Watch Out for Recent WordPress Gumblar PHP Exploit

May 12, 2009 · 96 comments

Kristi wrote a guest blog post at TechJaws about the attack last weekend on her well known Kikolani Blog by the PHP Script Injection Exploit in WordPress 2.7.1.  Kristi explains how she restored her blog and dealt with the issue. The UnMask Parasites blog provides additional details on what is known about this particular malware which has been dubbed the Gumblar .cn Exploit.

Gumblar exploit does NOT affect only WordPress. It can target any site using .php including Drupal, PhotoPost and even the Bangalore Telecom Web site.

The resources below will assist you in assessing your risk, increasing security for your WordPress blog and removing this exploit if you are already affected.

WordPress Security Resources:

Security Monitoring Tools for WordPress:

WordPress Security Audit Services:

WordPress Security Plugins:

Read the Best of GrowMap or Stay In The Loop!

Subscribe to the GrowMap feed via RSS or Email to receive notifications when new posts are published. Follow GrowMap on Twitter too!

{ 94 comments… read them below or add one }

stratosg May 12, 2009 at 6:16 pm

Twitter: @morpheas7887

Thanks for the mention! I wonder why all this fuss about security started this particular time…

stratosg’s last blog post..Should you be concerned about your WordPress security?

Reply

InternetStrategist from GrowMap.com May 12, 2009 at 7:02 pm

Twitter: @GrowMap

Whenever a well known blog is targeted other bloggers are more likely to hear about it – especially if that blogger guest posts in another well-known blog about it.

Given the huge number of WordPress blogs and the likelihood that a very large percentage of them would not have taken any security precautions I felt now was a good time to cover this subject.

As frequently happens, other bloggers have just posted updated information that makes my style of researching and publishing in an overview useful. As you probably know security doesn’t usually get addressed until there is a scare or incident.

InternetStrategist’s last blog post..The Serious Drawbacks to Using FLASH for Web Design: Usability, SEO, Editability

Reply

ken from Sushi May 13, 2009 at 1:09 am

Yeah, people doing this stuff shouldn’t target big blogs. After a big blog is hit it’s only the matter of time before someone creates a solution to the whole problem.

Reply

InternetStrategist from GrowMap.com May 14, 2009 at 9:38 pm

Twitter: @GrowMap

Hi Ken,

Ideally it would be great if spammers,scammers, and crackers would find something productive to do with their lives instead of wasting our time. Not much chance that will happen though so we’ll do what we can to control the damage they cause.

InternetStrategist’s last blog post..New Type of Scraped Comment Blog Spam

Reply

Jeff May 13, 2009 at 12:11 pm

If someone is competent enough to hack a website you would think they wouldn’t need to waste their time doing it!

There are exploits out all the time that are not targeted because the majority of competent programmers don’t waste there time but every once in awhile I hear about something like this what a waste of talent!

Jeff’s last blog post..What’s Jeff’s Scam, Niche Marketing

Reply

InternetStrategist from GrowMap.com May 14, 2009 at 9:42 pm

Twitter: @GrowMap

Absolutely! Surely there are productive projects they could be working on. If they’ll work on something useful I’ll even help promote them. I would much rather spend my time on that than fixing what they break.

InternetStrategist’s last blog post..Intelligent Bloggers to Consider Reading

Reply

Ty May 18, 2009 at 9:13 am

well what do when you have been attacted how do you fix the problem?!?!

Reply

InternetStrategist from GrowMap.com May 18, 2009 at 4:50 pm

Twitter: @GrowMap

Hello Ty,

The solutions are provided in the links that I shared in the post. Krista explained what she had to do to remove it in one of the first links I shared here. You may wish to request assistance from someone with advanced technical skills. I would definitely have to do that if my blogs were affected.

