Update: It is not a “mass” attack as we described. Sorry about that. A good number of sites were affected (we don’t have a clear number yet), but nothing massive or crazy as our post sounded.
If you follow our blog, you probably noticed that these last few months have been specially hard for hosting companies. Lots of them got hacked, bringing down thousands of sites with them. Now we are hearing reports of a mass hack of WordPress blogs hosted on Rackspace.
What is going on?
The attackers were able to get access to Rackspace databases and infect the sites through there. They created a new admin user on many Worpress sites, giving them full access to the WordPress admin panel.
With that access they were able to inject malware, and as we saw before they used that to inject SEO spam to the sites.
What are the symptoms?
The second sympton is a new user “amin” on WordPress and some backdoors spread through the system.
This is not a new attack and we have fixed sites infected by that for more than a month. However, just now we are putting the dots together that all of them were on Rackspace.
Our friends from Unmask Parasites and Smackdown posted more details about the attack:
Note that the issues described in there do not happen on all the cases. If you have more information, let us know.
If your site is hacked (or contains malware) and you need help, send us an email at firstname.lastname@example.org or visit our site: http://sucuri.net. We can get your sites clean up right away.
Also, consider checking out our site security monitoring. We will monitor your sites 24×7 and alert you if it ever gets infected with malware, hacked or blacklisted.