[HELP] My site has been hacked.

bobojonathan

Power Member
Joined
Sep 12, 2014
Messages
533
Reaction score
64
Hi Buddies.
My site got hacked and presently redirects to another site. Kind hearted members of this great forum should PLEASE assist on how to recover the site.
 
Last edited:
RIP.

What platform does it run? done any sketchy shit? still have ftp and db access? Where is it hosted?
 
Contact your host, they can run a scan (a good one can) and clean it for you. Otherwise you'll have to hire someone to do this for you. Maybe check fiver?
 
Contact your host, they can run a scan (a good one can) and clean it for you. Otherwise you'll have to hire someone to do this for you. Maybe check fiver?

100% if they are good, if not tell them to get off their arse and run ClamAV lmao.
 
Ok don't panic.

In general: Don't post a link to a hacked site, atleast remove the href so its not clickable. A hacked site may contain malware and users that accidentally click on the link may get infected.

So here we go:
  1. Have you used a CMS?
    If yes, see if you have access to the database and make a backup of it. This is the most important thing.

  2. Change your accounts passwords (ftp/sftp, database, hosting panel etc. ASAP) and remove EVERYTHING you have from your server It may be possible that php files or other files on your server have been infected by the hacker and can cause damage even after you have changed the ftp password.

  3. As other said, contact your hosting company and explain to them what has happend. They will tell you what to do next.

  4. In the meantime scan your computer. It is possible that even your machine is infected (RAT, Keylogger etc.).

I hope for you that you have a local backup of everything.
 
1. WordPress
2. No sketchy shit
3. I have ftp and db access
4. Hosted on http://Uppelink.com

The hosted link goes nowhere for me, odd, maybe a mistype?

What you can try is to check for any hardcoded redirects or footprints of a bvackdoor, try renaming your plugins folder, then see if its fixed, then uploads etc, and you can see where it is.

If you want to trust a rando on the internet with a profile picture of a crab, I am happy to go in and see what I can do? Plan would be to get you able to get on your WP admin to then run wordfence on the whole file directory...
 
If you have access to your cpanel, just restore your backup. I believe you have back up of your site.
 
If you have access to your cpanel, just restore your backup. I believe you have back up of your site.

Lets hope the backups are recent or available, i know some tight hosts block it away.

Worth also trying to contact support of there is no backups in cPanel, as things like R1Soft cant be done in individual cPanel accounts iirc.
 
Contact your host, they can run a scan (a good one can) and clean it for you. Otherwise you'll have to hire someone to do this for you. Maybe check fiver?

Done but got No virus on your site response.

100% if they are good, if not tell them to get off their arse and run ClamAV lmao.

Thanks for your recommendation. I'll do just that.

Ok don't panic.

In general: Don't post a link to a hacked site, atleast remove the href so its not clickable. A hacked site may contain malware and users that accidentally click on the link may get infected.

So here we go:
  1. Have you used a CMS?
    If yes, see if you have access to the database and make a backup of it. This is the most important thing.

  2. Change your accounts passwords (ftp/sftp, database, hosting panel etc. ASAP) and remove EVERYTHING you have from your server It may be possible that php files or other files on your server have been infected by the hacker and can cause damage even after you have changed the ftp password.

  3. As other said, contact your hosting company and explain to them what has happend. They will tell you what to do next.

  4. In the meantime scan your computer. It is possible that even your machine is infected (RAT, Keylogger etc.).

I hope for you that you have a local backup of everything.

Yeah, WordPress CMS.

I've contacted my host. Got a No virus on your site response .

I'll follow your recommendations. Thanks.
 
Ok don't panic.

In general: Don't post a link to a hacked site, atleast remove the href so its not clickable. A hacked site may contain malware and users that accidentally click on the link may get infected.

So here we go:
  1. Have you used a CMS?
    If yes, see if you have access to the database and make a backup of it. This is the most important thing.

  2. Change your accounts passwords (ftp/sftp, database, hosting panel etc. ASAP) and remove EVERYTHING you have from your server It may be possible that php files or other files on your server have been infected by the hacker and can cause damage even after you have changed the ftp password.

