1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Website hacked !!! A lesson to Newbies!!!

Discussion in 'BlackHat Lounge' started by bullseye123, May 11, 2011.

  1. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    Ok Here is my little story of almost shooting someone or even something worst.

    I Build a site, get up to PR2 spend Months and Months on Unique content,
    Just upgraded to the latest version of WP and not even a week later and my website has been hacked, with some footer script calling all kinds of shit malware.

    How did I pick this Up ??? Well good old G**gle told me, Got an email telling me there is harmful script running on my website, and the great thing is webmaster tools showed me the exact script.

    The Script is this shit ///***img heigth="1" width="1" border="0" src="http://adam-love.n et/t.php?id=14994951" ****///

    So I could not find the source file or place for where this is coming from, I asked my Host to please revert my site back to a previous backup that they make.

    They Told me that there is 2 options a weekly backup, and a Monthly backup.

    I oped for the weekly one as this must have just happened, and they said ok will do so.

    Got a message back from them and they said the backup was restored.

    And you know what, it is a F**ing backup of late 2009, I said ok please do the monthly one then. and that is a backup of the start of 2009.

    asked them to please just put everything back as it was, so I can try and remove the injected shit my self, and what do you know, they did not backup that before they revert back to the older backup's.

    Im Screwed all the hard work for more than a year fucked gone on a flight to Japan.

    More than 200 Unique self written content Heavily customized theme everything Gone, $5 a day with adsense GONE!!!!

    Who can I blame ????????? Only Me

    Why ??????? I didn't think it was necessary to make a fucking backup.


    SO TO ALL THE NOOBS AND EVERYONE RUNNING A WEBSITE. MAKE YOUR OWN WEEKLY BACKUP'S. I LEARNED THIS THE HARD WAY, AND DON'T THINK THAT YOU CAN'T BE HACKED. I CHANGED EVERYTHING ON THE SITE SO ACCORDING TO ME THERE WAS NO WAY IN.

    I WAS WRONG YET AGAIN.


    BACKUP BACKUP AND BACKUP.

    There is always someone that it trying to break your site so be careful.
     
    • Thanks Thanks x 8
    Last edited: May 11, 2011
  2. redstone.1337

    redstone.1337 BANNED BANNED Jr. VIP Premium Member

    Joined:
    Dec 30, 2009
    Messages:
    1,259
    Likes Received:
    999
    Recover all your content as soon as possible from G00gle's cache and put it back up on your site. Get all the indexed pages of your website with site: operator. Big G is always in your service for free backup! :D At least you can get back your 200 Unique Articles if not the heavily customized theme. :)
     
    • Thanks Thanks x 3
  3. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    Thanks allllooot !!! How can I recover this via Google's Cache ?

    This will help a lot.

     
  4. dan777

    dan777 Junior Member

    Joined:
    Mar 3, 2011
    Messages:
    106
    Likes Received:
    15
    Location:
    Europe
    OMG!!! :eek:
    Bullseye123, I'm really sorry for you.
    I should said thank you for this thread, but hope you'll understand.
    May I asked which Host is so sophisticated with backup technique?
     
  5. bk071

    bk071 Jr. Executive VIP Jr. VIP Premium Member

    Joined:
    Nov 24, 2010
    Messages:
    3,105
    Likes Received:
    7,917
    Occupation:
    I don't have a job
    Location:
    .............
    Here:

    1. Search for site:yoursite.com in Google.
    2. However many result appear, click on 'cached' for all of them one by one.
    3. Google will show a cache of your site from which you can copy-paste the articles and other contents of your site to some MS word file... Easy way to retrieve your content :)

    Hope this helped.
     
    • Thanks Thanks x 2
  6. redstone.1337

    redstone.1337 BANNED BANNED Jr. VIP Premium Member

    Joined:
    Dec 30, 2009
    Messages:
    1,259
    Likes Received:
    999
    Search this in g00gle:

    HTML:
    site:yourdomainhere.com
    You'll get all your indexed pages in the results. Click on "Cached" link beside the url of the search results. Copy down your articles back.
     
    • Thanks Thanks x 1
  7. paw70

    paw70 Newbie

    Joined:
    Aug 16, 2009
    Messages:
    4
    Likes Received:
    3
    Occupation:
    what is job?
    Location:
    East Coast USA
    Hostgator is better at getting recent backups... noway would I have had some backup from a 2 year backup... the most i lost was a few weeks. Who is your web host? Also do a xml backup of all your posts... you can do that in the admin area.
     
    • Thanks Thanks x 1
  8. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    It is amplehosting in South Africa, Im sure they host from someone in the US.

    But I can promise you that Im going to move, I can't work like this, I have 50 other Client's of mine also on the same Hosting and if something like this had happend to one of my client's, I can just imagine.

    Im No looking into this google cache that was mentioned.

