Pharma hack (3 posts)

  • Seems that the pharma hack for Wordpress (where hackers change how your title appears in serps and add links to articles) is a consistent nuisance for Wordpress blogs.

    I’ve read a number of guides on how to get rid of it but many still report being re-infected a few months later.

    Anyone have any experience with getting rid of this nuisance once and for all?

  • @adigaskell That one has been around for awhile. One of the most popular posts on it is this one by the creator of the Thesis WordPress theme: http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php

    For those site it keeps recurring on, it’s because the site owner hasn’t found the “backdoor” file that the hack leaves on your website to regenerate the malicious code. I had a different hack hit my website and wrote about cleaning it in this post back in 2010: http://kikolani.com/latest-wordpress-hack-symptoms-solutions-resources.html

    The other thing that’s really terrible about it is if you have multiple websites on one hosting account, the hack can spread through all of the files on those websites. I had to clean through 10 at one point – it hit every PHP and Javascript file throughout all of the WordPress installs. Plus it stuck the backdoor PHP file in a random images folder that you normally wouldn’t think to check for issues. It’s a real mess to deal with indeed, but if you take the time cleaning it up the first time, then you shouldn’t have to go through it again.

    Oh, also check your own computer out – sometimes the hacks originate from virus files on your own computer that find your FTP information if it’s saved in an FTP program.

  • that one is a bugger. the first time I just removed the code by using a script – not knowing that it had planted itself elsewhere. The next time I went file by file – total manual recover. That did suck.


Add your voice to the discussion

Existing members: . If you do not have a SME account, .