PINAC gets hacked

My admin page is totally out of whack and I’m not even sure if this post will get published.

Apparently, a multitude of WordPress blogs that host with Go Daddy were affected.

I spoke to Go Daddy earlier today about the problem and the guy I spoke to acted as if he had no idea what I was talking about, but said they would do a scan on my site to see if there was a problem.

He said the scan did not pinpoint anything, so there must not be a problem. On their end. But he also advised me to change my password, so maybe he knew something was up.

After hanging up with him, I came across this site that revealed an undetermined amount of sites were hacked.

http://blog.sucuri.net/2010/09/godaddy-sites-hacked-myblindstudioinfoonl...

I then tweeted this link to Go Daddy and they responded that they are aware of the problem and are working on it.

http://community.godaddy.com/godaddy/php-exploit-resolved/?isc=smtwsup

I am unable to provide live links, so you must cut and paste to read the above links.

More info here.

http://blogcastfm.com/announcements/warning-massive-number-of-godaddy-wo...

Comments

Anonymous
Anonymous

thanks.

Anonymous
Anonymous

Does that mean your 50% off offer was fake?

/just kidding. Didn’t see anything from a viewer standpoint.
//unless it was.

Anonymous
Anonymous

No, the 50 percent was not fake. But it didn’t last long because five readers jumped on the deals quick.

Anonymous
Anonymous

Earlier today, I got one of the “Your computer is infected with malware-Click here to fix this problem” popups while viewing your site.

Anonymous
Anonymous

And just now:
Warning: Cannot modify header information – headers already sent by (output started at /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php:2) in /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php on line 96

Warning: Cannot modify header information – headers already sent by (output started at /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php:2) in /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php on line 97

Warning: Cannot modify header information – headers already sent by (output started at /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php:2) in /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php on line 98

Warning: Cannot modify header information – headers already sent by (output started at /home/content/c/a/r/carlosmiller13/html/wp-comments-post.php:2) in /home/content/c/a/r/carlosmiller13/html/wp-includes/pluggable.php on line 891

Anonymous
Anonymous

I noticed the same thing as well DBC58 #4. That was around 5pm. I had to do a task manager shutdown of my browser.

Anonymous
Anonymous

Yeah, your site was serving up malware last night, and again this morning.

Cleaning up after getting hacked is always a pain. My sympathies, and best wishes for a quick recovery.

Anonymous
Anonymous

I’ve been on the phone with Go Daddy for the last 30 minutes.

The first time they blew me off. Now they appear to be trying to fix the issue.

Anonymous
Anonymous

I had a problem for a couple of days, when I used my bookmark, the link would take me to PINAC but only to the September 8th,

“Chicago activist faces up to three years for videotaping public statement”

article, this was on the 14th and 15th of September. I did a search for PINAC and the Google search led to the same page.
Not sure if this means anything, just thought I would mention it.

Anonymous
Anonymous

Been having the same issues with your site, I think you should start to look at alternatives to WordPress, I had the same thing happen a few times, always on WordPress sites.

I now use Drupal, and have not had an issue again, and have much more power. If you need some assistance switching over I can help you out.

Anonymous
Anonymous

So it was:

“No no we are not having any problems, don’t know what you are talking about”
“Here’s a link that’s all about the problem”
“oooooh…… you meant that problem, yeah we know about it”

Get another more honest provider.

Anonymous
Anonymous

As I told you with the email, avast! picked up the Trojan. Your site was being redirected and avast! slamed the door shut on it.

Anonymous
Anonymous

I noticed when my Android powered phone told me that my xp operating system was infected with 10 Trojans when I tried to visit.

Anonymous
Anonymous

GoDaddy does have to spend a lot of money making softcore porn commercials with Danica Patrick.

You wouldn’t want them spending that money on security or support, would you?
Michaelk42 recently posted..Unsurprisingly- Pogan gets no real punishment

Anonymous
Anonymous

I had to ctr-alt-del to shutdown firefox, malicious js is so FUCKING annoying. I stopped the nonsense by adding the redirect url to my hosts file, so no more annoying “you have malware to here” pop up. I’ve scanned the c drive with malwarebytes and comodo av, so far no results for viruses/malware. I’ll try clamshell av and spybot search and destroy next. The aggravation did prompt me to add NoScript to firefox.

