Category: Blog Security — BONTB @ 10:03 am —
Enjoy reading this post and subscribe to Bontb RSS Feeds

Lately I have noticed many bloggers complaining about having wordpress blogs hacked. Have you ever seen google message “This website may harm your computer” My friends and My blog www.hawaiib.com end up flaged on google because recently friend of mine changed wordpress theme that wanted to test first.

He thought that theme has better layout and it’s easy to re-code it. That same theme had part of encrypted code that allowed sites like wpsphere.com to approve comments, advertise without your knowledge and god knows what more!

I am here to tell you so you can tell others to keep away from wpsphere.com and also websites that provide “Wordpress Premium themes” , “Free Wordpress Themes” but don’t have link to “original source”

People usually charge for premium themes but some wordpress theme galleries that offer wordpress themes for free, coded evil plugins that you might not notice and might harm your visitors computers or display pop ups!

Theme my friend download was StudioPress originally created by DailyBlogTips he download it from some website that he don’t even know where he found it, but sure when I read 5thirtyone blog few days ago, site wpsphere look similar to my friend described to me, but URL was different!

What you need to remember from this post….

1. NEVER EVER DOWNLOAD WORDPRESS THEMES THAT ARE FROM 3RD PARTY BLOGS, WEBSITES (allways download themes from original source of wordpress theme)

2.WHEN DOWNLOADING THEME MAKE SURE IT’S LATEST VERSION

3. READ CHANGES, README, INSTALLATION files

4. WHEN YOU INSTALL THEME MAKE SURE ITS NOT LINKING TO SITES LIKE Casino, Pharmacy etc urls in “footer” or your Admin Theme/Presentation dashboard.

You don’t want this happen to you! (Click on image to view)

this site might harm your computer

I reconsidered this blog to google and I also called few of my friends from google to remove that statement because I changed theme to what it was before. You can still access website without any problems but if you go through google you will end with message:

 

 

Warning - visiting this web site may harm your computer!

You can learn more about harmful web content and how to protect your computer at StopBadware.org.

Suggestions:

Or you can continue to http://www.hawaiib.com/ at your own risk.

If you are the owner of this web site, you can request a review of your site using Google’s Webmasters Tools.

Advisory provided by Google

In conclusion

Check your themes for stuff like “c3Q9Ii4gdXJsZW5jb2RlKCRfU0VSVkVSWydIVFRQX0″ because why would somebody encrypt text and why would you install wordpress theme that half of the coding looks encrypted anyways.

If you are using Adsense Ready themes, make sure your shows your google_ad_client = “pub-yourpubadsenseidnumber“; otherwise you will not make a dime from google adsense.

Please be so kind and spread the word to other bloggers. Blog about it, link to this post, stumble this post, do what ever it takes that you and your friends know about this.

This makes “US” bloggers look bad, just because some idiots that use their brain for nothing else then harm other people.

Horaayy..there are 9 comment(s) for me so far ;)

#1

I have also seen this on one site I regularly visit, looks like it has been hacked.

Quit Smoking wrote on March 7, 2008 - 4:23 am
#2

Thanks for informing about this. I will have to stay alert now when choosing my themes.

Fahad wrote on March 7, 2008 - 12:53 pm
#3

I rarely download wp themes from 3rd party sites. I prefer “direct download” from trusted sites such as original author or themes.wordpress.net. Btw, thanks for this nice info :)

Finance Software wrote on March 10, 2008 - 5:27 pm
#4

Ah, never been hot by this, but it is worth reminding us to be vigilant when roaming the web for a new theme for our blogs - thanks!

Nick - road2blogging wrote on March 11, 2008 - 10:24 am
#5

Another solution, is to read the code and make sure it’s clean. This require PHP, HTML, and especially Javascript knowledge.

Keep it simple, try not to download themes with <script…> tag. Any thing client side script can be dangerous.

SEO Web Design wrote on March 11, 2008 - 10:28 am
#6

Thank you for posting this. I release lots of original free WordPress themes on my blog, and it really makes me sick when I find that others have taken my work and inserted encoded php code into them doing who knows what. PLEASE listen to the advice in this post and only download themes from the true author’s sites.

Leland wrote on March 16, 2008 - 11:26 am
#7

Hello,

I use a lot of free wordpress themes myself, I’m tired of wandering all around the web so I set up my own “free wordpress templates” site ( free-wordpress-templates.net ).

It is primarily aimed for my personal use, I don’t want to list every craps on the net but only a few selected ones that I project to use myself - among 1500 themes I have seen one by one !

I have not posted all the ones I have found pretty or usefull but should release them day by day.

Also the site is new and still in construction so please be indulgent with me :)

free-wordpress-templates.net wrote on March 17, 2008 - 8:06 am
#8

Forgot to say what I wanted to say in the first place:):

OF COURSE I DO LINK DIRECTLY TO THE AUTHOR’S SITE !

free-wordpress-templates.net wrote on March 17, 2008 - 8:08 am
#9

Good work. It was pleasant to me at you and I have decided to express to you. >

Olga Kolmakova wrote on May 3, 2008 - 3:19 am
You can leave a response, or trackback from your own site.

Write Your Comment

Comment Guidelines: Basic XHTML is allowed (a href, strong, em, code). All line breaks and paragraphs will be generated automatically.

You should have a name, right? 
Your email address, I promised I won't tell it to anyone. 
If you have a web site or blog, you can type the URL right here. 
This is where you type your comments. 
Remember my information for the next time I visit.