my website got hacked by a Japanese guy

Status
Not open for further replies.

FreakenSEOsmh

Power Member
Joined
Jul 31, 2017
Messages
587
Reaction score
401
Hello

So i used a nulled wp theme to test how its visual builder feels and to compare it with Elementor and WPbakery and after a while i noticed that google has crawled the website and like 6k pages on it, that i didn't create and that doesn't even exist on my server. I think this is how it was done

- Attacker purchased the original theme.
- Attacker planted php files in the theme that can change permissions of files and also remote upload new files.
- Attacker went to Google webmaster tools and added the website as his own.
- Google asked him to verify the website so he used the php files ( with the scripts he planted earlier ) to remote upload the google ownership verification HTML file.
- Attacker ownership verified so he submitted sitemaps to google.
- Stupid Google indexed the false sitemaps and the URLs in it.
- Attacker redirected all the newly created pages to his main website from my own URL - [ big mistake, later to come ]

How i found out:

+ Google gave me a new website owner alert and notification.
+ I then removed the mofo.
+ Inspected my website files and removed the Owner verification file and the sitemaps.
+ Removed the malicious php files from my server.
+ Decided to remove everything after that, the theme, the DB and even the wordpress installation.

Problem is:

His fucking pages are still indexed in google, i can remove them by using the removal tool, but as i mentioned its like 6k pages and i don't have time for this shit. I can forget about the website, it doesn't matter much to me, the domain i mean but NO. fuck that guy.

my question is how can i handle this from here? i need all pages de-indexed.

PS: i traced his original website, which is an online store and have ordered a couple of Ks adult links to it. Found his store social media profiles and ordered reviews on them as well..


i might have forgotten something, if you need more info let me know, and if you are aware of a solution that 'd be much appreciated.


Thanks.
 
That's sad, did you not use any security plugin?

Mine was also attacked a few months back: Owner was added and Asian(most probably Japanese) pages were created.

Someone here on BHW recommended using WordFence Plugin, no problem after that!

EDIT: The indexed URLs are still visible in SERPS even after 6 months of the attack(only few of them though).
 
Sometimes stupid kids hack websites and redirect spam pages to opponents sites.. so maybe the store you found isn't the cracker behind your problem.

As for your problem just disallow the folder and wait some weeks...
 
Never, ever, use nulled themes or plugins, even ones posted here. Getting rid of those viruses are a headache, so I would recommend getting a new server and restoring a backup to before you installed anything nulled, then remove those pages in Google webmaster. If you remove them on your own, they'll keep coming back.

I know you mentioned you don't care for this domain, but if you have other domains on your server, they're most likely infected as well.
 
Can't you deindex entire directory? (Remove)

Going to try that, thanks for your answer.

That's sad, did you not use any security plugin?

Mine was also attacked a few months back: Owner was added and Asian(most probably Japanese) pages were created.

Someone here on BHW recommended using WordFence Plugin, no problem after that!

EDIT: The indexed URLs are still visible in SERPS even after 6 months of the attack(only few of them though).

No security plugins were used, i was just testing a visual builder but i still want to know how i can recover from this, i might need that info in the future.

Sometimes stupid kids hack websites and redirect spam pages to opponents sites.. so maybe the store you found isn't the cracker behind your problem.

As for your problem just disallow the folder and wait some weeks...

will disallow the folder, as for it not being his website well, i have got to relief my anger somehow i guess

Fuck his website SEO then

believe me i am going to make him regret this, just have to get rid of my current workload and on my nearest holiday am going to fingerprint the asshole and make him wish he didn't even think about this.

Never, ever, use nulled themes or plugins, even ones posted here. Getting rid of those viruses are a headache, so I would recommend getting a new server and restoring a backup to before you installed anything nulled, then remove those pages in Google webmaster. If you remove them on your own, they'll keep coming back.

I know you mentioned you don't care for this domain, but if you have other domains on your server, they're most likely infected as well.

Lesson learned, its was only like 59 or 64$. I kind of deserve it tbh

checked the rest of the domains in the server and they are all good, well except for one where i tried to replicate what he did as its a smart idea. Learn more about Curl ;)

Forget about him and move on it was your mistake after all

Never. what if it happens again? also move on.



Lesson here is that google is far from being perfect and can still be gamed


Thank you all for your replies <3
 
That is not a good new when it was being hacked by someone. I don't like it though
 
How do you know that he is Japanese?

Anyway, I would just move on. Wasting time and energy on revenge is not worth it, use it to secure your next website.
 
Op must be smokin some gut crack... All that happened is you downloaded nulled plugin or theme
 
if they were in a directory, such as /blog/ ... then super easy to remove that directory and all urls nested in it.

If they were regular posts on the root domain, you'll have to do it each time.
 
if they were in a directory, such as /blog/ ... then super easy to remove that directory and all urls nested in it.

If they were regular posts on the root domain, you'll have to do it each time.
Phpbuilt... You come back after so many yrs... Mommy let you out of basement?
 
That is not a good new when it was being hacked by someone. I don't like it though

no meaningful info have been provided by your reply at all.

How do you know that he is Japanese?

Anyway, I would just move on. Wasting time and energy on revenge is not worth it, use it to secure your next website.

You are right, the spam is Jav doesn't mean the hacker is Jav as well.

Ok. Wait! Who gave you the idea to use Nulled theme? Who's fault is this?

Did i ask who's fault was it? did i?

Op must be smokin some gut crack... All that happened is you downloaded nulled plugin or theme

Ok thanks, didn't know that. ffs.



