wp-includes folder hacked?
-
Today I noticed from our Statcounter.com tracking some very weird URLs on our site. It seems like a hacker has hijacked our home page and added some random text and images below the main content. Here are some examples:
https://laurenbphoto.com/blog/wp-includes/images/define-buck
https://laurenbphoto.com/blog/wp-includes/images/define-bucket
https://laurenbphoto.com/blog/wp-includes/images/nordlingen-germanyWhen I log in to the admin, I can’t find any of the posts or images, though the source code says the images are hosted on our site. If I log in via FTP, I don’t see the images in the wp-includes/images directory. I even did a full server search using cPanel and could not locate the images.
Also, our site redirects to https://www.laurenbphoto.com if you put in https://laurenbphoto.com. Yet, these URLs work without the www.
I did a twitter search for define buck and found this tweet with some reference to it:
https://twitter.com/#!/wushunate/status/180589249589026816I looked at the users timeline and there are a bunch of similar links to other WordPress sites. The twitter account seems hacked though. Until these weird pages started showing up, he hadn’t tweeted in two years.
We’re hosting with Host Gator and I have them looking into it. Anyone else seen this and can explain what’s happening? Any security suggestions?
Better yet, how do I get rid of it?
Thanks,
Lincoln
- The topic ‘wp-includes folder hacked?’ is closed to new replies.