InternetStrategist’s last blog post..Be Pro-Active and Take Calculated Risks

Reply

Mike L from Makeup and Vanity Mirrors June 13, 2009 at 1:40 am

Nice linking in the amazing post. Its very informative post for me and my friends. I will share this with another to provide them a very useful information.

Reply

mark from almond flavored coffee June 17, 2009 at 4:21 pm

Twitter: @ChugginMcCoffee

I didn’t know that Gumblar exploit targeted other blogs than WordPress – so good to know because I know that myself and several friends don’t take these type of security precautions with our blogs right now!

Reply

Internet Strategist from GrowMap June 18, 2009 at 5:18 pm

Twitter: @GrowMap

Hi Mark,

Yes, I thought some might be interested in what other types of sites are at risk. How’s the coffee biz going? I don’t drink it myself so the only thing I remember is how expensive it got way back when I was still in school – ancient history.

Internet Strategist’s last blog post..Select Keywords First to Make Your Content Easy to Find

Reply

Oklahoma business listing June 26, 2009 at 10:39 am

Really it is nice post and thanks for sharing it and really it is very useful. I would love some feedback on my site Oklahoma business address when you got time.

Reply

Oregon business listing June 26, 2009 at 10:40 am

I can see that you are an expert at your field! I am launching a website soon, and your information will be very useful for me.. Thanks for all your help and wishing you all the success in your business Thanks for all your help and wishing you all the success in your business Feel free to check out my site Oregon business address when you got time.

Reply

rasim from Download Free Remove Spyware Adware June 27, 2009 at 2:57 pm

thanks for the keywordluv plugin. I wish more sites would follow.

Reply

James from it jobs in Dubai July 7, 2009 at 3:22 am

I am using Drupal for my blog and I be very careful now thanks for your post it will be very helpful for me. Keep posting

Reply

Internet Strategist from GrowMap July 23, 2009 at 5:26 pm

Twitter: @GrowMap

Hi James,

Glad to be of service. Are there many IT jobs in Dubai? I added your site to StumbleUpon and Tweeted it in case others are seeking jobs there.
.-= Internet Strategist @GrowMap´s last blog ..How to Add Your Business to Merchant Circle =-.

Reply

Kate Henlay from copywriting July 9, 2009 at 4:49 am

I hope solution is already provided.

Reply

Internet Strategist from GrowMap July 23, 2009 at 5:26 pm

Twitter: @GrowMap

Hi Kate,

Yes, there are solutions in the links I provided in this post.
.-= Internet Strategist @GrowMap´s last blog ..How to Add Your Free Business Listing to infoUSA =-.

Reply

Pet Medication July 10, 2009 at 6:42 am

Superb list of wordpress guides collections shared here. I’m new to blogging and wordpress, but these articles really gives a good guide for new users like me. Glad to find this post.
.-= Pet Medication´s last blog ..Pet Medicine =-.

Reply

Internet Strategist from GrowMap July 23, 2009 at 5:29 pm

Twitter: @GrowMap

Hi Pet,

There are many posts here that will assist you, especially Selecting Keywords which explains how to make sure your posts and Web pages are easy to locate in the search engines.
.-= Internet Strategist @GrowMap´s last blog ..How to Create and Install Favicons =-.

Reply

John from Ent Services July 14, 2009 at 5:38 am

Thanks for highlighting the exploits. Apparently my wordpress was hacked earlier with some russian guy stuffing russian site links in my index file.

Reply

Internet Strategist from GrowMap July 23, 2009 at 5:30 pm

Twitter: @GrowMap

Hi John,

I am sorry to hear you were hacked. I hope you have since recovered and added more security.
.-= Internet Strategist @GrowMap´s last blog ..How to Write a Review at Merchant Circle =-.

