PSA: Widespread WordPress Hack, Steals Search Engine Traffic

Written by nickel - 5 Comments

Sorry for wandering off topic, but…

This is just a quick public service announcement to anyone out there that runs a WordPress-based website. There is a pretty nasty hack going around right now that hijacks your search traffic. In fact, FiveCentNickel was compromised on Thursday, though this has since been resolved without any lasting damage.

I posted to Twitter about this while it was happening, and have also written up details here (with a followup and links here).

If you run a WordPress-based site, do the following:

» Clear your cookies (the hack uses cookies to hide itself)
» Run a Google search for your site
» Click through a related result

If you wind up at your own site, good for you. But if you get redirected to (or through) anyresults.net, then you’ve been hacked. Depending on your browser, the responsible cookies seem to be somewhat sticky, so you might want to run through the above steps a few times to be sure you’re okay.

I have spot-checked a number of sites myself and have found a number that have been compromised.

Published on June 7th, 2008 - 5 Comments
Filed under: About/Admin
email this article email this article - digg this - stumble it - save to del.icio.us

Related articles...

     » Sunday Roundup - Hacked Edition
     » Anniversary Giveaway, Final Update!
     » Another Giveaway Winner: The 5GB Microdrive
     » From the Archives (September 30th - October 6th)
     » Introducing Credit Addict (dot com)
     » Anniversary Giveaway, Update #1
     » More Gas Saving Tips
     » Anniversary Giveaway, Update #5

Comments (scroll down to add your own):

  1. Oh, thanks so much for the info!

    That explains so much. I’ve been busy doing research all over the web today, and I’ve encountered a few blogs that hung, and in the bottom of my FF page it said it was trying to connect to anyresults.net, but it was just hanging.

    Comment by Cindy — Jun 8th 2008 @ 2:05 am
  2. Sometimes I don’t know whether to applaud these tricksters for their diabolicalness, or to curse them for their criminal acts. Maybe a little bit of both.

    I know what you mean about the Wordpress upgrades being buggy though…

    Comment by Money Blue Book — Jun 8th 2008 @ 2:26 am
  3. Thanks for your help tonight, Nickel. You can find the results of my work here:

    http://www.getrichslowly.org/b.....snet-hack/

    Now I’m going to bed.

    Comment by J.D. — Jun 8th 2008 @ 5:31 am
  4. Thanks for the heads up. I just checked my blog and it’s okay, but I’ll be checking it regularly from now on.

    Cheers,
    Penelope

    BTW JD’s guide at Get Rich Slowly for if/when your site is hacked is great.

    Comment by Penelope @ Our Fourpence Worth — Jun 8th 2008 @ 6:15 am
  5. Yikes! The hack is kinda smart, though — if you got a cookie, you get your site, nice!

    Looks like my sites are ok too.

    Comment by payoff125k — Jun 8th 2008 @ 7:36 pm

Leave a comment

Subscribe without commenting

Subscribe for free updates...


Search this site...

Sponsors...

Great deals...

Readers’ choice...

Recent articles...

Recent comments...

  • Peggy: I have had this $10.00 deal from AT&T for over a year now and I...
  • Heather: We live in DC. Sitters around here expect way too much. Frankly I...
  • Jen: How do any of you ever go out? We have a babysitting budget of $20 a...
  • tina: i hate bankofamerica… there full of it they charge you for...
  • noelle: About 5-8 years ago when I was in middle school I babysat for my 3...
  • Sharon: What is the status for Capital One Direct Banking? I didn’t see...
  • Kelli: I have 3 kids -$10-15 per hour is the going rate depending on age and...
  • si: I have bought my living room furniture from them 10 years ago. We loved...

Most talked about...

Disclaimer...

    The terms of third-party offers referenced on this website are subject to change without notice. While we strive to maintain timely and accurate information, offer details may be out of date. Visitors should thus verify the terms of any such offers prior to participating in them. Please see our terms of service for additional details.