My WordPress site got hacked. What should I do?

HustleHardNow

Regular Member
Joined
Jun 30, 2017
Messages
290
Reaction score
60
Okay so long story short:

I started a new WordPress site last August, and stopped updating it sometime around November. I didn't put a lot work into it, there was only around 20~ articles on it.

Then I completely forgot about it until a few days ago. I wanted to start working on it again, and when I tried logging into my admin account I wasn't able to. I had to go through cPanel to get in.

Once I finally managed to log-in through cPanel I saw that my admin account was changed to "indexploit" and the title of my blog was changed to something like "hacked by...."

I panicked, and since knowing my site had barely any content on it I deleted the entire WordPress installation through cPanel.

Then I checked my cPanel last loggin IP address and it was some Indian IP address.
I am located in the US and so is my web host.

The good news is that this was the only site I had on that web host, and it wasn't a site I cared about much.

What I am really worried about now is someone having logged into my cPanel and potentially having done some harmful things on my account without me knowing.

I have no idea what to do right now. Should I contact my web host, and let them know about this, or what?

Serious answers only please.
 
Okay so long story short:

I started a new WordPress site last August, and stopped updating it sometime around November. I didn't put a lot work into it, there was only around 20~ articles on it.

Then I completely forgot about it until a few days ago. I wanted to start working on it again, and when I tried logging into my admin account I wasn't able to. I had to go through cPanel to get in.

Once I finally managed to log-in through cPanel I saw that my admin account was changed to "indexploit" and the title of my blog was changed to something like "hacked by...."

I panicked, and since knowing my site had barely any content on it I deleted the entire WordPress installation through cPanel.

Then I checked my cPanel last loggin IP address and it was some Indian IP address.
I am located in the US and so is my web host.

The good news is that this was the only site I had on that web host, and it wasn't a site I cared about much.

What I am really worried about now is someone having logged into my cPanel and potentially having done some harmful things on my account without me knowing.

I have no idea what to do right now. Should I contact my web host, and let them know about this, or what?

Serious answers only please.

You will never know the only way is to erase everything and import your clean save to start fresh, then subscribe the basic sucurinet offer, $10/ month (extremely powerful firewall)
 
Hi,

Do you have any other websites on this server, that can be configured by this cpanel ?

edit : Ok, I see that you only have this one.

You can change all credentials, check ftp users, db users, ssh users, ... and you're good to go. Or, if you can, go reset all cpanel and server
 
You will never know the only way is to erase everything and import your clean save to start fresh, then subscribe the basic sucurinet offer, $10/ month (extremely powerful firewall)


If he hade a minimum of knowledge he can do it alone for free, there's so many tuts on internet for that
 
Well, first of all do you have any backup of the last working version of the website? This can help you very much.
Let's suppose you have the backup. Reinstall the website from the backup and change all the passwords of the website. Also, change the database prefix and change the database login credentials.
Be sure that your theme is NOT nulled and also check any plugin ( if something is "nulled", get rid of it! ). Be sure that your WordPress version is up to date. Finally, try to install a security plugin ( you can find a lot of free security plugins ).
 
2nd: If you don't have any backup and you don't have the articles of the website saved in your pc, you may find a little help by accesing Wayback Machine ( if there is any saved version of your website ) or Google cache ( cache:yourwebsite.com ).

Good luck!
 
You will never know the only way is to erase everything and import your clean save to start fresh, then subscribe the basic sucurinet offer, $10/ month (extremely powerful firewall)

I erased the WordPress install directly from the cPanel. The entire WordPress installation along with everything that was on it (articles, theme, plugins, etc...) is gone, but what I am worried about now is that the hacker got into the cPanel itself, and did some potentially harmful things there. I am not sure how to deal with that. Should I contact my web host and ask them about it or what?

Hi,

Do you have any other websites on this server, that can be configured by this cpanel ?

edit : Ok, I see that you only have this one.

You can change all credentials, check ftp users, db users, ssh users, ... and you're good to go. Or, if you can, go reset all cpanel and server

Would it be possible to just reset everything in the cPanel? I want to make sure that I don't miss anything important and completely reset all the accounts.

I am not sure what the hacker did, but in cPanel it shows the last loggin from an Indian IP, and that really worries me.

Well, first of all do you have any backup of the last working version of the website? This can help you very much.
Let's suppose you have the backup. Reinstall the website from the backup and change all the passwords of the website. Also, change the database prefix and change the database login credentials.
Be sure that your theme is NOT nulled and also check any plugin ( if something is "nulled", get rid of it! ). Be sure that your WordPress version is up to date. Finally, try to install a security plugin ( you can find a lot of free security plugins ).

There is a back-up from a few months ago but since I didn't check this site for such a long time, it could be a back-up of the already hacked site.

I don't mind starting this site from scratch. There was barely any content on it and starting from scratch is okay with me.

What I want to make sure is that the cPanel itself wasn't compromised in some way, and if it was what I could do to fix it before starting my site over. I am not sure how to go about that. Should I contact the web host?
 
