My site has been hacked :(

Yup as others said take it as a hard lesson.

Sounds almost exactly the same as what happened to me on xmas day >_<.

Go to check my site and see some assholes banner on there.

Since then I take a backup after EVERY post to my website.
 
Depending on where you are from, cops take hacking seriously, you should contact them and explain your situation.
With a bit of luck the guy who done that to you will have an unpleasant visit from the interpol tonight. ;)
 
Using ultimate-security-checker, I got the following:

Code:
[B]F[/B]             [B]Code check[/B]
            [COLOR=#aaaaaa]Users can see the version of WordPress you are running from the readme.html file.
Installation script is still available in your WordPress files.
WordPress displays unnecessary error messages on failed log-ins.
Your blog can be hacked with malicious URL requests.
Some of blog core files have been changed.[/COLOR]


but when i click to view report it says it's fine :S
 
THEY should backup your site;) before site was hacked
 
That sucks, they hacked three of mine in one day. Good luck!
 
assuming you have access to phpmyadmin just follow these steps to get your blog back. also make sure you have a off the wall password like "hsjw#kk*-98*" or something.
http://www.wpbeginner.com/beginners-guide/how-to-reset-a-wordpress-password-from-phpmyadmin/
 
Your WP installation was updated ?

I'm working on a Fb Plugin to prevent this.... so could you let me know if some Cache plugin or something like this where installed ?

Thanks
 
check your theme mostly it maybe hacked .change the theme and check if site works ok
 
This is probably a good time for everyone reading to backup everything they have.

Personally I can't sleep at night if I don't have at least a backup folder on my hard drive and another backup folder on my external hard drive. For stuff like my main accounts/passwords I keep that on good old fashioned paper tucked away nicely, but I'm what most people call paranoid.

thats the best thing to save data and accounts /passwords
i have learned this hardway :(
 
For stuff like my main accounts/passwords I keep that on good old fashioned paper tucked away nicely, but I'm what most people call paranoid.
I can't be okay with writing all that info on a paper because somebody might see it so I keep everything in my head. So I recon you're not paranoid enough.
 
Hacking and defacing these sites, is such a waste of time.

Idiots that hacked me (yesterday), had the balls to leave not only links to their OWN WP site, but also their Facebook Page.

They love to gloat about their exploits.

Same site has been hacked over and over, and I have made a ton of changes to it.

The site stays safe for about a month and then bam....another hacker attack!

Grrrrrrr........

Anyone have a rock solid way to stop them in their tracks?
 
Get your hoster to give you the access logs for your domain and see if you can find out how they got in
 
currently im sorting out a hack. they've 301-ed everything to their own website. ffs.
 
alot of these hack attempts, especially defacing, is accomplished by the webmaster installing infected files on their server.

Always, always, always scan files before you upload and install them on your server.

Also, always, backup your site. Make it routine. Like once a week or anytime you make significant changes. Keep multiple backups, just in case.

When my site was hacked it was down for max 2 hours. The web hosting company wiped the account clean and I uploaded my backup and rebuilt the site. Easy.
 
We had a customer whose site got hacked this past Friday. Here are my suggestions and perhaps this can help you:

1) Upgrade to the latest version of WP (always)
2) Back up both your files AND database. We back up to AmazonS3 and also to another server (FilesAnywhere - it really doesn't matter).
3) We also keep an extra copy of a full (email, db, files, etc) backup on the actual host. (Call me anal, but I have been through lost data more than once and more than once the backup I went to was not a complete copy or current.)
4) Keep an online log (Google docs?) with columns for all these activities and the dates/times you last backed up.

Now... post a job somewhere like elance or vworker. Experienced people can help you recover your login profile as long as your host can get you ftp access... and your host perhaps has a backup... but make sure you get them before they back up your bad site with a bad version and delete the good (previous before hacked) version.

Good luck.
 
well you can always edit htaccess banned any ip to access to your server and edit it and your the only one who can access your web server.
 
Back
Top