WordPress users report hacked blogs

Share this article:

Some WordPress users running the latest version of the popular blogging software are complaining that their sites have been compromised to point users to malicious websites, an IT security monitoring firm said Friday.

The targeted sites appear to be those hosted by Network Solutions, according to a blog post from Sucuri Security, citing reports from its clients.

"What is interesting about this attack is that it does not create or modify any files, so the average security advice does not apply here," the post said. "The only thing [it] does is to modify your 'siteurl' inside the 'wp-option' table to point to http://networkads[dot]net/grep/, breaking the site layout completely."

SQL injections or a larger database problem at Network Solutions may be the cause, according to Sucuri.

But Network Solutions spokeswoman Susan Wade said the problem is not specific to blogs hosted by the company.

"This issue is not isolated to Network Solutions, nor is it a Network Solutions server issue," she told SCMagazineUS.com in an email. "We're working with the experts in the WordPress community and understand it is an issue with a WordPress plug-in or theme and it is impacting a number of websites that are hosted on various hosting platforms. 

Network Solutions offered more information here.

Sucuri recommended affected users "revert your siteurl back to the previous value. Log in to your control panel, go to 'manage database,' and edit the siteurl value on 'wp-option table.'"

In recent months, WordPress has become a popular vector to spread malware.

"In a typical scenario, a security vulnerability is discovered and patched, but many website owners running WordPress do not install the updated version of the WP software, leaving their sites open to the exploits that inevitably follow," Maxim Weinstein, executive director of StopBadware, a nonprofit aimed at fighting bad software on the internet, said in a 2009 blog post. "WordPress plug-ins are sometimes vulnerable, as well."

Share this article:

Sign up to our newsletters

More in News

In Cisco probe, misuse or compromise spotted on all firms' networks

In Cisco probe, misuse or compromise spotted on ...

Cisco analyzed the business networks of 30 multinational companies last year, and revealed the findings in its 2014 Annual Security Report.

Fareit trojan observed spreading Necurs, Zbot and CryptoLocker

The Necurs and Zbot trojans, as well as CryptoLocker ransomware, has been observed by researchers as being spread through another trojan, known as Fareit.

Post Heartbleed, tech giants join initiative to bolster open source

Post Heartbleed, tech giants join initiative to bolster ...

The newly formed Core Infrastructure Initiative, created to boost under-funded open source projects, will tackle OpenSSL first.