I just got an alert from Google that my website was on a danger list, that it included a link to some malware. (It’s gone now.) Sure enough, the Yahoo post below contained an IFRAME with a reference to Ghod-knows-what. After excising that, I found some link spam buried in two other posts, pointing to a gambling site. Also gone now.
I recently upgraded to WordPress 2.5, which I understand closed a major security hole. I hope that this closed that hole, and I’ll see no more of this evil nonsense.
Fucking parasites. Pardon my Anglo-Saxon, but this crap just makes me furious. Now my page is marked as “Evil! Unclean!” in Google’s index, until they get around to reviewing it again. And it wasn’t just someone having fun punking my site; this is how hackers build their botnets, using openings like this to subvert anyone unlucky enough to read a hacked web page.
(I repeat, the offending code has been removed, and if the programmers at Automattic know what they’re doing, it won’t be back. If you’re still worried, try switching to a more secure browser… like anything other than Internet Explorer. Like this or this or this.)