I erased the WordPress install directly from the cPanel. The entire WordPress installation along with everything that was on it (articles, theme, plugins, etc...) is gone, but what I am worried about now is that the hacker got into the cPanel itself, and did some potentially harmful things there. I am not sure how to deal with that. Should I contact my web host and ask them about it or what?



Would it be possible to just reset everything in the cPanel? I want to make sure that I don't miss anything important and completely reset all the accounts.

I am not sure what the hacker did, but in cPanel it shows the last loggin from an Indian IP, and that really worries me.



There is a back-up from a few months ago but since I didn't check this site for such a long time, it could be a back-up of the already hacked site.

I don't mind starting this site from scratch. There was barely any content on it and starting from scratch is okay with me.

What I want to make sure is that the cPanel itself wasn't compromised in some way, and if it was what I could do to fix it before starting my site over. I am not sure how to go about that. Should I contact the web host?
Yes, explain them the situation and ask them to "reset" everything
 
I think I'll contact my web host and explain my situation to them.

Can we keep this thread on-topic? I don't want it to get closed due to derailment. If you guys want to chit chat please do so in another thread thanks.

Could a mod clean it up please? @davids355 @BassTrackerBoats @MisterF

Edit: Lightning fast response from the mods. Thank you so much :)
 
Last edited:
If your host have any decent customer service they should do a reset of your account and that will end your worries.
 
If your host have any decent customer service they should do a reset of your account and that will end your worries.

Could I be held liable for anything that the hackers did with my account?
 
Could I be held liable for anything that the hackers did with my account?
Since you are not selling anything I m sure all they did was steal or used your traffic, or host some malware. Stealing traffic doesn't harm site repo. Hosting malware does. Better check your site repo from any online free scanner.

First thing is knowing how someone entered into it. Couple methods :
1. Through Shared Hosting
2. Through Vulnerable plugin
3. Through Keyloggers

1. If they have done it through Shared hosting, You will be attacked again. No firewall or service like sucuri can stop it. The only option will be changing host.
2. Since you have deleted all files nothing to worry. Change all details like ftp, database . Fresh Install everything. Copy paste your content and you are good to go.
3. Kindly run a rootkit scan on your pc, install keyscrambler.

If you have the ip of the attacker Kindly report it in any cyber division. Viruses don't harm Computer, Ignorance does.

Kindly contribute to the cyberworld by reporting any hacking incident.

Most Important Always remember , 99% secure is 100% insecure.
 
Well, first of all do you have any backup of the last working version of the website? This can help you very much.
Let's suppose you have the backup. Reinstall the website from the backup and change all the passwords of the website. Also, change the database prefix and change the database login credentials.
Be sure that your theme is NOT nulled and also check any plugin ( if something is "nulled", get rid of it! ). Be sure that your WordPress version is up to date. Finally, try to install a security plugin ( you can find a lot of free security plugins ).

Maybe late for this thread but this is absolutely wrong. If someone has access to your CPanel, changing anything else (db info, db password, Wordpress pw etc) is futile. Ditto for restoring from a backup.

As pretty much everyone said, since this is the only site on that shared hosting, contact hosting provider, have them reset and you are good to go.

+1 on finding out how it was hacked but since they accessed your cpanel there are essentially 4 options

1) you are using an insecure password that you are also using somewhere else.................
2) You logged in from an infected computer or using an insecure connection and your password was captured
3) You have this password in an email or something of the sort that was breached
4) Your host was somehow breached or they do not have Brute force protection at the server level
 
I erased the WordPress install directly from the cPanel. The entire WordPress installation along with everything that was on it (articles, theme, plugins, etc...) is gone, but what I am worried about now is that the hacker got into the cPanel itself, and did some potentially harmful things there. I am not sure how to deal with that. Should I contact my web host and ask them about it or what?

Would it be possible to just reset everything in the cPanel? I want to make sure that I don't miss anything important and completely reset all the accounts.

I am not sure what the hacker did, but in cPanel it shows the last loggin from an Indian IP, and that really worries me.

There is a back-up from a few months ago but since I didn't check this site for such a long time, it could be a back-up of the already hacked site.

I don't mind starting this site from scratch. There was barely any content on it and starting from scratch is okay with me.

What I want to make sure is that the cPanel itself wasn't compromised in some way, and if it was what I could do to fix it before starting my site over. I am not sure how to go about that. Should I contact the web host?

There is nothing to be compromised in Cpanel except your Cpanel Password. If you have deleted everything from File Manager ( including the DB ) and changed your CPanel password you should be fine.
Even if you contact your Host all they can do is change your Cpanel password, there is noting to "reset" in Cpanel. ( You can just check the Cron tab if there are some leftovers from the hack ).
These exploits happen because of Nulled Themes/Plugins or by compromised host server in general. Another way is if you get infected by malware, but since you say this is the only Cpanel account compromised than i guess its because of the first option mentioned.
Since your website didnt mean that much to you, you can just restore the backup and try to find and delete nulled/old plugins which are not updated anymore. Also if you are using a cracked theme than just replace with a paid version.
Best of luck.
 
Back
Top