Reply

Jerome P July 20, 2009 at 12:55 pm

Great article! We had a hack on one of our blogs that placed several dozen links to overseas pharmacy sites. We adjusted all passwords and have has no issue since. Internet Media Brands

Reply

Internet Strategist from GrowMap July 23, 2009 at 5:32 pm

Twitter: @GrowMap

Hi Jerome,

Sorry to hear you were hacked and glad you have recovered. Are you planning to build any affiliate stores on your domains? If you are I can recommend some tools and merchants you may wish to use. There will be more posts on that subject in the future here so if you’re interested you may want to subscribe.
.-= Internet Strategist @GrowMap´s last blog ..How to Add Your Free Business Listing to infoUSA =-.

Reply

Adam from blazing bumblebee August 13, 2009 at 2:31 am

I thought this was only for Wordpress. Will have to take a look at some of my other sites now. :(

Reply

UK company formation August 16, 2009 at 6:20 am

Excellent links given on wordpress plugins. I am relatively new to this system as it is providing superb management on daily updated contents. I was planning to use drupal earlier but many friends have advice me to go for wordpress instead. Now, I know why they have ask me to use wordpress.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:01 pm

Twitter: @GrowMap

Welcome UK,

While there are some who will recommend Drupal too, there is far more activity and many more plugins already written for WordPress. You may also be interested in our posts about growing any business and especially How to Start a Successful Blog Based Business
.-= Internet Strategist @GrowMap´s last blog ..Instantly Acquire 76 High Quality Incoming Links =-.

Reply

Zicam Lawsuit Attorneys August 17, 2009 at 2:29 am

I am always concerned about my Wordpress security vulnerabilities. If you use the right plugins you can make it a lot more inconvenient for your system to be hacked. Thank you for the links, I recommend that everyone looks over them.
.-= Zicam Lawsuit Attorneys´s last blog ..Longview attorneys file more lawsuits against makers of Zicam – Southeast Texas Record =-.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:02 pm

Twitter: @GrowMap

Hello Zicam,

Any site can be hacked so we all have to be wary and plug any security flaws that are identified. Wouldn’t it be great if hackers would find something more useful to do?
.-= Internet Strategist @GrowMap´s last blog ..Social Networking is NOT Chat =-.

Reply

mark from bunn coffee filters August 18, 2009 at 3:48 pm

Twitter: @ChugginMcCoffee

Hey, I appreciate those resources for finding out your WordPress security risk. WordPress is a huge learning process, so that’s always why I look for more information to make sure that I am not missing anything when it comes to my blog. That would be a terrible mistake!

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:03 pm

Twitter: @GrowMap

Hi Mark,

There will always be more to learn so collaborating and sharing what we find can really save time. I appreciate you being one of my most regular commentators. Thank you.
.-= Internet Strategist @GrowMap´s last blog ..How to Evaluate Your AdWords Accounts =-.

Reply

john from plymouth web design August 30, 2009 at 11:55 am

Strong set of resources tips, thank you. I don’t think this resource has been mentioned: http://digwp.com/ but these guys have some great suggestions regarding WP security.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:05 pm

Twitter: @GrowMap

Thank you, John, for sharing that additional resource.
.-= Internet Strategist @GrowMap´s last blog ..How to Evaluate Your AdWords Accounts =-.

Reply

Steven from Semenax September 14, 2009 at 6:57 pm

A bit off topic…just wanted to ask you for some hlep.

I’m using Wordpress verison 2.6.1 and I got hacked a few days ago…some bastard really screwed up my site.

I was wondering if you’ve been hacked and how you fixed it….how do you find the leak?
.-= Sharon@Steve@Semenax´s last blog ..Fruit, Veggies, and a Side Order of Sex | Foods To Increase Libido =-.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:08 pm

Twitter: @GrowMap

Hi Steven,

I remember your question and thought I had answered it. We lost power suddenly and I may have lost it along the way. I rely on others for technical support so if I did get hacked – which thankfully has not happened – I would have to get them to assist.

If someone needed assistance with their WordPress blog I would recommend they contact Sammy Russo at Search Friendly Web Design.
.-= Internet Strategist @GrowMap´s last blog ..
How to Optimize Your PPC Advertising to Benefit YOU =-.

