My wordpress sites got hacked - what next?

Kingjay

Junior Member
Joined
Sep 2, 2012
Messages
104
Reaction score
17
Hello guys I sort of freaked out this morning when I saw my websites had been hacked! I luckily only had to change the index.php file to "restore" the home page. Do anyone have an idea how it is possible for hackers to do that, from what I understand that had to be able to log into my cpanel or ftp account or how else?

How can I protect my websites against further / future attacks.

I know there is a lot of wordpress documentation on this that I still have to read but thought I would ask the real experts at BHW :-)
 
Have you got a plugin called WordPress better security? If not, get it now. It's free and easy to set up and it works well.

James :)
 
Remove any plugins you aren't using and make sure keep plugins you are using to a minimum (and Google for any reported issues on them).
 
Probably, hackers have created backdoor on your site. You have to check full wordpress files and change hosting and ftp passwords. First install, worddefence security plugin and sucuri plugin both are free, and scan for any vulnerability, infection or backdoor present. if you found anything, you have to clean everything.
 
1.Dont use cracked plugins/themes onwords.
2. Update wordpress when it is available.

This will keep 99% hackers away from your blog
 
Thanks for the replies guys, will jump right to it. I actually use only free plugins and one paid theme at the moment.

Thanks again for all your help...
 
I am a wordpress specialist and a hacker.. Contact me if you are serious..
 
I am a wordpress specialist and a hacker.. Contact me if you are serious..

me too. maybe i can help you just contact me.

for simple solution you should install plugins :

Wordpress Firewall 2
AntiVirus
Mute Screamer

it's really powerful even you cannot change setting your theme when wordpress firewall and mute screamer active.
 
I use wpbetter security and I got done once.

Moral of the story dont ever leave your login as Admin and pick a good and long cryptic password.
 
Doesn't matter. They always find the correct username somehow. Better use captcha in your login. You can also use Login Lockdown..
I use wpbetter security and I got done once.

Moral of the story dont ever leave your login as Admin and pick a good and long cryptic password.
 
Back
Top