The / Hack and how to get rid of it

Saturday morning a couple of my sites were hacked by something I’ve not found a lot of info about. I’ll call it The Drunkjeans Hack. I’ve also found this being inserted from other domains (see below).

Some idiot has inserted a piece of code into the main index.php file that looks like this:

The first line calls a JavaScript file on the given domain, while the second line is a unique identifier (consider yourself an individual).

What this thing does is unclear, but depending on how far the hackers get with this, it could be anything from a wonky homepage to the entire site being down. I did some digging and here’s what I found out:

This thing attacks all browser default files as well as .js files. Literally ALL of them in your site, including sub directories. Browser default files are index.php, index.htm, index.html, start.thm, start.html et cetera.

In WordPress, there’s an index.php in your root and one in your theme’s directory.

There are also several .js files cattered all over the installation, including plugin and theme subdirectories so it can be a rather lenghty search…

The good news is that it appears that the exploit does not seem to mess with your database from what I can tell.

What does it do?

The Hack attaches a piece of code that loads a Javascript whereever it can. What it does is unclear (I tried to download one for closer inspection but it didn’t work). It does this either as a <script> tag or a JavaScript document.write statement.

A good example for this is the Next Gen Gallery Plugin, which uses the Shutter Reloaded library. Here’s what I found at the end of the shutter-reloaded.js file (in wp-content/plugins/nextgen-gallery/shutter/):

document.write('<s'+'cript type="text/javascript" src=""></scr'+'ipt>');

Why does it do that?

I think I’ve discovered the big idea now: on a shared hosting package with Strato in Germany I found some files that redirected the site to several Viagra Shops (like – grab a bargain while it’s hot).

How can we kill it, Cap’n?

Looks like deleting the code and saving the file is doing a good job. The code is always at the end of the aforementioned files so it’s fairly easy to find – once you know which file it’s attached itself to. Use a security software, try Trend Micro, Sophos or the free version of AVG for clues.

If you want to find EVERY file on your site that’s infected issue this server command in your home directory:

Be patient, this could take a while. This command will show you a long list of everything that’s infected in your directories and sub directories. It’s then up to you to open every one of them and delete the piece of code.
Once your files are clean, you’re well advised to change ownership of these (or all files) to root and permissions to “read only” via the following command – this only works if you have shell access though:

PHP Finder Script

I figured that many of us don’t have the liberty of sheel access, so I’ve devised this little php script that should do the hard work of finding infected files for you.

Copy the code below into a new text file, call it test.php and upload to the root directory of your site. Then call it in a browser (say by and the script will get to work. This can take a few minutes – be patient.

Replace the “” domain with whatever bug you think you have. To be 100% sure, run the script several times with all the domain variations listed below.


So far I’ve found the following code fragments. Your site is only ever affected by one of these domains so that’s the one to search your files for.

A WHOIS lookup reveals that these domains were registered on the 7th of July 2010 in Rubaix, France via (that’s a Chinese ISP and Hosting Provider).


<script type="text/javascript" src=""></script>


<script type="text/javascript" src=""></script>

<script type="text/javascript" src=""></script>

What’s funny about this vairation is that apparnetly McAfee have classed this domain as SAFE… why am I not surprised?


<script type="text/javascript" src=""></script>


<script type="text/javascript" src=""></script>


<script type="text/javascript" src=""></script>


<script type="text/javascript" src=""></script>




In the WP backend, I could see something being called from – not sure which file is compromised but I’m determined to find out.

Further Reading

Some forum posts I found about this exploit:

About Jay Versluis

Jay is a medical miracle known as a Super Survivor. He runs two YouTube channels, five websites and several podcast feeds. To see what else he's up to, and to support him on his mission to make the world a better place, check out his Patreon Campaign.

43 thoughts on “The / Hack and how to get rid of it

  1. Same problem as above, several sites got infected and i use CentOS, Cpanel and FileZila.

    I think we had a similar problem about 6/7 months a go where all our index files got infected. but since then i have move to a new saver but with the same company .

  2. we got it pretty bad

    Search ".ru" (4255 hits in 1298 files)
    not all of them are the address but most are

    1. we got ( infected our blog most of them on .js files.
      sorry for your loss bro, [Search “.ru” (4255 hits in 1298 files)] its really a big deal. you should clean your PC first.

  3. Same here. They “hacked” our website i think through ftp and installed the above code. The url of the javascript doesn’t exist and the funny thing is that google got it just before i could do something. (i found it straight away)

    Now i changed ftp password and changed also the infected files. (mostly .js files) and just one php file.

    They dont hack your FTP or server directly (might be, but smaller chance).
    They infect the machine (probably with a .sys driver (try out bitdefender addon for FF)) that you used to upload your sites files to your webspace.
    If u stored your FTP credentials on it … they connect to your webspace and alter the the index and js files.
    So beware, changing FTP PW is only working until you log on to your space again if u dont clean your machine first !!!

Add your voice!