{"id":1070,"date":"2012-10-24T18:32:40","date_gmt":"2012-10-25T01:32:40","guid":{"rendered":"http:\/\/www.hickendesign.com\/site\/?p=1070"},"modified":"2017-05-31T21:40:51","modified_gmt":"2017-06-01T04:40:51","slug":"unhacking-a-hacked-wordpress-site","status":"publish","type":"post","link":"https:\/\/www.hickendesign.com\/site\/2012\/10\/unhacking-a-hacked-wordpress-site\/","title":{"rendered":"Unhacking a Hacked WordPress Site"},"content":{"rendered":"<p>WordPress is pretty solid these days but every now and then, an exploit is found and taken advantage of. Recently we cleaned several websites who had all fallen prey to an exploit which modified every php file on the server.<\/p>\n<p>The exploit added a malicious &lt;script&gt; tag to the very beginning of each php file. Since the modifications to these files were all uniform, it was fairly easy to undo the damage. The code added to each file looked something like this&#8230;<br \/>\n<code><\/code><\/p>\n<pre>&lt;?php \/**\/ eval(base64_decode(\"aWYoZnVuY3Rpb25...    ...B9ICB9\"));?&gt;<\/pre>\n<p>It was a big long string of characters that made no sense until decoded.\u00a0 Our solution was to use a php page that could repair the damage. Thanks to <a href=\"http:\/\/theandystratton.com\/2010\/godaddy-shared-linux-hosting-hack-fix\" target=\"_blank\">theandystratton<\/a> for providing a good starting point.<\/p>\n<p>You can upload this file to the root folder of your server and then visit it in a web browser.\u00a0 It will first find all infected php files.\u00a0 Then you can click the &#8220;Fix Files&#8221; button and the malicious code is removed for you.\u00a0 If you intend to use this script, please know that we take no liability for it.\u00a0 That said, our clients have had great success with it.<\/p>\n<p><a href=\"http:\/\/www.hickendesign.com\/site\/wp-content\/uploads\/2012\/10\/repairHackedSite.php_.txt\">_repairHackedSite.php<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress is pretty solid these days but every now and then, an exploit is found and taken advantage of. Recently we cleaned several websites who had all fallen prey to an exploit which modified every php file on the server. The exploit added a malicious &lt;script&gt; tag to the very beginning of each php file. &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.hickendesign.com\/site\/2012\/10\/unhacking-a-hacked-wordpress-site\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Unhacking a Hacked WordPress Site&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-1070","post","type-post","status-publish","format-standard","hentry","category-technical"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/posts\/1070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/comments?post=1070"}],"version-history":[{"count":7,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/posts\/1070\/revisions"}],"predecessor-version":[{"id":1081,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/posts\/1070\/revisions\/1081"}],"wp:attachment":[{"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/media?parent=1070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/categories?post=1070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hickendesign.com\/site\/wp-json\/wp\/v2\/tags?post=1070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}