WordPress Hack Epidemic!
April 9, 2008 by Jayvee Fernandez
Filed under Computers
The WordPress hidden text exploit I blogged earlier has exploded to epidemic proportions, hitting even big sites like ZDNet. The worst part: ZDNet wasn’t even running an old version of WordPress.
The attack is two-pronged: it creates spammy pages within blogs, and it creates hidden text links to those spammy pages on other blogs. A single blog can fall victim to both. These attacks chain together for a massive serial blogfuck.
Diagnosis is likewise two-pronged: check for hidden text on blogs (I use Lynx), and check for strange new PHP files in the blog directory.
Hidden text can result in a business-killing Google deindex. Since victimized blogs could already be disappearing from various indexes and aggregators, what we see could be just the tip of the iceberg.














