forumNew topic

Unknown lines added to site's HTML and PHP, need to find them fast

MMelis Ö***Expert
Job title
Social media manager
Sector
E-commerce
Organization type
120-person company
Joined
Feb 2022
Message
14

Doki · Log management setup · 2025

#1

Client said site speed dropped, so I started checking. Right-clicking in browser, inspecting element — there's some weird JavaScript at the bottom of the page. I delete it, refresh, it comes back. I go directly to the file, open via FTP — it's not there. So it's being injected dynamically.

I open PHP files in a text editor and look for the scripts I'm searching for, I see an orange line in some — starts with @ sign, isn't that an obfuscation technique? I delete it, it comes back again. Doesn't feel fair, I'm losing control to my computer.

Did they get in via SQL injection into the database? Or some other way? I want to understand what's going on here before complaining to the hosting company.

ŞŞerife K***MemberCommunity member
Joined
Jul 2024
Message
186
Most Helpful#2

This points to injection via the database. If the code isn't directly in your file system but appears when the page loads they might be storing options in the database via SQL injection. If you're using WordPress check fields like siteurl home, gplus_profile etc. in the wp_options table. Dump the database and grep for PHP functions like '%base64%', '%eval%', '%preg_replace%'. The @ sign suppresses errors, malware's favorite. 2) Check FTP logs — you'll see who accessed in the last 7 days. 3) Check access permissions of wp-config.php (should be 644, not 777). 4) Check modification dates of all files, look at the last 30 days.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#3

sQL injection is very classic, they might have run a select users query and put admin info into wp-postmeta tables. delete the plugin then whichever one wasnt updated. or drop table..... no its not something that always happens...

NNecati E***MemberCommunity member
Joined
Jan 2024
Message
3
#4

Steps: 1) Enter database via phpmyadmin 2) Get wp_options, check all 3) Check wp_postmeta, see if there are foreign meta_keys 4) FTP logs (in hosting panel) 5) post_content field in wp_posts table — if there are many posts and it's fine or if there are script commands delete 6) Disable all plugins and themes 7) Upgrade WordPress

MMustafa K***ExpertCommunity member
Joined
Jan 2025
Message
3
#5

I read you saying you're losing control to your computer... seems like you're experiencing it very dramatically. SQL injection is a simple thing if you don't sanitize queries your database gets compromised too. Investigate 'which plugin didn't I update' and it's done.

AAlperMember
Job title
Field sales manager
Organization type
cooperative
Joined
Mar 2024
Message
102

Doki · E-commerce infrastructure · 2026

#6

I have a testing method: restore from full backup in WordPress staging environment, update plugins and themes, then check if it's still there. If it's not in staging, it's in the file system, if it is, it's in the database. Work accordingly depending on which route you want to take.

ZZehra Y***Member
Job title
Marketing manager
Sector
Furniture manufacturing
Organization type
20-person company
Joined
May 2024
Message
324
#7

I didn't understand the problem very well but... what is a database? What is FTP? Do I need to learn MySQL soon to solve this? Or will someone definitely help?

VVeli N***Expert
Job title
System administrator
Sector
Packaging
Organization type
a company within a holding
Joined
May 2022
Message
359
#8

There's a common mistake people make when doing this. If you don't write this down from the start it leads to arguments later.

If you post the result here, it will help others too.

UUğur S***Member
Job title
Regional Manager
Sector
Chemistry
Organization type
sole proprietorship
Joined
Sep 2024
Message
22
#9

This thread is archived.

SSena P***New member
Job title
Logistics planning
Sector
Construction
Organization type
chain store
Joined
Jul 2026
Message
389

Doki · Interface design · 2023

#10

the answer above hits the nail on the head. start with a small trial; don't commit to everything at once.

CCemMember
Job title
Agency · Project Manager
Organization type
chain store
Joined
Jun 2024
Message
103

Doki · Infrastructure migration · 2023

#11

Sorry, but this doesn't apply in every case. Payment information changes are never verified through the channel they came from.

EElif B***Member
Job title
Courier coordinator
Sector
Healthcare services
Organization type
a company within a holding
Joined
Dec 2023
Message
228
#12

Quick summary for newcomers: When you try to change everything at once nothing settles.

That's all sorry if I went on too long.

İİbrahim T***ExpertCommunity member
Joined
Mar 2025
Message
22
#13

Let me clarify the technical side. If it's your first time, start small; scaling comes later.

Hope this helps.

OOrhan B***VeteranCommunity member
Joined
Jan 2023
Message
26
#14

I'm in the same situation, that's why I'm asking. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

This is my opinion, I'm not claiming it's absolute truth.

YYasemin S***MemberCommunity member
Joined
Feb 2024
Message
42
#15

I'm writing this so you don't make the same mistake. The harder it is to reverse a decision, the slower you should make it.

Forgotten test environments are more often the entry point than live systems. If I were you I'd go this route.

BBeren B***Member
Job title
Network Administrator
Sector
Energy
Organization type
medium-sized business
Joined
Dec 2023
Message
14
#16

There is something to watch out for. Most incidents start with a leaked password, not a vulnerability.

Just leaving this note, it might be useful.

EElif Z***Expert
Job title
Production planning
Sector
Glass
Organization type
medium-sized business
Joined
Feb 2023
Message
164
#17

You're right. The answer varies greatly by industry; there is no one-size-fits-all rule.

Most time waste accumulates in tasks waiting for approval.

İİbrahim P***Member
Job title
Human Resources Specialist
Sector
Consulting
Organization type
sole proprietorship
Joined
Jul 2024
Message
48
#18

You're right. When you try to change everything at once, nothing settles.

Hope this helps.

AAycan U***MemberCommunity member
Joined
Jul 2023
Message
2
#19

i went through the same thing and btw just because everyone does it doesn't mean it's right.

having backups accessible on the same network and with the same identity makes them part of the target. proven by experience.

AAyşe Ç***Member
Job title
Chief Information Security Officer
Sector
Construction
Organization type
cooperative
Joined
Feb 2025
Message
27
#20

I agree. If permission and scope aren't in writing, don't start that test.

Most incidents start with a leaked password, not a vulnerability. Hope this helps.

Reply