Very helpful mr Moderator. very helpful :facepalm:

To those saying boohoo you used a nulled theme, i fucking know and you are not helping at all so keep to yourself please. don't you think i know? don't even reply to this and forget about the whole thread. Thank you.

if they were in a directory, such as /blog/ ... then super easy to remove that directory and all urls nested in it.

If they were regular posts on the root domain, you'll have to do it each time.

The best way to handle this, and after going through Google, copied as it is from stackexchange - for anyone that might have the same problem.

We just had this problem.

It was really ugly, 60 000 pages of spam created because of loop hole in our spam filter. We manually deleted all the pages, causing 404 error to be present for Google.

Months later the ugly pages were still in Google SERPs.

We searched for bulk removal tools in Google Webmaster, no luck, clearly 1 by 1 removal was not suitable using Google's tool.

We decided the best way was to add all of the 404 pages to our robots.txt file to the disallow list, (read up on this if you're not sure what it is).

The trick, is, to do this within minutes we did the following:

  1. Go to Google Webmaster Tools, crawl errors and there downloaded to .csv the errors.

  2. Open .csv, highlight the column with the URLs

  3. Paste the URLs into a plain text editor, (removes frames). You'll get a list of full URLs.

  4. Now you need to change http://www.yoursite.co.uk/page-you-want-to-delte into Disallow: /page-you-want-to-delete.

  5. So paste the list into Ms Word, or similar word processor

  6. Go to 'edit' find replace, find, http://www.yoursite.co.uk replace with Disallow: .

  7. Tweak until you've got it right, paste the results into a basic text editor to remove fancy text formatting.

  8. Bang you have the URLs in a format ready to copy and paste directly to your robots.txt.
 
no meaningful info have been provided by your reply at all.



You are right, the spam is Jav doesn't mean the hacker is Jav as well.



Did i ask who's fault was it? did i?



Ok thanks, didn't know that. ffs.




Very helpful mr Moderator. very helpful :facepalm:

To those saying boohoo you used a nulled theme, i fucking know and you are not helping at all so keep to yourself please. don't you think i know? don't even reply to this and forget about the whole thread. Thank you.



The best way to handle this, and after going through Google, copied as it is from stackexchange - for anyone that might have the same problem.

We just had this problem.

It was really ugly, 60 000 pages of spam created because of loop hole in our spam filter. We manually deleted all the pages, causing 404 error to be present for Google.

Months later the ugly pages were still in Google SERPs.

We searched for bulk removal tools in Google Webmaster, no luck, clearly 1 by 1 removal was not suitable using Google's tool.

We decided the best way was to add all of the 404 pages to our robots.txt file to the disallow list, (read up on this if you're not sure what it is).

The trick, is, to do this within minutes we did the following:

  1. Go to Google Webmaster Tools, crawl errors and there downloaded to .csv the errors.

  2. Open .csv, highlight the column with the URLs

  3. Paste the URLs into a plain text editor, (removes frames). You'll get a list of full URLs.

  4. Now you need to change http://www.yoursite.co.uk/page-you-want-to-delte into Disallow: /page-you-want-to-delete.

  5. So paste the list into Ms Word, or similar word processor

  6. Go to 'edit' find replace, find, http://www.yoursite.co.uk replace with Disallow: .

  7. Tweak until you've got it right, paste the results into a basic text editor to remove fancy text formatting.

  8. Bang you have the URLs in a format ready to copy and paste directly to your robots.txt.
That’s a lot of sass coming from someone who’s basically a ‘thief’.
 
Very helpful mr Moderator. very helpful :facepalm:

You posted on a public forum and you will get a variety of responses.

Mine was in line with the forum rules.

I'll be more expansive for you though - using a nulled theme is not a very wise move in most instances as you may encounter issues just as you did. Spend the money for the theme from the developer and you will likely not have the issues you have.

Facepalm all you want as I did the same thing when I read that you are using a nulled theme but did not want to make that public but since you did I will.

Be smart with your sites if you care about them and use legitimate themes.
 
I think the reply was intended to make me feel uncomfortable, guess what ... I don't.
Go and have some burger if you want to feel comfortable. You should not have posted this atall, if you didn't want to feel uncomfortable. Duhh.
 
You posted on a public forum and you will get a variety of responses.

Mine was in line with the forum rules.

I'll be more expansive for you though - using a nulled theme is not a very wise move in most instances as you may encounter issues just as you did. Spend the money for the theme from the developer and you will likely not have the issues you have.

Facepalm all you want as I did the same thing when I read that you are using a nulled theme but did not want to make that public but since you did I will.

Be smart with your sites if you care about them and use legitimate themes.

The problem is, I know, i swear to god I KNOW using nulled themes can lead to problems. that is why i haven't used it on a production website. this is all for testing purposes, if i hadn't used a nulled theme and this happened to me i wouldn't have known about the removal tool, and that google don't directly provide Bulk removal, and that you can use the robots.txt files to disallow indexing and alot more info.

What made me upset is the replies saying that its my fault, I already know that.

the domain name i used even has numbers on it :D i couldn't care less about it but now i know how to fix these types of problems should they happen again in the future.

As for using nulled themes, i don't think am going to stop using them but on domains with extensions like .xyz and someother shit and for testing purposes as i am trying to become a web designer/developer.

So much explaining that isn't even related to the main issue.

Go and have some burger if you want to feel comfortable. You should not have posted this atall, if you didn't want to feel uncomfortable. Duhh.

i must be stupid, i don't get what you wrote. Please don't try to explain it, Thanks.
 
Status
Not open for further replies.
Back
Top