[lbo-talk] Cleandraws.com infected?

// ravi ravi at platosbeard.org
Sat Mar 10 09:55:05 PST 2012


On Mar 10, 2012, at 12:44 PM, Doug Henwood wrote:
> In the course of visiting "Shag"'s delightful blog the other day, the first attempt redirected me to mystreamvideo.rr.nu/11f. It just happened again on a revisit. It looks like it installed some Java thing, which I force-quit through the Mac Activity Monitor.
>

I had pointed this out privately to Shag a few days ago. I don’t think it’s any Java thing (you might have killed some random innocent process via Activity Monitor :-)). I think whatever/whoever hacked into the site, if they did, are using either PHP or JavaScript redirects to point to the .ru site. Doesn’t reliably happen each time. When I get some time I will try to get at the source and try to figure out what’s going on.

Shag, given that this is now visible not just to me, I think you can conclude this is real intrusion and reinstall WordPress from scratch after removing the current installation and then change the DB passwords.

—ravi



More information about the lbo-talk mailing list