All my sites hacked

If you're using Wordpress, once you have a CLEAN Wordpress site set up, the first plugin you should install and configure is:

Code:
http://wordpress.org/extend/plugins/bulletproof-security/

Also, get a proper backup/restore plugin for when you want to sell someone a site, rather than making a rookie mistake in phpMyAdmin (or similar). At least you will just backup/restore that plugin. Avoid nulled themes and instead use one with a good reputation from Wordpress' own site (no backdoors "pre-packed").



I was waiting on some jackass with too much time on his hands to come to this thread and say something stupid. Thanks so much for that.
 
Well the next time I want to give something away I'll just throw it away.
 
I was waiting on some jackass with too much time on his hands to come to this thread and say something stupid. Thanks so much for that.

If you want to leave yourself open and not use something like BulletProof Sercurity, go ahead. It will not only help prevent, but also warn of potential site issues. (Did you actually take a look at what it protects against? Probably WP's most extensive plugin for security, and will stop most ways people are injecting code.) You made a mistake, live with it (not necessarily the one that caused your sites to be hacked - seems a lot of recent hacks have been on sites with paid themes). If you want to take it out one someone, yourself rather than anyone trying to give you some suggestions (I could have made fun instead - may as well have given your response).
 
Had this problem too. Check your index.php file and possible you'll have a long line before <?php

Happened to me, just deleted it and was fixed
 
Why would you send him a free site with details to the rest in the first place? ...
 
I was waiting on some jackass with too much time on his hands to come to this thread and say something stupid. Thanks so much for that.

Nothing stupid here, he suggested exactly what you need. Its the best plugin that you can find to prevent injections, xss etc. Your answer is retarded and un-respectful. Don't ask for help if you think that you don't need it.
 
Nothing stupid here, he suggested exactly what you need. Its the best plugin that you can find to prevent injections, xss etc. Your answer is retarded and un-respectful. Don't ask for help if you think that you don't need it.

Yeah, I didn't really get the jackass comment. Even if the plugin sucks (I don't know, never used it) it couldn't hurt anything.
 
For more security install "Crawlprotect" it's free. I used to be hacked twice a week during 3 months!!!!!!!! by a stupid competitor, when I installed this and blocked all his IPs I had no more hack attempt.
 
Nothing stupid here, he suggested exactly what you need. Its the best plugin that you can find to prevent injections, xss etc. Your answer is retarded and un-respectful. Don't ask for help if you think that you don't need it.

That's funny. If you saw me in person you'd look down at the ground. It's the

nerds with the smart mouths that kill me on these forums. Tough talking from

somebodys basement in their underwear..
 
I guess it wasn't as big of a mistake as I initially thought. I'm seeing some good

answers with some good info in them thanks. Everybody that reads this thread will have

the most impenetrable sites online.
 
Yeah, I didn't really get the jackass comment. Even if the plugin sucks (I don't know, never used it) it couldn't hurt anything.


The comment wasn't about the plugin I actually thought it was a good

suggestion. It's the little condescending remark about it being a "rookie

mistake" that's why I called him a jackass. It's unnecessary. Most times I

overlook it because it's petty but sometimes I respond.
 
I learned a lot from this situation and I'm sure people who read this thread will too.

Don't ever think you're immune to making mistakes because it happens. I learn the

most from mistakes actually. I still gave away 4 ranking, functioning sites without a

catch or motive which was a big contribution to the members who received them.

Thanks again to everybody who had something relevant to say.
 
That's funny. If you saw me in person you'd look down at the ground. It's the

nerds with the smart mouths that kill me on these forums. Tough talking from

somebodys basement in their underwear..

Wow, you're a loser. If I saw you in person I'd laugh at you for being so stupid and sending your mysql files. I'm 6'3" 235lbs with 8%bf, I think I'd be okay :D:D:D:D:D
 
Dont Feel too bad about it OP I made the mistake of telling a Fiver guy off because he did not understand English, so he went in and deleted my biggest site.
My bad since I never changed the Log ins that I gave him.
Well site Lost but Lesson learned
 
If ONE theme has an old version of tim thumb it gives access to the database with a hack.You don't need sql to get in,there was a patch but if you haven't patched it it is a big exploit.
 
Wtf are people even bashing others? Enough with the internet tough guy b.s., it happens. Maybe not to you superfantastic webmasters(of the universe), but it happens.

Anyway, that does suck. I try to back up my stuff once per week, and I am constantly changing passwords, etc. Get my sites checked for exploits, whatever I can do.

I've actually got a goofy Russian kid who helps me out with that now. And when I say "goofy", I mean he's smarter than I.
 
Dont Feel too bad about it OP I made the mistake of telling a Fiver guy off because he did not understand English, so he went in and deleted my biggest site.
My bad since I never changed the Log ins that I gave him.
Well site Lost but Lesson learned

That's terrible. I guess it could always be worse..
 
If ONE theme has an old version of tim thumb it gives access to the database with a hack.You don't need sql to get in,there was a patch but if you haven't patched it it is a big exploit.



I'll look into that. I came to conclusion of the sql exploit because of some

help from namecheap tech support. If it's because I haven't patched a few

themes the timing is impeccable with this whole sql thing.
 
Back
Top