Reply

Tony from Baby Cot September 18, 2009 at 4:33 pm

After reading a bunch of exploit news I started increasing the time my database backup plugin sends me a backup to my email. If anything happens to any of my blogs I can restore it with the backup. If anyone doesn’t use a backup plugin you should get one asap. It will help out even if you make a mistake on your side and lose precious data
.-= Tony@Baby Cot´s last blog ..Baby Cot Furniture =-.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:12 pm

Twitter: @GrowMap

Hi Tony,

Thank you for sharing that excellent tip. You are absolutely correct. After Derek Semmler had hosting failure I checked with him and he assures me he has backups of our sites emailed to him regularly so we won’t lose anything should our host lose a server or get hacked.

For those who don’t know, you can restore an entire site from the last backup you have so you want to have backups sent as frequently as you tend to update content. If you make any major changes you will want a fresh backup asap.
.-= Internet Strategist @GrowMap´s last blog ..Local Search Directory Taps the Power of Television =-.

Reply

Ben from Maybelline October 1, 2009 at 7:03 pm

Backup and update! ALWAY AND ALWAYS. Nice post!
.-= Ben@Maybelline´s last blog ..Maybelline XXL Mascara – FREE! =-.

Reply

Internet Strategist from GrowMap October 2, 2009 at 2:13 pm

Twitter: @GrowMap

Hi Ben,

You know many people don’t know how to backup and aren’t doing it. Most only start after they’ve had their first major loss. Perhaps this post will motivate them to take action sooner instead of after it is too late.
.-= Internet Strategist @GrowMap´s last blog ..Success IS a Numbers Game =-.

Reply

ryan from chicco car seat October 11, 2009 at 10:24 pm

Thanks for this very informative information. This is a good view to know things about .php
.-= ryan@chicco car seat´s last blog ..Chicco Baby Products – Introduction =-.

Reply

jON from Facial Hair Removal October 15, 2009 at 10:41 pm

Well that, that is interesting. I guess I will have to keep updating my wordpress so I make sure that I dont get screwed over.
.-= jON@Facial Hair Removal´s last undefined ..If you register your site for free at =-.

Reply

growmap February 23, 2010 at 9:10 am

Twitter: @GrowMap

Yes Jon, it is unfortunate that some dedicate their lives to causing problems for others. If they are smart enough to do that one would hope they could find something more productive and beneficial to focus on.
.-= growmap´s last blog ..KeywordLuv: How Using It Benefits Us All =-.

Reply

Used stair lifts October 29, 2009 at 10:33 am

Thanks for the notice. I will keep a lookout.
.-= Used stair lifts´s last blog ..Replace stair lift battery =-.

Reply

Replace parts of electric wheelchairs October 29, 2009 at 10:35 am

I just got hit by Gumblar. Everyone beware.

Reply

letter opener as christmas gift October 31, 2009 at 3:20 am

Will the anti virus detect it?
.-= letter opener as christmas gift´s last blog ..Promotional letter opener for marketing events =-.

Reply

growmap February 23, 2010 at 9:12 am

Twitter: @GrowMap

I would guess probably not.

Reply

sticker printing November 3, 2009 at 4:21 pm

Twitter: @muqtada123

I have seen the same thing with our website admin, someone told me a small script basically a SQL injection which can pass me easily through every admin of my website, i informed my IT manager to take care of this and after a few days, i went there again and put the same injection script but this time an awful message appeared which is basically for the person who is accessing that admin with SQL injection or you can say me for the time being but when i asked my manger that what is its remedy and tell me the way, he did not tell me anything but later on i got it from some forum where i got my manager’s username who is asking the same answer and i got a solution from there. Its basically hacking but a kinda cool hacking. :)

Reply

Adam from Eyeclops Night Vision Goggles November 9, 2009 at 11:56 pm

Thanks for the heads up about this matter. I just started using WP about 6 weeks ago and have noticed this kind of thing happens a lot…i guess thats the downside of using the platform…in any case, staying in tune will help us all remove these types of threats.
.-= Adam @ Eyeclops Night Vision Goggles´s last blog ..Eyeclops Night Vision Binoculars =-.

