my wordpress site got hacked

ceniicr7

Junior Member
Joined
May 18, 2015
Messages
146
Reaction score
13
hello i have an good dedicated server and my website has been hacked they edit theme and upload so many files and are doing spam how can i check what are they doing spam and how they uploaded backdoor and shells?
 
Do you have an FTP connection available? If so, use FileZilla and look at all the files that have been updated recently that you haven't touched, and delete them.

Then, change your listen port. Normally, your SSH is on port 22, I believe. There is more, such as checking your PHP & Apache settings. But this should get you started.
 
Do you have an FTP connection available? If so, use FileZilla and look at all the files that have been updated recently that you haven't touched, and delete them.

Then, change your listen port. Normally, your SSH is on port 22, I believe. There is more, such as checking your PHP & Apache settings. But this should get you started.
yes currently i have access and to root with whm but i want to check ip that have been log in on wordpress and what are they doing spam and how they hacked me
 
yes currently i have access and to root with whm but i want to check ip that have been log in on wordpress and what are they doing spam and how they hacked me

You can check that in the backend of WHM or the back end of wordpress for IPs that have accessed your server/site. Follow the link posted above for further troubleshooting.
 
This can happen if you have used a nulled wordpress theme from BHW, for example.
 
Never have a Wp site hacked. Use legit themes and plugins and you'll be fine.
 
theme was from wordpress themes but plugins from gfxfree
 
Scrape the lot start agin ...

this time set hard to guess passwords......

use the Microsoft password rule.
 
I had a similar experience some time back and I was able to resolve many of the issues using the plugin below. You can set it to scan your whole system and even compare to original wordpress files. As many mentioned on this thread, you should check for any recent changes via FTP as well, however, this plugin will find many of those and let you remove/resolve.

https://wordpress.org/plugins/wordfence/
 
So, it isn't advisable to use those Wordpress themes being given away for free here on BHW?

In a word; NO

There are some devious scum on all forums, who are happy to appear to be the good guys by sharing nulled themes / plugins etc but have actually supplied you with a free of charge Trojan or backdoor exploit.

These people are the lowest of the low, so it is best to buy legit themes and plug ins.
 
How do we know if a nulled theme can be hacked?

A virus total and/or other users posting about it. It's easy to find an exploit or a file that shouldn't be there or even a line of code that shouldn't be there.
 
Back
Top