So it’s a very clever and very dirty way of boosting search engine rankings for dirty companies. I have no idea how they compromised wordpress or my server.
The WordPress pharma hack quietly exploits your highest-ranking and most valuable pages by overriding the title tag and by inserting spammy links into the page content. Interestingly, the modified title tag and spammy links are only visible to search engines.
If you search for Crackunit on Google you see this:
Which is bad.
But when I actually arrive at the page there’s no mention of Zopiclone – not even in the source code anywhere. There’s no links, no nothing?!? And there’s no Pharmacy name in the hack, so I wondered what anyone could be getting out of this apart from a pain in the ass.
I did a search for Zopiclone blog hacks and various other things. And didn’t find anything useful. But I did find that Cookie (made-in-england.org) appears to have been ‘got’ too.
After a bit more digging I found this useful write up from the excellent Pearsonified blog: http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php
Unfortunately the fixes that are listed are complicated and time consuming – and on first pass it looks like my version of the hack is slightly different. Which makes it even more painful to fix. Sigh…
Anyone got any thoughts apart from ‘give up’?