Website Hacked! Need Advice

brucewayne90

Regular Member
Joined
Dec 19, 2013
Messages
424
Reaction score
149
Well shit. Today one of site got hacked. I logged in to serpbook and noticed that one my site rankings just went from top 5 to oblivion. I thought i got hit with a penalty so I went ahead and do a manual search for my site on google. To my surprise, i saw a lot of weird chinese/japanese characters on my domain. So i'm pretty sure it's caused by the hack.

Went to hostgator and they told me it was an injection hack and it's a pretty serious issue. They said someone else is using my site for their own purposes and have no reason to stop or go away. Bollocks!

So i was told in order to clean and get my rankings back i need to subscribed to sitelock for a period of 12 months at 80 dollars per month and they will do the cleaning for free. Another alternative is sucuri.net where i only need to pay 199 annually.

I'm not sure which should i choose though. Any thoughts fellow bhw members?
 
1. check for the date when the site was hacked and compromised. You can use archive for that. or you can go into your cpanel and check the files modification date. If a site is hacked usually all the PHP or JQERY FILES modification date will be same.
2. Once you determine the date your site got hacked, do a complete backup to a couple of days earlirr from CPANEL using R1SoftBackup 3. Change passwords, username of site
 
Thanks for advice. Appreciate it. However, since im not really good with files or codes (afraid i will mess it up), i have decided to go with sucuri for malware clean up. Hopefully I will get my rankings back after this.
 
That really sucks dude and I feel for you. You might also want to change any email passwords you have been using with that site if applicable. Hacks suck and its an up hill battle.
A few things I do on all my wordpress sites (not sure if yours is)

Add wordfence plugin (free)
Add site to cloudflare (free) and add some settings to create a challenge for like 3/4 of the coutries in the world. Most of my sites serve Canadians and Americans so no need to let people from Asia on it.
Add IP Geoblock plugin (block 3/4 world)
Create backups like seoz87 mentioned to never let this happen again.

If you really care about that site, you might even want to change hosts. The IP could be on a blacklist, that might be over kill but still.
 
and finally, be careful of who you give the address to on this site. can't even say how many times I gave a site out on here and within 10 mins I had people trying to login to the backend from some Asian country.

oh and also never keep admin as username. I actually auto ban any IP that even tries those names of ones like it.
 
Just to be clear, i was offering my help, was not selling anything. Have helped a lot of people in the past with hacked sites. So cheers to the mod who deleted the post.
 
Well shit. Today one of site got hacked. I logged in to serpbook and noticed that one my site rankings just went from top 5 to oblivion. I thought i got hit with a penalty so I went ahead and do a manual search for my site on google. To my surprise, i saw a lot of weird chinese/japanese characters on my domain. So i'm pretty sure it's caused by the hack.

Went to hostgator and they told me it was an injection hack and it's a pretty serious issue. They said someone else is using my site for their own purposes and have no reason to stop or go away. Bollocks!

So i was told in order to clean and get my rankings back i need to subscribed to sitelock for a period of 12 months at 80 dollars per month and they will do the cleaning for free. Another alternative is sucuri.net where i only need to pay 199 annually.

I'm not sure which should i choose though. Any thoughts fellow bhw members?
Those are just junk upsells imo. There's no guarantee you will get rankings back from giving them your money. If anything they go through some steps on submitting an appeal to google which you can find with 1 minute on google search.
I had same thing happen when i used Hostgator. I triggered their security sys because I hosted some files they deemed as bad and they assumed I was hacked. Immediately I was getting tons of offers to buy some premium security package. So many scare tactics. I even got emails from random security companies wanting to extract my money. Pissed me off enough to change hosts. HG sucks as a host anyway. I switched to OVH half the price, double the speed.
Read others had same happen, typically from nulled WP themes.
What do you do next... change all passwords (ftp, cpanel, vps, all mysql users). If you're using nulled themes then delete them, probably best to totally wipe the server and manually import your wp-settings & wp-posts as not to accidentally import the file that had a backdoor in it. Next install wordfence plugin & read a blog post on how to properly configure it for maximum security. Be sure WP is always up to date.
If you're not on WP then think hard on how you got that back door. I've seen people null simple scripts like social content locker and put encrypted backdoors in there. There are free tools online where you can upload your site or a file and it will scan for these backdoor codes and identify them.
 
Thanks for advice. Appreciate it. However, since im not really good with files or codes (afraid i will mess it up), i have decided to go with sucuri for malware clean up. Hopefully I will get my rankings back after this.

good luck. But you could have saved your money and do it yourself. There was no coding needed
All you need to do was Just check CPANEL Public html directory and files in wp-admin directory and if modification dates of all files are same then you could have simply ask the host to do a full backup of your site to a previous date.

Never fear to do anything as you will learn a lot and since you already lost the ranking so it was a good chance :)
 
Last year I logged into one of my sites on Bluehost which I don't use anymore to discover all my storage had been used up.
I asked why so much and they said it had malware and they was going to disable my whole control panel until I fixed it, I asked them how they new there was malware/which files were infected etc and they would not tell me and advised I used sitelock. I tried the demo, it didn't fix the malware and messed up the ssl on the rest of my domains on Bluehost.