     
  9. redstone.1337

    redstone.1337 BANNED BANNED Jr. VIP Premium Member

    Joined:
    Dec 30, 2009
    Messages:
    1,259
    Likes Received:
    999
    If your time is precious then you can use Best SEO Suite which has Google Cache Ripper to rip your site back.

    Link - http://www.blackhatworld.com/blackhat-seo/buy-sell-trade/293404-best-search-engine-optimization-suite-scrapes-spins-translates-checks-links-more-all-one-tool.html
     
  10. Rendan

    Rendan Newbie

    Joined:
    Apr 13, 2010
    Messages:
    26
    Likes Received:
    12
    My wordpress website was hacked yesterday too. It had this code in index.php file
    ///***img heigth="1" width="1" border="0" src="ht tp://imgddd.ne t/t.php?id=16855152"***///

    I removed it and sent a review request to google. It doesn't give "this site may harm your computer" error now.

    I use justhost. The same thing happened to my joomla website a week ago.
     
  11. goldstrike4u

    goldstrike4u Junior Member

    Joined:
    Dec 22, 2007
    Messages:
    189
    Likes Received:
    124
    If you are too late and Google has already updated its cache then you should still be able to get your content from archive.org which will probably have older versions of your site available.
     
  12. barabaAA

    barabaAA Newbie

    Joined:
    May 7, 2011
    Messages:
    9
    Likes Received:
    0
    nice.i like this.
     
  13. TNphoneman

    TNphoneman Senior Member

    Joined:
    Dec 15, 2010
    Messages:
    1,177
    Likes Received:
    695
    I think the hosting service owes you some compensation.
     
  14. bigdaddy

    bigdaddy Newbie

    Joined:
    Nov 28, 2007
    Messages:
    29
    Likes Received:
    623
    Occupation:
    Copywriter, speaker, Daddy...and professional bum.
    Location:
    East Coast of the USA.
    OUCH!!!
    That's a painful lesson indeed.

    And that was VERY cool of you to share your experience
    as a warning to anybody & everybody to back their shit up
    on the regular.

    Me personally, I use Backup Buddy WP Plugin, which I'm sure should be easily
    found here on this forum somewhere!

    Big ups to everybody who gave you some encouragement or advice
    on how to get your precious content back.

    Please post here w/ the end result - did you get your content back ok?
    What exactly did you do & how did it work out for you?

    Thanks & good luck!

    --BD
     
  15. Sundace60

    Sundace60 Registered Member

    Joined:
    Jun 22, 2009
    Messages:
    53
    Likes Received:
    18
    If your using Wordpress, there is a plugin that I recommend. It will give you a database backup via email every day.

    Code:
    http://wordpress.org/extend/plugins/wp-db-backup/
     
    • Thanks Thanks x 1
  16. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    I will keep up to date as to what is happening, Still a wild discussion going on between me and the host, This is theirs last response :

    [FONT=&quot]"We will do everything we can to check for that newer content, please hold while I forward this to our 3rd level techs.[/FONT]"


    Im also researching the google cache retrieval, But Downloading 200 posts like that is a hell of a job on its own, I found a software called Warrick, that might be able to do just that and download everything from google cache so Im busy trying to figure out how it works. Will let all of you know what the outcome is.

    Thanks everyone for the support and lots of help so far. Thank YOU BHW.

     
  17. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    If I do the site:yourdomain.com search, I can pretty much see all my links, only problem is there is not a single one showing the Cache link next to it ?

    I can't find my cache !!! whhhhhhhhh Going out of my mind!!!
     
  18. hellokitty

    hellokitty Registered Member

    Joined:
    Aug 3, 2008
    Messages:
    67
    Likes Received:
    23
    see if there is anything at
    Code:
    http://web.archive.org/web/
     
  19. nemsis

    nemsis Jr. VIP Jr. VIP Premium Member

    Joined:
    Sep 27, 2009
    Messages:
    173
    Likes Received:
    283
    This is a serious issue I feel sorry for you man..

    Some suggestions

    1. Shut down immediatly your site so google cannot refresh its cache

    2. Install this chrome plugin so you can browse the google cache easily
    Code:
    https://chrome.google.com/webstore/detail/joiigeomfncembaeikpogcipaoddddhc
    
    3. As a fellow blackhatter said, check thewaybackmachine
     
  20. nicofan

    nicofan Junior Member

    Joined:
    Jul 25, 2010
    Messages:
    135
    Likes Received:
    77
    Occupation:
    unemployed, unemployed, unemployed, unemployed, un
    Location:
    LOLercoaster
    so, I have learned from this that it is absolutely necessary to backup your websites as frequently as possible. What is still not clear to me is why you got hacked in the first place, since you wrote your WP is up to date. How can you prevent somebody from hacking your website?

    feel sorry for you, hope your can get your articles back from g00gle cache.
     
    Last edited: May 11, 2011