WordPress hacked: googlerank.info
Thursday, March 6th, 2008It came to my attention in the last few days that a handful of people had been experiencing some errors when viewing this site. Many visitors had the site return a 404 Page Not Found error page, while others had their browser crash completely. One individual even reported that their anti-virus software had thrown a red flag while visiting this site. My first instinct was that one of the site’s plugins were causing the errors, but upon further investigation, I have found what I believe to be the catalyst: googlerank.info.
Before I begin describing the issue, I want to state that I do not have a permanent fix (though I do have a temporary one). The purpose of this post is to document my findings for anybody who has experienced the symptoms or is interested in helping me find and fix the underlying issue. I’ve found very little documentation on this problem thus far, so I’m hoping to provide some clarity to all others who may be searching for it.
Overview
A hidden <iframe> that points to googlerank.info has been found embedded into a handful of files that are associated with a WordPress installation. The <iframe> always appears at the very bottom of the source code, just before the </body> tag. It is possible that WordPress presents a vulnerability that allows an unauthorized user to access and alter files, thereby compromising the security of the site owner as well as the site’s visitors.