Reply

growmap February 23, 2010 at 9:14 am

Twitter: @GrowMap

Hello Adam,

I don’t hear about these types of issues too often. Given the huge number of WordPress blogs we are fortunate there aren’t more of these problems.
.-= growmap´s last blog ..KeywordLuv: How Using It Benefits Us All =-.

Reply

Aaron from Huffy Green Machine 2 November 11, 2009 at 12:43 am

Im pretty sure the anti virus wont be able to protect it unfortunately…
.-= Aaron @ Huffy Green Machine 2´s last blog ..Huffy Pink Green Machine =-.

Reply

water purifier November 16, 2009 at 6:52 am

Great post. I guess we’ll just have to be more aware…

by Anz with where to buy water purifier
.-= water purifier´s last blog ..Ultraviolet (UV) Water Purifier =-.

Reply

house lighting November 16, 2009 at 6:55 am

any other ways to restore it?

ac and the house lighting

Reply

growmap February 23, 2010 at 9:15 am

Twitter: @GrowMap

All bloggers need to be aware that in order to restore any site there needs to be a backup (ideally a CURRENT backup). While most better hosting companies should do this for you it is unwise to rely on that. It is better to set up backups that are automatically emailed to you.
.-= growmap´s last blog ..MEME: BizLuv in Support of Small Businesses =-.

Reply

from gmail.com' rel='external nofollow' class='url'>Computer Maintenance November 17, 2009 at 2:20 am

One reason why everyone should regularly upgrade to the latest version of WP. Hope this exploit has been handled in 2.8.6!

Reply

Computer Maintenance Guide November 18, 2009 at 2:54 am

There’s a lot of talk about hacks to WP based sites. It’d be great if you can write a post about what to do after such a hack. A clear step-by-step guide or something would help.
.-= Computer Maintenance Guide´s last blog ..Delete Temporary Files/Cache and Speed Up Your Computer =-.

Reply

Internet Strategist from GrowMap November 20, 2009 at 5:16 pm

Twitter: @GrowMap

Hello,

Security is a specialty that I usually leave to experts. Although I have a very technical background I rely on others to adminstrate technical aspects in my blogs. I did include a link to how to recover from this one and will gladly update this post with any other relevant links I find or that my readers can suggest.
.-= Internet Strategist @GrowMap´s last blog ..Best of GrowMap: Our Pillar Foundation Content =-.

Reply

folders printing November 18, 2009 at 6:32 pm

Twitter: @muqtada123

There must be some helpful plug ins for WP to protect them with these PHP exploits and as well as the other stupid hacking techniques, i know there must be but needs an expert suggestion.

Reply

SPORTS PICKS November 23, 2009 at 12:02 am

Twitter: @PicksNetwork

They have to figure out something, but then the hackers will figure another way to screw us..lol

Reply

growmap February 23, 2010 at 9:16 am

Twitter: @GrowMap

Yes, that is pretty much true. It is an eternal cat and mouse game.
.-= growmap´s last blog ..Better Twitter Retweets From Favorite Twitter Apps =-.

Reply

Josiah from Watch Dead Like Me Online November 23, 2009 at 5:09 pm

Twitter: @josiahstaggs

Thanks for the head’s up. Even though WP lets you upgrade wordpress right in the dash, it’s still something i’m worried ver because i tend to think it will break something..
.-= Josiah@ Watch Dead Like Me Online´s last blog ..Season 2: Episode 15 =-.

Reply

Paul from Muscle growth supplements December 3, 2009 at 2:48 pm

Wordpress has to update for bugs and security flaws so often that it only pays to bother upgrading when its a very critical security flaw.

