HELP!!! My Site Has been Hacked!

DuckingOutstanding

Senior Member
Joined
Dec 22, 2015
Messages
1,108
Reaction score
769
What do I do to recover it??? Or How nasty is it??? My adult tube site <Site removed for privacy purposes> got hacked by some Asshole gamer douche named "KaLiNux" who is probably a virgin and clearly has entirely too much free time on his hands -what can I do to recover my site from this punk? How bad is this hack? PLS HELP!
 
Do you have a backup's? need more tech details..
 
which platform its on? can you access the cpanels? or atleast to the ftp?

I can access Cpanel on my host - the site is built with WP-Script Pro (theme and grabber) on WP (clearly)...not sure what to clean up in the cpanel other than maybe see if there is an earlier restore point? not sure if there is/where to find
 
If you are using Nulled version then it may be have some encrypted virus
if you don't know how to check php files or if your knowledge is not in programming then please hire anybody fast or take help of someone via Teamviewer .

OR Come in PM i can assist you on Teamivewer
 
well, in all those years of IM and 100+ WP installs, it was either:
fucked up theme that was abandoned (thanks *** from de-optimizepress!)
or shitty hosting claiming it was "clients fault", not running "anti herpes software" or having "holy virgin weak p@zzw0rd$"
 
@DuckingOutstanding Well, it would be great if you'd understand what your vulnerability is, otherwise, what would stop him from attacking you again?
yu7
would love to know - clearly - but at this point that's a "Hindsight is always 20/20" issue...meanwhile - it was on shared hosting but with an SSL certificate, Jetpack, and WP Fence....it's a free tube site ad-monetized that does not take any form of payments for anything directly so they did it for fun basically....idk
 
If you are using Nulled version then it may be have some encrypted virus
if you don't know how to check php files or if your knowledge is not in programming then please hire anybody fast or take help of someone via Teamviewer .

OR Come in PM i can assist you on Teamivewer
Def not nulled, pro version of both purchased full price and downloaded directly from wp-script.com along with updates kept it up to latest version of WP, all my plugins, and WP-Script Theme and Grabber meticulously
 
well, in all those years of IM and 100+ WP installs, it was either:
fucked up theme that was abandoned (thanks *** from de-optimizepress!)
or shitty hosting claiming it was "clients fault", not running "anti herpes software" or having "holy virgin weak p@zzw0rd$"

Of those suggestions the only one that makes sense would (MAYBE) be hosting issue - but in all fairness havent had enough time passed to give them a fair shot to reply (site was fine literally 2 1/2 hours ago, i posted this "HELP" thread immediately after submitting a ticket to my hosting company, immediately upon discovery) password is unlikely to be the issue and theme seems to have an update every week or two
 
Check your server logs. Ive had many wordpress sites "attacked" through xml-rpc vulnurability. If you can still log into your cpanel but not able to log into wordpress I would suspect you were victim of some sort of brute force attack on your wp-admin. if you have a weak password then this is fairly simple.

But yeah, you would need to drop way more details on your current set up to get any sort of valuable feedback.
 
Of those suggestions the only one that makes sense would (MAYBE) be hosting issue - but in all fairness havent had enough time passed to give them a fair shot to reply (site was fine literally 2 1/2 hours ago, i posted this "HELP" thread immediately after submitting a ticket to my hosting company, immediately upon discovery) password is unlikely to be the issue and theme seems to have an update every week or two

dude.if your site got whacked and you werent the usual cheap, be true to yourself, change hosting.
rule of thumb, pay 2x next time.

also, if yo use WP, expect hacks. I was surprised, I only had 1 issue inall years.
if you use windows, be prepaired to get virii
.
if you use android, be prepaired for hacks.
and so on.
if you use any electronic shit, be prepaired.
if you leave your house, be prepaird for cars running you over.
and so on.
and I was even more susprised, a plain html site( ya know, coded in notepad... and n scpript) got hacked.
when I found out, I killed the contracat and moved the 4kbyte of site.
 
Check your server logs. Ive had many wordpress sites "attacked" through xml-rpc vulnurability. If you can still log into your cpanel but not able to log into wordpress I would suspect you were victim of some sort of brute force attack on your wp-admin. if you have a weak password then this is fairly simple.

