December 1, 2007
wp_footer Exploits Continue
The troubles with the evil wp_footer exploit continue. My friend Roy alerted me to the fact that wp_footer had reappeared and was once again creating spam links in my footer. Those spam links went to Scott Rosenberg’s site, Wordyard. I contacted Scott and he told me he knew his site had been hijacked to host these spam pages and he was busy cleaning it up. He helpfully told me that “wp_footer” was being called by some rogue code in the “default-filters” file which can be found in the folder “wp-includes.”
Scott also pointed out that I should delete another rogue file, “class-mail,” also found within the folder, “wp-includes.”
Let’s see if this solves the problem.

