1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

My site is hacked...!! Plz Help...!!

Discussion in 'BlackHat Lounge' started by SwanWing, Sep 12, 2010.

  1. SwanWing

    SwanWing Registered Member

    Joined:
    Jun 27, 2009
    Messages:
    55
    Likes Received:
    7
    Location:
    France
    Hi people...

    I tried to access my site today and the home page that showed up was not mine... but some "Albanian Hacking Crew". I have no idea wat to do now... I'm not able to access my WP admin account also...The password and the password recovery mail id has also been changed...

    I have no idea what to do now... I'm all freaked out!!! Can anyone plz tel me wat's happening or suggest some solution... :(
     
  2. jodys

    jodys BANNED BANNED

    Joined:
    Feb 10, 2010
    Messages:
    174
    Likes Received:
    131
    Restore a backup and move on. If you weren't doing backups your hosting service probably was. Ask them to restore a backup of your account from before you were hacked. No big deal, just get it done quick before Google picks it up
     
  3. SwanWing

    SwanWing Registered Member

    Joined:
    Jun 27, 2009
    Messages:
    55
    Likes Received:
    7
    Location:
    France
    And the admin login...??
     
  4. CyrusVirus

    CyrusVirus BANNED BANNED Premium Member

    Joined:
    Aug 20, 2009
    Messages:
    1,110
    Likes Received:
    686
    well hopefully it was just a admin sql injection, in that case, just goto your sql database and change the admin name to whatever, and change the email back to yours. im not sure if there is a forgot pass but that always helps. try the new admin name with your pass first though.
     
  5. likeskoolaid

    likeskoolaid Regular Member

    Joined:
    Dec 27, 2009
    Messages:
    352
    Likes Received:
    104
    Occupation:
    \˚ㄥ˚\
    Location:
    \ᇂ_ᇂ\
    Sorry to hear that. Was your password difficult to crack or was it a normal everyday kind of word? If it was someones name or something, your password probably got cracked. I suggest in the future you use some kind of combination like

    Z8kJkKkl239JhAhE, which is nearly impossible to get cracked. Unless you were key logged. Which means whatever you type is being monitored and sent to the hackers.

    Have you downloaded any new or suspicious software recently? If you have then you should backup the rest of your files and do a reboot of your hard drive. But I don't think that's necessary I think you were just brute forced because you used a simple password.

    There's probably not much you can do unless you can reset your password through email.. try the official word press site for that.
     
  6. daserpent

    daserpent Power Member

    Joined:
    May 10, 2010
    Messages:
    762
    Likes Received:
    470
    What kind of site was it? Did you have a good alexa rank?
     
  7. youssef93

    youssef93 Senior Member

    Joined:
    Sep 14, 2008
    Messages:
    828
    Likes Received:
    1,148
    Occupation:
    Student, Part-time Online Marketer
    Location:
    Egypt
    First off, calm down.

    Second, if you still have FTP/Cpanel access, go there and take out your index.php file. A downtime when google crawls is better than indexing the hacked content.

    3. Get a technician from your webhost to help you identify why you got hacked and to help you restore a backup.

    4. Clean up your system (spybot, malwarebytes) and change your passwords.

    5. Restore index.php and Ensure your wp is up to date.

    Hope that helps.
     
  8. SwanWing

    SwanWing Registered Member

    Joined:
    Jun 27, 2009
    Messages:
    55
    Likes Received:
    7
    Location:
    France
    Thanks people... I still have my Cpanel access and will do as you people have suggested. I'll let you know wat happens... Again, thanks a lot!! :)
     
  9. Bossii

    Bossii Newbie

    Joined:
    Sep 12, 2010
    Messages:
    16
    Likes Received:
    0
    albanian hackers are very danger so be carfully from they