But yeah, you would need to drop way more details on your current set up to get any sort of valuable feedback.

for like 6 months, some bot is tried to get into /wp-admin/
I even posted that here.
a simple plugin that moves wp-admin to some other folder solvedd that..
I bet you, 99% hacks guys get when they are doing IM like we, are never the cause of week pazzwords..

even some PBN sites got whacked. some sellers here stated that. and I am very sure, they dont even know their sites password..
 
without looking at the server nobody can tell you how bad it is nor how to fix it. most replies were from people as cluless as you if it comes to security, no offense :)
i mean yes nulled scripts often contain backdoors but never "encrypted viruses" lol
just FYI i'm not talking out of my ass, i do penetration tests (also for fortune 500 companies) since the 90s so i've seen thousands of hacked servers over time...

first of all if its wordpress then there are many entry points. there are tons of vulnerable plugins and themes, these plugins are usually coded by people who have no or very little clue of security.
that being said, it might not have been wp at all. deppends on what other services are running on the server. maybe an outdated ftpd, smtpd, pop3d, imapd? or did you run other domains that have php scripts?
offten times people also have "secret" php scripts somewhere as they think if its not indexed by searchengines, nobody can find them, which is of course wrong..
or maybe some "test" install of wp somewhere left over?

if you have a bit of linux knowledge, login via ssh and check for newly created, or edited php files in the directory where the hacked site is hosted. since you said its a tube site, it is very likely that the upload mechanism is exploitable to upload files other than images or videos. so i'd check the upload, cache and temp directories (if they exist).

@daruelez sorry to say, but weak passwords are VERY common in the IM world :) i offten tell customers to set better passwords and they go "why its only for a <PBN,porn,mfa,enter whatever here> site?" ..some honestly set 4-5 char passwds!! many compromised wp installs are due to bruteforce as admins think its clever to set passwords like "password1", "mydomainname1" or "123456789". seriously :p
 
First and foremost thank you all 4 your input advice and rapid response it is that type of genuine peer support without motive that keeps me coming back to bhw almost everyday for almost 2 years now I do really appreciate it.

UPDATE: so it looks like I was fairly lazy / sloppy with my unused themes and plugins a few of each something I know better than to do and here's a reminder of why we get rid of unused themes and plugins besides speeding up the site of course they leave in their wake vulnerabilities and opportunities for exploits although I've been meticulous about keeping my used plug-ins and themes of today not only have I needlessly carried that coded baggage that is installed but unused inactive themes and plugins but I also neglected to update those as well... my web hosting provider actually got rid the issue for the moment and actually stepped up to the very quickly I might add I'm talking it was fixed within a few hours of submitting an email ticket they also provided me with a rather thorough checklist of tasks to complete to insure no such vulnerabilities exist going forward and proactively identified potential vulnerabilities that were not specifically exploited in this attack... it is with gratitude and surprise that I'm saying this today but I am beyond ecstatic that I went out on a limb said what the hell and chose not to listen to my initial assumption that jvzoohosting would be inferior or somehow cheap as I perceive a lot of the I am products sold on jvzoo to be because apples for apples not only is this much better support than I have ever received from a hosting provider bad looking at uptime speed features and under the hood specs they actually even beat out a2hosting my previous favorite although the one time I had a minor hack on a site hosted by A2 hosting they made it damn clear I was on my own even though I had been paying for what was allegedly protection against exactly that but I digress..

Serious kudos to jvzoohosting.com ( not an affiliate link not any sort of incentive or motive for mentioning them other than genuine satisfaction with the service purposely not hyperlinking that URL in order to eradicate any misunderstandings about that)

Now the only negative besides of course meeting to rearrange files and folders change all passwords and certain admin and file prefixes is that my most recent backup /restore point that I bothered to create happened to create was when my sight was in much more of an infancy status if you will... Not unpolished mind you, however the vast majority of the video content I had hand curated and SEO optimized with unique descriptions titles tags Etc doing my due diligence to insure against duplicate content penalties is gone... my burgeoning high-quality targeted Niche specific tube site went from having nearly 20,000 highly relevant hand curated to ensure quality tube videos 2 less than 4000 so clearly I have my work cut out for me if I am to build it back to that level but that may be a blessing in disguise because although I had been applying all of my mainstream SEO knowledge and techniques to the creation of this very site somehow even with unique content respectable word length per page natural keyword usage sufficient to establish a topic without over optimization ensuring that I don't cannibalize keywords connecting and. using social media obtaining relevant backlinks from sites that do rank and avoiding lq links and using multiple SEO tools to ensure on page optimization my sight was not ranking worth s*** even with a few thousand visitors a day largely from other tube sites Reddit Twitter and display ads actually pretty much all from those almost zero organic visitors and my site did not even show up in search if you typed in my specific URL without the dot or the ww w the site name was pussylicking.party if I typed pussylickingparty or pussy licking party into search you would not find pussylicking.party anywhere in the first five pages of results and although there were a number of keywords well a dozen to be honest in the top 100 results for that keyword none of them or even in the top 50 he was truly driving me insane as it made 0 sense to me whatsoever especially since sites that were raking way higher than mine for certain keywords didn't appear if you have any relevance whatsoever to said p word or little at best and appeared both aesthetically and Via SEO audit to be inferior perhaps now I can diagnose the issue and learn the nuances of adult site SEO that I clearly haven't mastered as I assumed it would be same actions just adult version which I was obviously wrong about LOL not to change the topic of the thread but if any adult webmasters or SEO specialists in the adult industry could perhaps shed some light on the subject that would be awesome
 
Back
Top