Reply

folders printing December 3, 2009 at 2:56 pm

Twitter: @muqtada123

Good advice if it will be picked up quickly before more exploits.

Reply

Mike from physical security assessment December 8, 2009 at 5:51 am

nice post with useful information…

Reply

Cleaning wool area rugs December 10, 2009 at 12:19 am

I didn’t realise wordpress is so vulnerable. I now have some concerns over the wordpress blog that I am using now. Is there any other to make it more safe?
.-= Cleaning wool area rugs´s last blog ..Types of wool area rugs and how to place them =-.

Reply

Cleaning wool area rugs December 10, 2009 at 12:21 am

I am not sure if my previous comment got through. I was asking if there is any way to strengthen your security for the wordpress blogs.
.-= Cleaning wool area rugs´s last blog ..Types of wool area rugs and how to place them =-.

Reply

Amanda December 10, 2009 at 4:12 pm

I just started using word press and had no idea about any of that stuff. Great article.
.-= Amanda´s last blog ..Bearpaw Women’s 419 Demi Boot =-.

Reply

Sergey December 20, 2009 at 3:35 am

Yes attacks happen now on everywhere not only on such blogs and failures occur everywhere

Reply

folders printing December 21, 2009 at 9:23 am

Twitter: @muqtada123

i think its already attacked in some blogs powered by WP, because i tried so many times to comment in that, i got no luck, what is the solution, anyone please

Reply

Boardwalk from Best Muscle Building Supplement December 26, 2009 at 5:30 pm

I had no idea there were so many threats to blogs out there. As a newbie, I guess I have been pretty naive. Thanks for providing me with the tools to protect myself.
.-= Boardwalk @ Best Muscle Building Supplement´s last blog ..Muscle Building Tips =-.

Reply

Portland Photo Booth Rental December 31, 2009 at 3:09 pm

Subscribe to blogs about Wordpress plugins and security threats to keep your blog online and healthy!

Reply

instockphones from best cricket phones January 5, 2010 at 7:54 am

Twitter: @muqtada123

I have noticed that in the recent google PR update, it does not update the PR for most blogs powered by WP and this could be the reason that why google did this.

Reply

growmap February 23, 2010 at 8:52 am

Twitter: @GrowMap

Hello,

I don’t watch the PR updates very closely but I know that many blogs that are more tightly focused on SEO do. While I need to update it you may be able to find some of the best blogs that cover that subject on my personal GrowMap MyAlltop page.
.-= growmap´s last blog ..KeywordLuv: How Using It Benefits Us All =-.

Reply

Bearpaw Boots February 11, 2010 at 4:40 pm

Not sure what you mean by the PR

Reply

growmap February 23, 2010 at 9:07 am

Twitter: @GrowMap

InStockPhones is referring to Google Page Rank. There are many explanations of what it is online including this one on What is Google PageRank.

There is much disinformation online about almost everything and especially about SEO so never believe everything you read.
.-= growmap´s last blog ..MEME: BizLuv in Support of Small Businesses =-.

Reply

free computer tips February 22, 2010 at 6:39 pm

Currently I am using blogspot and I am planning to switch to wordpress because of its great feature. So I am collecting more information about wordpress. Anyway, Thanks.

Reply

growmap February 23, 2010 at 9:08 am

Twitter: @GrowMap

Hello Computer Tips,

Be sure to read my post about setting up WordPress blogs for businesses. It contains much valuable information on Business Blogging.
.-= growmap´s last blog ..KeywordLuv: How Using It Benefits Us All =-.

Reply

Leave a Comment

CommentLuv Enabled

This site uses KeywordLuv. Enter YourName@YourKeywords in the Name field to take advantage.

{ 2 trackbacks }

Previous post: How to Create a Successful Blog Based Business

Next post: Intelligent Bloggers to Consider Reading