Site got Hacked! Need Help finding the cause.

Okay, just because I was feeling that I should mention... just fuck it... I use every nulled theme possible. No one could hack my site yet(PM me if you wn da site link n ur a w00t). I have been doing PHP web development for 8 years now. I know where the bad codes are. I know what they mean ;)

It is not about using the nulled themes. It is about being a technical user, If you do not knwo what you are doing, better respect others and if you do, you have the license ;)

btw

my company's themes are coming soon ( 0 effort themes). better buy them lawl :D


You are pretty much asking for your website to be hacked when you use a nulled theme.

You can find a nulled version of every theme created....do you actually think people are taking the time to null them out of the goodness of there heart? Maybe, but more then likely No they are not.

They insert malicious code and share the themes so peoples sites get infected.

Sure there are some themes that are shared that are clean, but 90% are infected.

You should immediately stop using nulled themes. Themes are not something you can run on Virtual Machine or in a Sandbox like you can with cracked or nulled software on your computer. Once you install a nulled theme, you are installing an edited code with potential malicious script in it.

And not the mention, the "nulling" process erases certain parts of code and changes it, so that alone opens up security vulnerabilities that might not otherwise be in the theme.

If you actually care about your site not being hacked again, the first step would be removing the theme.

However its already probably to late to just "remove" the theme. If it was infected code, the only thing you can do is copy the posts and start fresh with a non nulled theme.
 
Last edited:
Do you have a login attempt limit plugin set up on your WP blog? I had the same thing happen a while back to my theme but not my database. Now that I limit login attempts and lock out failed attempts I swear I am blocking like 800-900 attempts every month.
 
You are pretty much asking for your website to be hacked when you use a nulled theme.

You can find a nulled version of every theme created....do you actually think people are taking the time to null them out of the goodness of there heart? Maybe, but more then likely No they are not.

They insert malicious code and share the themes so peoples sites get infected.

Sure there are some themes that are shared that are clean, but 90% are infected.

You should immediately stop using nulled themes. Themes are not something you can run on Virtual Machine or in a Sandbox like you can with cracked or nulled software on your computer. Once you install a nulled theme, you are installing an edited code with potential malicious script in it.

And not the mention, the "nulling" process erases certain parts of code and changes it, so that alone opens up security vulnerabilities that might not otherwise be in the theme.

If you actually care about your site not being hacked again, the first step would be removing the theme.

However its already probably to late to just "remove" the theme. If it was infected code, the only thing you can do is copy the posts and start fresh with a non nulled theme.
okay, i have deleted everything but i dont have enough money to purchase the theme. So i'm gonna use the nulled one until i get the money. thanks for your opinion :)
There was a great lengthy article somewhere a few weeks ago, regarding the use of "free" premium themes (or nulled themes as we call them). It shows that a HUGE amount of them had malicious coding implemented.. not just redirects and link-jacking stuff but creating new users with admin capabilities without listing it to you, basically giving away a key to your website to the coder.

Can't find the article though.. I'm sure some of you read it, I think I remember Matt Cutts posting it on twitter?

Anyway, what I'm trying to say is: DON'T USE NULLED THEMES (if you don't know & trust who nulled them)
okay boss, will keep that in mind! :)
Dont use admin as username
i know mate, i always use username other than the admin. i also change the prefix of tables. :) thanks for ur opinion thouggh ;)
i highly recommend you to clear all and reinstall wp.because hackers can backdoored any php files with codes

Eg:



i don't think any scanner will detect this small code.so think about it and take some strong action. :)
reinstalled everything mate, lets hope i dont get hacked this time. :)
Okay, just because I was feeling that I should mention... just fuck it... I use every nulled theme possible. No one could hack my site yet(PM me if you wn da site link n ur a w00t). I have been doing PHP web development for 8 years now. I know where the bad codes are. I know what they mean ;)

It is not about using the nulled themes. It is about being a technical user, If you do not knwo what you are doing, better respect others and if you do, you have the license ;)

btw

my company's themes are coming soon ( zero effort themes). better buy them lawl :D
that's what i'm talking about man ;) that's the attitude "fk it" :p i wish i was that knowledgeable in php so i can analyze my nulled themes :)
Do you have a login attempt limit plugin set up on your WP blog? I had the same thing happen a while back to my theme but not my database. Now that I limit login attempts and lock out failed attempts I swear I am blocking like 800-900 attempts every month.
yes, i have limit login attempts and wordfence. So i get notified when a user logs into or tries to log into my site. I get 200-300 attempts per day bro, and that's fking sick and annoying! I see people coming to my login page and guess what, they are referred from facebook. Although I can't find on fb where my site is posted for hack practice sessions, lol! :p
 
^^^^ lawl i am a mod at elegant themes. choose anyone of those u like n let me know(PM me). i can giv it to u for free bro :p
dun be sad :)
 
  • Like
Reactions: V
^^^^ lawl i am a mod at elegant themes. choose anyone of those u like n let me know(PM me). i can giv it to u for free bro :p
dun be sad :)
oh that's cool man! i'll let you know which one I want. :)
Thanks a lot :)
 
I also assume you moved wp-config up 1 level? If you have, sounds like your hosting may have been the problem -- of course nulled themes are never a good idea. If you use one, put it in a folder on your computer and use a good search program to look in the files -- look for url,s base64 etc. I actually had a customer couple weeks ago ended up with a new admin account from an old plugin. Dont forget, like timthumb is in 100s or maybe even thousands of other plugins and themes -- where you dont even know its there.

Good luck! And reinstall a fresh copy of wp -- after you delete all the files! and look in root for any oddball files to be safe as well!
 
Back
Top