<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: How to Diagnose and Remove the WordPress Pharma Hack	</title>
	<atom:link href="https://pearsonified.com/wordpress-pharma-hack/feed/" rel="self" type="application/rss+xml" />
	<link>https://pearsonified.com/wordpress-pharma-hack/</link>
	<description>Best damn website on the planet since 2005</description>
	<lastBuildDate>Sun, 30 Sep 2018 13:10:07 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.1</generator>
	<item>
		<title>
		By: sunny		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1675641</link>

		<dc:creator><![CDATA[sunny]]></dc:creator>
		<pubDate>Mon, 15 Feb 2016 09:54:02 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1675641</guid>

					<description><![CDATA[Great tutorial. pharma hack files can identify PHP functions.]]></description>
			<content:encoded><![CDATA[<p>Great tutorial. pharma hack files can identify PHP functions.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Damian		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1598231</link>

		<dc:creator><![CDATA[Damian]]></dc:creator>
		<pubDate>Sat, 03 Oct 2015 18:42:35 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1598231</guid>

					<description><![CDATA[Is this still doing the rounds ?]]></description>
			<content:encoded><![CDATA[<p>Is this still doing the rounds ?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Ivan Sindell		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1592706</link>

		<dc:creator><![CDATA[Ivan Sindell]]></dc:creator>
		<pubDate>Sun, 27 Sep 2015 18:06:36 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1592706</guid>

					<description><![CDATA[pharma hack. Wordfence free version spotted five files with bad code- and showed the code, and securi noted the same files were changed. 

the files are in the wp-includes  directory
However, nothing about the database. 

The  files cannot be removed without bringing down the site.]]></description>
			<content:encoded><![CDATA[<p>pharma hack. Wordfence free version spotted five files with bad code- and showed the code, and securi noted the same files were changed. </p>
<p>the files are in the wp-includes  directory<br />
However, nothing about the database. </p>
<p>The  files cannot be removed without bringing down the site.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Shaun		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1550451</link>

		<dc:creator><![CDATA[Shaun]]></dc:creator>
		<pubDate>Sat, 22 Aug 2015 17:05:06 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1550451</guid>

					<description><![CDATA[So, with the hack affecting Google results, how do you know if you&#039;ve  actually fixed it? Surely only time will tell once Google crawls your site again?]]></description>
			<content:encoded><![CDATA[<p>So, with the hack affecting Google results, how do you know if you&#8217;ve  actually fixed it? Surely only time will tell once Google crawls your site again?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Sarah		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1528451</link>

		<dc:creator><![CDATA[Sarah]]></dc:creator>
		<pubDate>Tue, 04 Aug 2015 21:45:06 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1528451</guid>

					<description><![CDATA[You are a lifesaver. I have literally JUST found out that my work&#039;s blog (which is in the public sector, yikes) was infected with the Pharma hack.

I&#039;ll be following the steps in your post to hopefully fix the problem, crossing my fingers!]]></description>
			<content:encoded><![CDATA[<p>You are a lifesaver. I have literally JUST found out that my work&#8217;s blog (which is in the public sector, yikes) was infected with the Pharma hack.</p>
<p>I&#8217;ll be following the steps in your post to hopefully fix the problem, crossing my fingers!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Christiane LagacÃ©		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1481755</link>

		<dc:creator><![CDATA[Christiane LagacÃ©]]></dc:creator>
		<pubDate>Fri, 26 Jun 2015 16:26:27 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1481755</guid>

					<description><![CDATA[Thanks for this. Though I didn&#039;t face exactly the same problem, your article helped me to find the malicious file in my website.

&lt;a href=&quot;http://christianelagace.com/wordpress/a-laide-un-hacker-a-ajoute-une-chaine-encodee-dans-mon-code-php-base64_decode/&quot; rel=&quot;nofollow&quot;&gt;Here is how I solved my problem.&lt;/a&gt;

Thanks again!]]></description>
			<content:encoded><![CDATA[<p>Thanks for this. Though I didn&#8217;t face exactly the same problem, your article helped me to find the malicious file in my website.</p>
<p><a href="http://christianelagace.com/wordpress/a-laide-un-hacker-a-ajoute-une-chaine-encodee-dans-mon-code-php-base64_decode/" rel="nofollow">Here is how I solved my problem.</a></p>
<p>Thanks again!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Got me too		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1428013</link>

		<dc:creator><![CDATA[Got me too]]></dc:creator>
		<pubDate>Sun, 31 May 2015 06:51:57 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1428013</guid>

					<description><![CDATA[I had a client hit by this too. Thought I found everything and site scanned clean, a little later it was back by a backdoor that was missed. 

A few things I noticed on google searches, disabling the .htaccess file stopped the redirect. 

After I deleted the site, new results on google searches would call up with sitename.com/somenumber-html for the pharmacy, of course since it is currently deleted they do not redirect.

