I think my site was hacked….

  • Unknown's avatar

    Not every time, but occasionally, I get a link that pops up on the wp-login page ‘Katie fisher sex video’….I can’t figure out where it is coming from…I captured the html code and see this:

    <!DOCTYPE html>
    <!–[if IE 8]>
    <html xmlns=’http://www.w3.org/1999/xhtml’ class=’ie8′ lang=’en-US’>
    <![endif]–>
    <!–[if !(IE 8) ]><!–>
    <html xmlns=’http://www.w3.org/1999/xhtml’ lang=’en-US’>
    <!–<![endif]–>
    <head>
    <meta http-equiv=’Content-Type’ content=’text/html; charset=UTF-8′ />
    <title>Peak Harvest Coaching › Log In</title>
    <link rel=’stylesheet’ id=’buttons-css’ href=’http://peakharvestcoaching.com/wp-includes/css/buttons.min.css?ver=4.4.2′ type=’text/css’ media=’all’ />
    <link rel=’stylesheet’ id=’open-sans-css’ href=’https://fonts.googleapis.com/css?family=Open+Sans%3A300italic%2C400italic%2C600italic%2C300%2C400%2C600&subset=latin%2Clatin-ext&ver=4.4.2′ type=’text/css’ media=’all’ />
    <link rel=’stylesheet’ id=’dashicons-css’ href=’http://peakharvestcoaching.com/wp-includes/css/dashicons.min.css?ver=4.4.2′ type=’text/css’ media=’all’ />
    <link rel=’stylesheet’ id=’login-css’ href=’http://peakharvestcoaching.com/wp-admin/css/login.min.css?ver=4.4.2′ type=’text/css’ media=’all’ />
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-includes/js/jquery/jquery.js?ver=1.11.3′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/modernizr-2.0.js?ver=2.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/superfish.js?ver=1.4.8′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/jquery.prettyPhoto.js?ver=3.1.2′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/jquery.nivo.slider.js?ver=2.5.2′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/easyTooltip.js?ver=1.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/jquery.loader.js?ver=1.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/cufon-yui.js?ver=1.09i’></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/Aller_italic_400.font.js?ver=1.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/cufon-replace.js?ver=1.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-includes/js/swfobject.js?ver=2.2-20120417′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/jquery.cycle.all.js?ver=2.99′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/audiojs/audio.js?ver=1.0′></script>
    <script type=’text/javascript’ src=’http://peakharvestcoaching.com/wp-content/themes/theme1357/js/custom.js?ver=1.0′></script>
    <meta name=’robots’ content=’noindex,follow’ />
    </head>
    <body class=’login login-action-login wp-core-ui locale-en-us’>
    <div id=’login’>
    <h1>Peak Harvest Coaching</h1>

    <form name=’loginform’ id=’loginform’ action=’http://peakharvestcoaching.com/wp-login.php’ method=’post’>
    <p>
    <label for=’user_login’>Username
    <input type=’text’ name=’log’ id=’user_login’ class=’input’ value=” size=’20’ /></label>
    </p>
    <p>
    <label for=’user_pass’>Password
    <input type=’password’ name=’pwd’ id=’user_pass’ class=’input’ value=” size=’20’ /></label>
    </p>
    <p class=’forgetmenot’><label for=’rememberme’><input name=’rememberme’ type=’checkbox’ id=’rememberme’ value=’forever’ /> Remember Me</label></p>
    <p class=’submit’>
    <input type=’submit’ name=’wp-submit’ id=’wp-submit’ class=’button button-primary button-large’ value=’Log In’ />
    <input type=’hidden’ name=’redirect_to’ value=’http://peakharvestcoaching.com/wp-admin/’ />
    <input type=’hidden’ name=’testcookie’ value=’1′ />
    </p>
    </form>

    <p id=’nav’>
    Register | Lost your password?
    </p>

    <script type=’text/javascript’>
    function wp_attempt_focus(){
    setTimeout( function(){ try{
    d = document.getElementById(‘user_login’);
    d.focus();
    d.select();
    } catch(e){}
    }, 200);
    }

    wp_attempt_focus();
    if(typeof wpOnload==’function’)wpOnload();
    </script>

    <p id=’backtoblog’>← Back to Peak Harvest Coaching</p>

    katie fisher sex video </div>

    <link rel=’stylesheet’ id=’jetpack_css-css’ href=’http://peakharvestcoaching.com/wp-content/plugins/jetpack/css/jetpack.css?ver=3.9.1′ type=’text/css’ media=’all’ />
    <div class=’clear’></div>
    </body>
    </html>

    I don’t know who wholegraindesign.com is — and the link itself doesn’t actually go to a page.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar

    Hello, I noticed that you’re referring to a wp-login page meaning it’s self-hosted WordPress.ORG site. Please note that this is WordPress.COM therefore we are unable to help with any blogs that are not hosted here.

    Here’s a helpful article to better understand the differences between WordPress.COM and WordPress.ORG:
    http://support.wordpress.com/com-vs-org/

    You can get help for your site at the WordPress.org forums here:
    https://wordpress.org/support/

    You’ll need a WordPress.org account to post to the forums. If you don’t have one yet, please register here:
    https://wordpress.org/support/register.php

  • What is the URL of your WordPress site?

  • The topic ‘I think my site was hacked….’ is closed to new replies.