FreakenSEOsmh
Power Member
- Jul 31, 2017
- 587
- 401
Hello
So i used a nulled wp theme to test how its visual builder feels and to compare it with Elementor and WPbakery and after a while i noticed that google has crawled the website and like 6k pages on it, that i didn't create and that doesn't even exist on my server. I think this is how it was done
- Attacker purchased the original theme.
- Attacker planted php files in the theme that can change permissions of files and also remote upload new files.
- Attacker went to Google webmaster tools and added the website as his own.
- Google asked him to verify the website so he used the php files ( with the scripts he planted earlier ) to remote upload the google ownership verification HTML file.
- Attacker ownership verified so he submitted sitemaps to google.
- Stupid Google indexed the false sitemaps and the URLs in it.
- Attacker redirected all the newly created pages to his main website from my own URL - [ big mistake, later to come ]
How i found out:
+ Google gave me a new website owner alert and notification.
+ I then removed the mofo.
+ Inspected my website files and removed the Owner verification file and the sitemaps.
+ Removed the malicious php files from my server.
+ Decided to remove everything after that, the theme, the DB and even the wordpress installation.
Problem is:
His fucking pages are still indexed in google, i can remove them by using the removal tool, but as i mentioned its like 6k pages and i don't have time for this shit. I can forget about the website, it doesn't matter much to me, the domain i mean but NO. fuck that guy.
my question is how can i handle this from here? i need all pages de-indexed.
PS: i traced his original website, which is an online store and have ordered a couple of Ks adult links to it. Found his store social media profiles and ordered reviews on them as well..
i might have forgotten something, if you need more info let me know, and if you are aware of a solution that 'd be much appreciated.
Thanks.
So i used a nulled wp theme to test how its visual builder feels and to compare it with Elementor and WPbakery and after a while i noticed that google has crawled the website and like 6k pages on it, that i didn't create and that doesn't even exist on my server. I think this is how it was done
- Attacker purchased the original theme.
- Attacker planted php files in the theme that can change permissions of files and also remote upload new files.
- Attacker went to Google webmaster tools and added the website as his own.
- Google asked him to verify the website so he used the php files ( with the scripts he planted earlier ) to remote upload the google ownership verification HTML file.
- Attacker ownership verified so he submitted sitemaps to google.
- Stupid Google indexed the false sitemaps and the URLs in it.
- Attacker redirected all the newly created pages to his main website from my own URL - [ big mistake, later to come ]
How i found out:
+ Google gave me a new website owner alert and notification.
+ I then removed the mofo.
+ Inspected my website files and removed the Owner verification file and the sitemaps.
+ Removed the malicious php files from my server.
+ Decided to remove everything after that, the theme, the DB and even the wordpress installation.
Problem is:
His fucking pages are still indexed in google, i can remove them by using the removal tool, but as i mentioned its like 6k pages and i don't have time for this shit. I can forget about the website, it doesn't matter much to me, the domain i mean but NO. fuck that guy.
my question is how can i handle this from here? i need all pages de-indexed.
PS: i traced his original website, which is an online store and have ordered a couple of Ks adult links to it. Found his store social media profiles and ordered reviews on them as well..
i might have forgotten something, if you need more info let me know, and if you are aware of a solution that 'd be much appreciated.
Thanks.