Middle of last month the website caught some malware…I hope it didn’t infect or inconvenience anyone. If it did, my apologies…
I woke up December 15 to multiple emails from Google stating that www.beforetheyweredinosaurs.com had been quarantined. An email from the web hosting service stated they had cleaned the infection. They gave some good advice, suggested I change all the passwords, run antivirus, uninstall unused/unneeded programs, etc…did all that.
When I tried to bring up the site, only a blank page appeared.
I was still able to login to the admin page, so I updated WordPress and all its plugins. Still the main page was blank.
So I put up a static page until I had time to figure things out.
Not a big deal anyways – my posts have been increasingly infrequent lately (but that’s another story).
But when a friend asked what was up with my website, it was time to do something…
That day came last Thursday – I disabled all the WordPress plugins, then updated the themes – I’d been a bit nervous about that, wondering if it might blow up the site.
That had already happened, no fear now…and that fear was unfounded – the main site came up.
I reenabled the first plugin. It was cute little flash audio player for the mp3 links.
Microsoft Security Essentials instantly flagged malware. Doh! It turns out the audio player plugin hadn’t been updated in quite some time and was using an outdated version of jquery (1.3).
And somehow it had become infected with malware known as blacole (Black Hole).
So now I’m using a new audio player widget (Thank you, Matteo Bicocchi!), and I have disabled the out-of-date widgets. As some would say, reduce the attack surface!