Anonymous
Anonymous

@Guy Fawkes

Once you get NoScript set the way you need it, it is very much your friend.
Michaelk42 recently posted..Unsurprisingly- Pogan gets no real punishment

Anonymous
Anonymous

I had to ctr-alt-del to shutdown firefox, malicious js is so FUCKING annoying. I stopped the nonsense by adding the redirect url to my hosts file, so no more annoying “you have malware to here” pop up. I’ve scanned the c drive with malwarebytes and comodo av, so far no results for viruses/malware. I’ll try clamshell av and spybot search and destroy next. The aggravation did prompt me to add NoScript to firefox.
Update – Clamwin gave me this: WARNING: Can’t open file C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\CardSpace\CardSpaceSP2.db: Permission denied
WARNING: Can’t open file C:\Documents and Settings\Administrator\Local Settings\Temp\fla102.tmp: Permission denied
Googling cardspacesp2.db came up with references to an incredibly nasty virus called virut? Anyone else get something similar? How did you get rid of it?

Anonymous
Anonymous

I cant access your website with firefox (I get a message about “cannot modify header” etc etc. But I CAN access your website with google chrome. I am posting this from it.

Anonymous
Anonymous

I feel your pain Carlos. This is unfortunately part of blogging. No provider or software is totally immune from it.

If it means anything, I have no issues. Looks fine to me, but I wasn’t here last night, and I am running a MAC.

Hang in there, as my mom used to say, “This too shall pass”.

SBG

Anonymous
Anonymous

I had the same trouble as CanadianGirl (#9). For days on end I kept seeing that same post as the newest. Everything seems to be back to normal now.

I dropped GoDaddy ages ago because I had many problems with their hosting and support. I found a better host and never looked back. Also switched to Drupal and haven’t had a problem since.

Anonymous
Anonymous

I can’t even access my admin page anymore. Go Daddy says they’ll have it fixed by Monday.

It’s too bad because I do have some important announcements to make, such as, PINAC will be migrated to a new photo site called http://pixiq.com.

I signed a contract over the weekend. I’ll be getting paid for my content. Everything else will stay the same except I will be blogging more because as I said, I will be getting paid.

I wanted to dedicate an entire post to this, but this virus screwed things up, so for those of you reading, this, now you know.

Anonymous
Anonymous

It’s A GoDaddy Miracle!

But seriously, good job on getting the paid gig.
Michaelk42 recently posted..Unsurprisingly- Pogan gets no real punishment

Anonymous
Anonymous

Sorry about the hack. I ventured over to see what was up when your feed hadn’t updated for three days. Hell of a birthday present.

But congratulations on the blogging deal!
mkhall recently posted..Move over and let HAL drive

Anonymous
Anonymous

how do you pronounce that? pixi-que? pix-ik?

congrats!

Anonymous
Anonymous

Sorry you were hacked, but your site looks fine on Mac running firefox, and chrome, ubuntu running firefox is good as well

Anonymous
Anonymous

well, i tried to tell you

Anonymous
Anonymous

This is one reason you never have anything of importance on shared hosting. You can get a virtual dedicated host which means you have full control (root access) to the entire thing for $300/year.

There’s a linux root worm going around right now for 64 bit systems but it doesn’t affect me because there has to be a malicious local user. Shared hosting will limited shell access will have local users; I do not.

Move to virtual dedicated hosting Carlos. I recommend it.
Difster recently posted..Lessons From Mexico

Anonymous
Anonymous

JR, which host do you have? I have GoDaddy for my site, which hasn’t yet been completed and posted.

Anonymous
Anonymous

It is important to stay current with wordpress versions. They continually battle the hackers and close up any exploits they find. WP 2.9.2 fixed a similar-sounding exploit and 3.something has since been released.

I got burned on a WP 2.8 version by the fix that 2.9.2 fixed – I had not gotten around to upgrading to the newer version.

Anonymous
Anonymous

You host with GoDaddy? What are you, some sort of masochist?

Anonymous
Anonymous

I was going month to month with Go Daddy but I was staying there out of comfort because every time I switch hosts, I end up going through all kinds of technical problems.

I used to host with Lunar Pages and they were the worst experience ever.

Anonymous
Anonymous

@Shawn: I’m using JustHost(.com) now and I am quite happy with them.

Anonymous
Anonymous

TotalChoiceHosting has alays been good to me.

Post new comment

Pixiq on Facebook

Join the 10192 Pixiq fans on Facebook

Share

  • Share

Subscribe

Get weekly updates from Pixiq. Short, sweet, and always interesting.