I then did what was advised above, checked which of my files had been updated and saw inside loads of random code, I just restored the folders with files which were infected with malware, some folders had 100s of pages generated from the malware. After restoring I asked the host to check again and they said everything was fine.

I updated my server/websites security and its been ok for at least 6 months. It took me a few hours to through the files and restore.
 
Those are just junk upsells imo. There's no guarantee you will get rankings back from giving them your money. If anything they go through some steps on submitting an appeal to google which you can find with 1 minute on google search.

Exactly, a big waste of money, because all they will do is tell you the exact same thing that you would have found out in a few simple google searches, and there is no way anyone can guarantee the return of the rankings.
At best all they can do is submit a reconsideration request after cleaning your website.

If you ask me you are much better off to clean the hacks manually, that way you will learn a thing or two, and gather expirience if it ever happens again.
You can start by erasing all suspicious files and scripts/code from the php files, check the WP version if its up to date - check the plugins on the website and see when they are last updated ( most hacks come from old plugins that were re-sold ), also if you are using a cracked theme than replace it immediately with the paid version. You can still install sucuri or wordfence plugins for free and run a scan to see if any of the wordpress files have been modified or any backdoors uploaded to your site.
You can also use the Fetch as Google tool to see if there is any leftover content that is lurking on your website.
At the end make a backup of your website and see how it goes by keeping an eye on your files in the next few days, so if the hack repeats itself than do a restore and go through the steps again.

After your site is clean go to google and submit a reconsideration request explaining that your website was hacked ( you could also have a manual report on google webmaster you should check there as well ), and explain that you have resolved the issue and cleaned your website as well as taken further steps to make sure it wont happen again. Than just wait some time until they review the report and hopefully restore your rankings.
 
@virtualpurity Great advice and I agree with you about manually going in and fixing stuff.

Most of the time you get lucky and have to clean out some eval base64 encoded shizzle and check every file for changes.

You could always start with a grep command to find out on which exact *.php files the word eval is added.

Anyone interested in this can read more info on this page: https://codex.wordpress.org/User:Hakre/Grep_And_Friends#Hacked_Blog
 
Hey everyone. Thank you all for the advice and tips on how to deal with hacked website. Really appreciate it. However I went ahead and subscribed to sucuri basic protection plan and requested for the malware clean up.

They managed to clean up the site in quite a short period of time. I panicked as this was the first time my website got hacked. I usually try to secure all my sites following tips from wordpress blog such as wpbeginners etc. But this was unexpected.

Apparently there was a folder of one of my deleted site in the public html folder which I neglected and forgot to delete. Am using shared hosting btw. Was told that that folder of my deleted site could be the cause for the malware injection. Lesson learned!

Lucky for me this site of mine is a small affiliate site earning a couple of hundreds per month, so at least it's not so heartbreaking.

On a brighter note, I've managed to get my rankings back. Although one of my main keyword is on page 2 :(, but am happy so far.

Thank you all for taking the time to reply and give great advice on wordpress security. I've learned a lot and time for me to take wordpress security more serious!
 
@brucewayne90 Glad to read that your site is secure again.

Securi and it’s people are great and I would like to say that you made the right decision to have them dealing with the hack.

The same goes for Wordfence, their team is also very good, fast, and friendly when it comes to managing a hacked site in order to get it cleaned and up and running again.

Best of luck and I do hope you will get all your keywords to rank at the same position again, or even better!
 
@NotAllenTuring Thanks man. Yup they're really helpful though their response time can be slow. Was having second thoughts about using their service as they were bought by godaddy but I don't care at that moment.

Yeah heard good things about wordfence too. Will be checking them out. I've been using ithemes security free plugin but now I think I need to have at least a premium security service for all my sites just to have a peace of mind. Maybe switch over to managed hosting too.
 
simple things u have to do.... restore website to a date it wasn't hacked and install Cleantalk anti-spam.
 
Sorry for the reply not exactl being on-topic with your concern, but I believe I have something going on to my website. I believe it's being spammed. I get comments on articles from different users with a loan service and their website. And I get a lot per day...I banned some IPs, but it seems those guys get new ones and I get bombarded with new comments spamming their shitty website. What should I do? :))
 
@Raneni Is this a WP site you run? If so, what settings do you have under Settings -> Discussions?
 
simple things u have to do.... restore website to a date it wasn't hacked and install Cleantalk anti-spam.

make sure u do this. If u can't I will do it for free 100%. I have been hacked a lot... To the extent one of them somehow managed to flag my IP as a spam IP and sites started seeing me as suspicious. Do what I told u bro... Clrantalk will give u some free services for some months b4 they start charging u, and they don't charge much.
 
@Raneni If it's spam comments, just use akismet plugin. If you're using wordpress though.That should take care of it.
 
Back
Top