Skip to content

Comment on Ask HN: I can't tell why my site is showing malware warning.

Comments

What we have been seeing that web-malware that appears intermittently, only appearing to certain browsers and not appearing twice in a row to the same browser/IP, is usually pushed in via a FTP credential compromise.

The code often resides in template file, in config files and/or sometimes is also put into the database.

We've seen a lot of these kind of "intermittent" malware through the recent timthumb attacks on WP sites:http://www.stopthehacker.com/2011/08/30/timthumb-malware/

You've already got a lot of good information from the other responders, so I will not repeat the obvious, but great, points. Change password, check plugins..

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.