{"id":864,"date":"2011-08-23T04:21:00","date_gmt":"2011-08-23T04:21:00","guid":{"rendered":"http:\/\/2slick.com\/web\/?p=864"},"modified":"2012-04-24T08:47:06","modified_gmt":"2012-04-24T08:47:06","slug":"somethings-not-right-here","status":"publish","type":"post","link":"https:\/\/2slick.com\/web\/somethings-not-right-here\/affordablewebsitestips\/tutorials","title":{"rendered":"Something&#8217;s Not Right Here!"},"content":{"rendered":"<p>If you've gone to your WrodPress website, in the Chrome browser and have seen this message:<\/p>\n<p>Warning: Something's Not Right Here!<br \/>\ncontains content from counter-wordpress.com, a site known to distribute malware. Your computer might catch a virus if you visit this site...<\/p>\n<p><a href=\"http:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/Warning_Something_not_right_here.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-950\" title=\"Warning_Something_not_right_here\" src=\"http:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/Warning_Something_not_right_here.jpg\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/Warning_Something_not_right_here.jpg 600w, https:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/Warning_Something_not_right_here-300x150.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Then your WordPress website has most likely fell victim to a hacker exploiting the vulnerability in your <strong>Timthumb.php<\/strong> file. The truth is, there's no telling what someone can do once they're able to get into your website like this. There is trend in what scripts are hacked and they can sometimes be easily fixed.<\/p>\n<h3>Timthumb.php Vulnerability Common Fixes<\/h3>\n<p><strong>First we'll update your timthumb.php file so that this vulnerability is gone.<\/strong><br \/>\nUse an FTP program to replace your\u00a0vulnerable\u00a0timthumb.php file code with this newer version (<em>Back up your original timthumb.php code before updating it just incase the new version brakes your site<\/em>): <a title=\"timthumb.php zipped\" href=\"http:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/timthumb.zip\" target=\"_blank\">timthumb.php zipped<\/a><\/p>\n<p><strong>Next we're going to clean out the most common infected files for this type of exploit.<\/strong> These files are the ones in your 'script' directory of the custom WordPress theme and your config.php file in the root of your install. Here's some instructions on how to replace the files:<\/p>\n<ol>\n<li>Connect to your website via <a title=\"free ftp program\" href=\"http:\/\/filezilla-project.org\/\" target=\"_blank\">FTP<\/a><\/li>\n<li>Unzip the custom WordPress theme, that you used for your WordPress website, into a directory on your computer.<\/li>\n<li>Download the 'scripts' from your WordPress website: 'wp-content\\themes\\<span style=\"color: red;\">yourthemefolder<\/span>\\scripts' then delete the 'scripts' folder on your server.<\/li>\n<li>Upload the scripts folder that you just unzipped from your theme into the\u00a0'wp-content\\themes\\<span style=\"color: red;\">yourthemefolder<\/span>\\' on your server. Now most of the hacked files should be replaces.<\/li>\n<li>Download the 'wp-config.php' from the root directory of your WordPress install. Open this file in notepad or a code editor. This file should be about ~90 lines long. If your file is much longer then this and or has extremely large blank spots in the code (over 30 lines long) it's probably been tampered with.<br \/>\nSo an infected wp-config.php file will have about ~90 lines or proper code, a ton of blank lings, a bunch of \u00a0lines of hacking code, a ton of blank lines again then the end of the\u00a0document. Back this hacked file up as wp-config_hacked.php and create a duplicate of it.<\/li>\n<li>Highlight the blank lines of code, the hacking code that's between them and delete it all.<\/li>\n<li> Save this file as wp-config.php<\/li>\n<li> Upload your new wp-config.php into the root directory of your WordPress install replacing the current one that's there.<\/li>\n<\/ol>\n<p><!--nextpage--><\/p>\n<p><strong>Now we're going to test to see if your site's fixed.<\/strong><\/p>\n<ol>\n<li>Open a new tab in your Chrome browser and type in the page of your website that previously caused the error to\u00a0occur.<\/li>\n<li>Hold down the 'Ctrl' key, the 'Shift' key, and press the 'Delete' key.<\/li>\n<li>Check the boxes 'Clear browsing history', 'Empty the cache' and 'Delete cookies and other site and plug-in data'.<br \/>\n<a href=\"http:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/clear_browsing_data_chrome.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-961\" title=\"clear_browsing_data_chrome\" src=\"http:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/clear_browsing_data_chrome.jpg\" alt=\"\" width=\"602\" height=\"401\" srcset=\"https:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/clear_browsing_data_chrome.jpg 602w, https:\/\/2slick.com\/web\/wp-content\/uploads\/2011\/08\/clear_browsing_data_chrome-300x199.jpg 300w\" sizes=\"auto, (max-width: 602px) 100vw, 602px\" \/><\/a><\/li>\n<li>Click the 'Clear browsing data' button.<\/li>\n<li>return to the tab of your browser that produced the error page, hold down 'Ctrl' while you press the 'F5' key to refresh the page.<\/li>\n<\/ol>\n<p>Hopefully the error is gone and your site is fixed. If not contact your web host and tell them your site's been compromized and they should scan your site for injection scripts etc. There is also a chance Google flagged your site and you will have to request to be delisted even after the threats are removed from your site.<\/p>\n<p>If you are seeing a Google Attack Page when you visit the site, use the  steps below to request that Google review the site and hopefully remove  this block.<\/p>\n<p>This excerpt was copied from the URL below, and provides step by step instructions to request a delisting.<\/p>\n<p><a title=\"google delist website\" href=\"http:\/\/www.google.com\/support\/webmasters\/bin\/answer.py?answer=45432\" target=\"_blank\">http:\/\/www.google.com\/support\/webmasters\/bin\/answer.py?answer=45432<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you&#8217;ve gone to your WrodPress website, in the Chrome browser and have seen this message: Warning: Something&#8217;s Not Right Here! contains content from counter-wordpress.com, a site known to distribute malware. Your computer might catch a virus if you visit this site&#8230; Then your WordPress website has most likely fell victim to a hacker exploiting [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":950,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,4,6],"tags":[156,158,157,159,164,69,155],"class_list":["post-864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-affordablewebsitestips","category-tutorials","category-wordpress","tag-attack","tag-malware","tag-timthumb","tag-virus","tag-vulnerability","tag-wordpress-2","tag-zero-day"],"_links":{"self":[{"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/posts\/864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/comments?post=864"}],"version-history":[{"count":17,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/posts\/864\/revisions"}],"predecessor-version":[{"id":2474,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/posts\/864\/revisions\/2474"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/media\/950"}],"wp:attachment":[{"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/media?parent=864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/categories?post=864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2slick.com\/web\/wp-json\/wp\/v2\/tags?post=864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}