Website hacked !!! A lesson to Newbies!!!

Status
Not open for further replies.
i feel sorry for your loss.
did hacker send you any message ? if you have any contact, you can kindly ask him/her for your data.

I run my wordpress websites on a local Apache server on wmware and publish everything same as i do for my live websites. Try to learn it, its really easy.

What is still not clear to me is why you got hacked in the first place, since you wrote your WP is up to date. How can I prevent somebody from hacking my website?
dont know much, but be careful while using free wp theme for your website.
 
Last edited:
Don't waste your time and do that quickly as you can. Google these days has became too fast to remove the content which is not accessible.
Believe me I have a PR-5 site which bought down by my host provider a month ago saying that I was using too much cpu resources on a shared hosting and guess what after a single day my site was not on google. I had over 2000 posts at that time and not even a single one was on Google. Its amazing you know Google slapped the whole site out of its index.
Although when my site came up after resolving with host provider I got everything back on track but that's not the case with you i guess ;)
 
Hey bulleye, it seems either you free wordpress theme or some nulled version is causing this issue.

You can clean your files with this javascript but until and unless u delete those infected files you will not get rid of this issue.

If your files and database is still hosted than take a backup of all of ur files and PM me ur skype id, i will tell u how to track and delete it :)
 
What theme and which plugins?

I bet it's a justhost reseller.
 
Install security plugins like firewall and security scanner.
 
My wordpress website was hacked yesterday too. It had this code in index.php file
///***img heigth="1" width="1" border="0" src="ht tp://imgddd.ne t/t.php?id=16855152"***///

I removed it and sent a review request to google. It doesn't give "this site may harm your computer" error now.

I use justhost. The same thing happened to my joomla website a week ago.

hi rendan, may i know which index.php that your are referring to....home folder has index and many others too.....which exactly?

And really thanks to you Bulleye for warning us....really feel sry for you....a lesson learned.
 
If I do the site:yourdomain.com search, I can pretty much see all my links, only problem is there is not a single one showing the Cache link next to it ?

I can't find my cache !!! whhhhhhhhh Going out of my mind!!!

did you try yahoo, bing ....and others?
 
Last edited:
hi rendan, may i know which index.php that your are referring to....home folder has index and many others too.....which exactly?

And really thanks to you Bulleye for warning us....really feel sry for you....a lesson learned.

It was main folder index.php . After removing that line of code, it started working properly again.
 
Thanks for warning us all about this. I cannot imagine what will happen to my sanity if something like this happens to my sites.
 
bullseye123,
did you use any nulled/cracked/free plugin/theme ?

it happened to me before. my accounts (on 2 hosting accounts at the same time) got hacked with malicious script that did mail spamming:
There are 52722 records in mail log and 4624 mail in mail queue
We had to suspend your Account
Please contact us as soon as possible
so one of the hosting company just suspended my account.


and this the massage from another hosting account:
Hello,

An account under your control was recently found to be sending out emails at a rate faster than 500 messages/hour, which resulted in the investigation outlined below. As outlined in both our terms of service (Web Hosting, Reseller Hosting, and Dedicated Website Hosting w/ cPanel - HostGator) and mail policies (HostGator Mail Policy), the maximum number of messages an account is permitted to send is 500 per hour.

We will review the content of the messages being sent from your account; if they appear to be spam or otherwise violate additional HostGator policies, your account may not be eligible for reactivation. If your actions were unintentional, the content of your messages are found not to be spam, and this incident was simply an oversight of our rules we will be more than happy to work with you in order to correct this matter. Continuing this type of mail volume on shared servers, or spamming, will not be an option.

The results of our investigation have been outlined below.

to cut the story short hostgator has done a good job finding and deleting the script without suspended my account...
 
Last edited:
After a lot of consultations with the host, They have managed to get my website Back to the state where it was hacked. Now I Have everything back, and Busy trying to remove the Malicious script, I can't find it in my index.php file like someone mentioned.
 
This is in no way your fault, this is 100% the hosts fault for their failure to specify when these backups were from

They also failed to make a backup before overwriting all of your data

You dont need to blame yourself, you need to be blaming the web hosting provider


Also I just read your above post

Check your header.php and your footer.php file I bet its in there
 
its a desirer. i am really sorry for the matter. i think recovering your unique contents from Google is a good way but its very hard to do it for an old site like yours.
but i think you should try your best.
 
Jennifer Martin

Thank You very much.

Jennifer helped me on Skype, and we were able to Identify a very serious Hacking.

We discovered all kind of files that was definitely created to do some serious damage. Im sure Jennifer will explain more about this here later.

Im not certain that all the problems are solved, but Im getting there.

To Jennifer Martin Thanks + Rep Given.

Hey bulleye, it seems either you free wordpress theme or some nulled version is causing this issue.

You can clean your files with this javascript but until and unless u delete those infected files you will not get rid of this issue.

If your files and database is still hosted than take a backup of all of ur files and PM me ur skype id, i will tell u how to track and delete it :)
 
my server hosts rusn some anti malware scanner on the server and detects bad scripts.. i had a similar thing happen but nothing came of it. i got saved.
 
The only mistake you did is using Wordpress.
 
So whats the best plugin for backup which can be easily implemented afterwards easily?
Thanks.
 
If your using Wordpress, there is a plugin that I recommend. It will give you a database backup via email every day.

Code:
http://wordpress.org/extend/plugins/wp-db-backup/


Vickygarg, try the plugin that Sundance60 has mentioned above.


So whats the best plugin for backup which can be easily implemented afterwards easily?
Thanks.
 
Status
Not open for further replies.
Back
Top