The bad guys have been busy this month!
Several of our clients had their WordPress blogs hacked. A malware Javascript was used to load bogus sites was injected into the page footers.
How can you tell if you have this problem on your WordPress site or blog?
This particular script, is easy to spot from how your site reacts even though it is not visible in the content. When you visit your site [or blog], instead landing at the top of the page where you would expect to start, the script immediately takes you to the bottom of the page instead. If it does this, then there is a strong likelihood you have this malware on your WordPress.
If you use Firefox for your web browser, you may get an ugly warning page that your site has been reported as an attack site. Not fun. You will not be able to access your site at all… anywhere. This can make it harder get to rid of the problem because you may not be able to access your site admin area. Internet Explorer did not block entry to the sites because of this particular malware.
What should you do if this has happened to your WordPress?
If you can access your WordPress admin area using your web browser, then it’s relatively easy to get rid of the malware script. This particular exploit only affects one file, named footer.php.
You can edit this by going to Appearance=>Themes=>Editor and opening this file in the editor pane. The files are all listed to the right hand side of the pane.
Now you edit the footer.php file to remove the script. It will look like this screenshot of the one we removed from several sites.
Select the entire script with your cursor being careful not to touch anything else. Delete it and save your changes. Your site is clean again.
WARNING: If you needed these instructions, you are not someone who should be doing this on your own and we so we wouldn’t normally recommend you even attempt this yourself. But it’s simple deletion so we thought we’d include it here. Even so, if there is any doubt in your mind about whether you should be doing this yourself, get help. If you don’t have a web person, contact us for help
If you are one of the unlucky ones who have been reported as an attack site, you will need to submit your site to Google for it to be declared clean otherwise visitors may not be able to access your site for some time.
It may be cleared without submitting it but it will definitely take much longer. Posting right away and each day for a few days will alert the search engines to spider your site and find a clean, malware free site.
Stay tuned for our next posts where we will discuss how to submit your site to Google Webmaster tools for review and what you can do make your WordPress more secure from this type of an attack.

