, for those (if any) who found several pages of visible Viagra links at the end of the last few posts, my apologies. A vulnerability in the version of WordPress I was running allowed a machine at keymachine.de [87.118.124.3] to directly inject spam links into posts using the attach\/edit features. (This site is apparently a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_FSMCFIC_featured_image_caption":"","_FSMCFIC_featured_image_nocaption":"","_FSMCFIC_featured_image_hide":"","iawp_total_views":2,"footnotes":""},"categories":[2],"tags":[],"class_list":["post-460","post","type-post","status-publish","format-standard","hentry","category-rants-rambles"],"_links":{"self":[{"href":"https:\/\/tim.cexx.org\/index.php?rest_route=\/wp\/v2\/posts\/460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tim.cexx.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tim.cexx.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tim.cexx.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tim.cexx.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=460"}],"version-history":[{"count":0,"href":"https:\/\/tim.cexx.org\/index.php?rest_route=\/wp\/v2\/posts\/460\/revisions"}],"wp:attachment":[{"href":"https:\/\/tim.cexx.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tim.cexx.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tim.cexx.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}