(This post is a little on the geeky side. No apologies, none at all)
It all started a few weeks ago when I logged into WordPress to write some of my usual drivel.. down the bottom of the screeen I could see that the browser was trying to access what appeared to be some sort of real estate website in China.. “Hmmm, not good” is the sanitized version of what came to mind, but it seemed harmless enough so I more or less forgot about it.
The fine people at Google decided to remind me about this late last week – I tried to access my site and got a big, red warning screen stating that my site had been flagged as being potentially dangerous and that it was possibly distributing some sort of virus.. I tried to log into WordPress to try and have a poke around – same warning screen – My Firefox security settings must have been set to high (unusual for me – perhaps it was the default setting when I downloaded the most recent update?) as the browser seemed to ignore my attempts to ignore the warning. This mutual ignoring wasn’t getting me anywhere – the last thing a blog with a mere subscription base of 23 needs is to have the ubiqitous Google corporation on your back…
At least the folks at Google provided a link to a relevant diagnostic page to give some idea as to what was going on. And yes, this page confirmed that the Googlebot thought that my site was a portal for the distribution of malware. Cr@p! (- and no that’s not meant to say CROP). A link to a group educating the world about these types of website problems proved to be only a little helpful – when they tell you to “clean up your site” they don’t exactly provide you with a tool to seek out and identify the offending code – Thanks guys…
So via my FTP program I had a bit of a search around some of the files which make up Polliweb – lo and behold.. embedded into about a dozen files was some code linking to this Chinese Real Estate site (www.tellicolakerealty.cn) .. I was stunned.. It was a bit like the moment in Alien 3 where Ripley sees the scan with the alien in her brain and realises that her worst nightmare has come true. (OK, so I’m using a bit of dramatic licence here – Alien Vs Predator 2 has turned out to be my worst nightmare so far – talk about an opportunity wasted.) All the same – I was quite alarmed..
So what happened? Turns out that the evil malware programmers had exploited a security vulernability
in the WordPress codex and embedded the dodgy code into a number of the php files on my site – (B@stards!) many of the files were now redundant so deleting them was not an issue. In the files I had to keep I simply deleted the offending code and then upgraded to the latest version of WordPress which closed up the backdoor the hackers had exploited.
Once the site was as clean as I was going to get it, I was able to request “reconsideration” from Google.. a process which they claim could take weeks…. argh.. Fortunately it only took about two days and we appear to have returned to normal operations here in the land of Polliweb. The flag is gone – woohoo – my site is cleansed.
Am interested to see if the emails corresponding with these posts start to go out again – I copy myself on these mails to make sure all is working as it should – and lately I’ve not been seeing anything – so let’s see how we go.
So all’s well.. have learned a lot… and have vowed never to buy real estate in China, EVER!
Postscript – seems that this attack was quite common – SEE ARTICLE.