There is more information about these two exploits. It is not just limited to php-based blogs and forums – larger sites, such as Tennis.com, Variety.com, and Coldwellbanker.com have been hit with this exploit, along with over 2,300 other websites. The average internet surfer will discover that their machine is infected with this virus when they realize their Google search results in Internet Explorer and Firefox have been hijacked – clicking on the result you want will take you to some other site. The virus will also go one step further and look for any FTP credentials on your machine in order to inject the script onto more websites. Some sites have reported that the script can also modify the permissions of specific directories to give them access to write in the files within.
What does this mean to website owners?
- Up to an hour (or more, depending on size) of cleaning up and rebuilding each site infected.
- Visitors receiving warning messages through their browser or security software that your site is dangerous.
- Possibility of being de-listed by Google to prevent spreading the virus.
So how do you protect yourself, the average internet surfer?
- Update your Flash Player to the latest version.
- Update your security software and scan for spyware / viruses.
How do you clean your infected WordPress site?
- First, protect your machine as listed above. Uploading files onto your website from an infected machine will just lead to more injections of the script later.
- The newer scripts also add an images.php and/or gifimg.php file with the malicious code to many or all of your images directories, from the main one down to image directories in themes, plugin folders, and so on.
How do you protect your website from further attacks?
- For WordPress, apply recommended security measures listed in the following articles: WordPress Security Tips, How to Stop Your WordPress Blog Getting Hacked, WordPress Security.
- Do not save/remember your FTP credentials or administrative logins to your websites. Also, be sure to use a secure FTP client.
- Keep a clean backup of the latest changes you have made to your site. The better your backup, the faster your rebuild process if this happens to you.
Thanks to Kristi the owner and author of the Kikolani blog for this great follow up article.