  3. As other said, contact your hosting company and explain to them what has happend. They will tell you what to do next.

  4. In the meantime scan your computer. It is possible that even your machine is infected (RAT, Keylogger etc.).

I hope for you that you have a local backup of everything.

Hi, is it real? My pc will get infected even if i click the homepage link, for example http://www.blackhatworld.com? I always thought we are safe as long as we do not grant any pop out permission or download files from there.
 
Hi, is it real? My pc will get infected even if i click the homepage link, for example http://www.blackhatworld.com? I always thought we are safe as long as we do not grant any pop out permission or download files from there.

Always possible to be hit with a drive by download (https://heimdalsecurity.com/blog/how-drive-by-download-attacks-work/) which essentially exploit a vulnerability in your flash player, browser or plugin to get enough permissions to drop the malware in.
 
Always possible to be hit with a drive by download (https://heimdalsecurity.com/blog/how-drive-by-download-attacks-work/) which essentially exploit a vulnerability in your flash player, browser or plugin to get enough permissions to drop the malware in.

Damn. I feel like every website is not safe after reading that article. Haha. I think turn on 2 steps verification whenever available is safest for now.
 
Damn. I feel like every website is not safe after reading that article. Haha. I think turn on 2 steps verification whenever available is safest for now.

Most antiviruses have some form of anti-exploit, if your paranoid, then grab the paid version of malwarebytes, as it has a really good anti-exploit utility built in that works really well for most of the known exploit kits like angler and all that.
 
Most antiviruses have some form of anti-exploit, if your paranoid, then grab the paid version of malwarebytes, as it has a really good anti-exploit utility built in that works really well for most of the known exploit kits like angler and all that.

Ya Malwarebytes was the first thing pop out on my mind too. Been using free version few years ago and decided to uninstall it because i think i am good enough to prevent malwares until i read the article you shared.
Thanks again.
 
Always possible to be hit with a drive by download (https://heimdalsecurity.com/blog/how-drive-by-download-attacks-work/) which essentially exploit a vulnerability in your flash player, browser or plugin to get enough permissions to drop the malware in.

Fortunately any competant anti-virus out there to date such as Norton (Yes, even Norton!), MalwareBytes, Avast are pretty good at stopping Drive By vulnerabilities.
- Cons, sadly new viruses are created every single day to exploit peoples sytems, an anti virus will do 90% of the job, people need to not be spastics and do anything stupid to facilitate a virus to function past your anti-virus.

For instance; many people click disallow to malware pop ups, strange, you'd think people would take security seriously after everything that has happened in the last few years.

Check out ClamAV, it's ideal for server-wide security.

Hi Buddies.
My site got hacked and presently redirects to another site. Kind hearted members of this great forum should PLEASE assist on how to recover the site.

-- Regarding OPs site;

Speak to your hosting company, if you have access to your cPanel you can remove any forwarders from the Cpanel instance yourself. Strange they're just redirecting to another website at the moment, only reason someone would do that is if it's got a decent DA.

Is there a chance that the hacker got in at domain-level? For example; Has access to your GoDaddy, NameCheap etc, this means they could directly bypass cPanel by doing a domain name forward.

Change your WordPress back end password in PHPMyAdmin, or your backend by going to the localhost of the server. Here (http://www.wpbeginner.com/beginners-guide/how-to-reset-a-wordpress-password-from-phpmyadmin/)

Change your Domain Registrar username/password to something more secure.

** WordPress vulnerabilities.
What version of WordPress are you running? Did you know that there are many vulnerabilities in almost every version of WordPress, it's hard to keep up with them all, I'd update to the latest version of WP which at the moment has only a few, better than being on a version that has thousands..

** Antivirus
I'd recommend MalwareBytes, do a full scan, it offers you free 14 day premium so utilise that and do a hyperscan, and full scan.

Most websites are pretty secure now a days as most hosts do have an antivirus or firewall installed on most servers to resolve problems like this at the core, however most problems related to website hacking comes directly from the user.

Sources: Cyber Security Analyst 6 years.

Let me know if you need any extra help OP, drop me a pm and I'll do my best to answer, or guide you in the right direction.
 
if its a redirect issue first thing to check is your htaccess file you can find the redirect there
then you can check the index file of the cms your are using (in you case wp)
 
Back
Top