Just spent two days recovering from a hack attack at Cultofmac.com. The site was a seething cesspit of Viagra spam and — get this – Windows malware.
Looks like hackers compromised an FTP login to our host (a notorious weakspot), allowing the filthy scumbags to inject hidden spam into almost every post we’ve ever published (more than 3,500 articles).
The lowlifes also added a malware redirect to a couple of index.php files. The redirects were located inside hidden iframes, and took a bit of finding. Not sure how these manifested themselves, but they seem to have popped up in the site’s RSS feed. At least one reader seems to have been infected with the System Security 2009 Trojan and the Bloodhood PDF virus — both Windows malware. Sorry Chris!
Luckily, most of you guys are on the Mac, or I’d have a lot more apologising to do.
I’ve spent the last two days downloading the site database, doing a global search/replace to remove the spam and virus links, and the re-uploading the DB.
I changed all the logins/passwords to everything; killed a bunch of old and dodgy-looking accounts on the site and host; and locked down the site with WordPress plugins to prevent brute-force logins and the like.
Amazingly it all seems to have worked, because I’ve no idea what I’m doing.
There may be a few gremlins in the RSS feed. New feeds are working fine, but I’m unable to get my old feeds to update. If you’re having the same problem, just cross your fingers and we’ll all hope together that the problem magically fixes itself tomorrow, especially because I’ve got a major scoop.