Is there any way to stop these google search results with the site domain name ?]]></description>
			<content:encoded><![CDATA[<p>I had a client hit by this too. Thought I found everything and site scanned clean, a little later it was back by a backdoor that was missed. </p>
<p>A few things I noticed on google searches, disabling the .htaccess file stopped the redirect. </p>
<p>After I deleted the site, new results on google searches would call up with sitename.com/somenumber-html for the pharmacy, of course since it is currently deleted they do not redirect.</p>
<p>Is there any way to stop these google search results with the site domain name ?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: mopsyd		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1422530</link>

		<dc:creator><![CDATA[mopsyd]]></dc:creator>
		<pubDate>Thu, 28 May 2015 00:01:53 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1422530</guid>

					<description><![CDATA[I&#039;ve found a very easy way to track down web infections if you use git. You will need a pre-existing commit of the clean site in order to do this though. If you get hacked and do have a git repo for that site, just commit again and check the diff between the two, which will reveal all lines changed in all files, as well as any new files added since your previous one. Be careful not to remove anything that was legitimately updated (like plugin or theme files).

This will not isolate the database issues, however, unless you have a ton of plugins and settings, you can export the wordpress.xml export from the tools menu, rebuild your database completely and reimport it and it will clear any bad records completely in the process. You may lose a few settings from poorly built plugins that do not store database records in the process, so two ways around this are:

A) Create a duplicate database, rebuild the first one, and toggle between the two by editing the wp-config.php file (this way you have an immediate backup to go back to if you bork it without downtime, and without having to work against the live database)

B) Move your entire site to a staging server (localhost or a subdomain), clean it, and then push the clean version back to your live installation.

That&#039;s how I generally go about removing these. There are a lot of variants, and missing something generally leads to reinfection, so I typically just rebuild from clean downloads whenever possible.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve found a very easy way to track down web infections if you use git. You will need a pre-existing commit of the clean site in order to do this though. If you get hacked and do have a git repo for that site, just commit again and check the diff between the two, which will reveal all lines changed in all files, as well as any new files added since your previous one. Be careful not to remove anything that was legitimately updated (like plugin or theme files).</p>
<p>This will not isolate the database issues, however, unless you have a ton of plugins and settings, you can export the wordpress.xml export from the tools menu, rebuild your database completely and reimport it and it will clear any bad records completely in the process. You may lose a few settings from poorly built plugins that do not store database records in the process, so two ways around this are:</p>
<p>A) Create a duplicate database, rebuild the first one, and toggle between the two by editing the wp-config.php file (this way you have an immediate backup to go back to if you bork it without downtime, and without having to work against the live database)</p>
<p>B) Move your entire site to a staging server (localhost or a subdomain), clean it, and then push the clean version back to your live installation.</p>
<p>That&#8217;s how I generally go about removing these. There are a lot of variants, and missing something generally leads to reinfection, so I typically just rebuild from clean downloads whenever possible.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Michael Decker		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1314560</link>

		<dc:creator><![CDATA[Michael Decker]]></dc:creator>
		<pubDate>Wed, 25 Mar 2015 03:11:56 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1314560</guid>

					<description><![CDATA[Hey found oldie but a goodie :). I ended up going in phpMyAdmin and deleted the database entries that contained malicious code. 

Thanks a bunch will definitely will start following!]]></description>
			<content:encoded><![CDATA[<p>Hey found oldie but a goodie :). I ended up going in phpMyAdmin and deleted the database entries that contained malicious code. </p>
<p>Thanks a bunch will definitely will start following!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Mike		</title>
		<link>https://pearsonified.com/wordpress-pharma-hack/#comment-1201699</link>

		<dc:creator><![CDATA[Mike]]></dc:creator>
		<pubDate>Mon, 19 Jan 2015 19:10:52 +0000</pubDate>
		<guid isPermaLink="false">https://pearsonified.com/?p=742#comment-1201699</guid>

					<description><![CDATA[My findings:

I did have a number of entries returned with the rss_% search, but none seemed to be the offending ones. I deleted them anyway.

I did not have any malicious files in Akismet.

The first line of my active theme&#039;s functions.php did contain the bad stuff and it was backwards (you&#039;ll see edoced at the end of a giant string of garbage characters all on a single line). Deleted and all good. Be careful to not delete your opening php declaration as it&#039;ll appear connected to this.]]></description>
			<content:encoded><![CDATA[<p>My findings:</p>
<p>I did have a number of entries returned with the rss_% search, but none seemed to be the offending ones. I deleted them anyway.</p>
<p>I did not have any malicious files in Akismet.</p>
<p>The first line of my active theme&#8217;s functions.php did contain the bad stuff and it was backwards (you&#8217;ll see edoced at the end of a giant string of garbage characters all on a single line). Deleted and all good. Be careful to not delete your opening php declaration as it&#8217;ll appear connected to this.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
