Website Hacked?

Thanks, to both of you. I can now get started on rooting this crap out of my site. Lesson learned, never hesitate to update wordpress/themes/plugins/etc. Is there anything else I can do to prevent this stuff from happening in the future?

EDIT: I would, but I share the hosting with someone else and don't feel comfortable exposing their sites too without their permission. I think I know what to look for now so I'll give it a whirl and see what's what.

Don't be afraid to call your Web Host for help too. Sometimes they will help you (not always) and they typically have more server access so they may be able to use shell to clean up the site fast.

As for preventing this from happening again, just make sure to keep everything up to date. Or just don't use Wordpress :)

As for myself, I have a few things I like to do.
1. Change the default Database table prefix away from 'wp_'.
2. Change the default 'admin' username to something else.
3. Use strong passwords for everything.
4. Add extra password protection to your wp-admin folder (use .htaccess so you're basically logging in twice, and it's password protecting the entire folder from being tinkered with).
5. Rename your login page for WP.
6. Move your installation into a subdirectory - I had explained this method on another post recently too. Here's what it is. You make a subdirectory named whatever you wanted (I usually use a folder named "site") and throw all your WP files/folders in it except .htaccess and index.php. Then edit your index.php to reference to that new folder. Then go into your database and in your wp_options you have to make a change to the URL so your main URL stays as "domain.com", but the coding of your site references to the subdirectory.

With that method, you can help throw off malicious bots and people from trying to compromise your site. It's going to confuse them because they're going to expect to go to domain.com/wp-content or doman.com/wp-includes, but those folders don't exist because they're actually in domain.com/site/wp-content, etc.

Anyways, good luck :)


Yeah, Right now I'm wishing I had a backup of the sites. So that's another thing that's happening from now on.

Good idea ;)
 
It could be but I've never heard of that happening before though. I checked out his website too and did infact find a phishing page impersonating a login for some UK company called orange.co.uk.

There you go, that would be the payload. If you're interested in knowing more about how the bastids like to exploit WP sites, I recommend you take a look at Metasploit. It's fantastic for learning more about the common exploits and payloads, not only for WP, but for a whole host of other platforms as well.

Don't be afraid to call your Web Host for help too. Sometimes they will help you (not always) and they typically have more server access so they may be able to use shell to clean up the site fast.

As for preventing this from happening again, just make sure to keep everything up to date. Or just don't use Wordpress :)

As for myself, I have a few things I like to do.
1. Change the default Database table prefix away from 'wp_'.
2. Change the default 'admin' username to something else.
3. Use strong passwords for everything.
4. Add extra password protection to your wp-admin folder (use .htaccess so you're basically logging in twice, and it's password protecting the entire folder from being tinkered with).
5. Rename your login page for WP.
6. Move your installation into a subdirectory - I had explained this method on another post recently too. Here's what it is. You make a subdirectory named whatever you wanted (I usually use a folder named "site") and throw all your WP files/folders in it except .htaccess and index.php. Then edit your index.php to reference to that new folder. Then go into your database and in your wp_options you have to make a change to the URL so your main URL stays as "domain.com", but the coding of your site references to the subdirectory.

With that method, you can help throw off malicious bots and people from trying to compromise your site. It's going to confuse them because they're going to expect to go to domain.com/wp-content or doman.com/wp-includes, but those folders don't exist because they're actually in domain.com/site/wp-content, etc.

Anyways, good luck :)




Good idea ;)

Follow this solid advice.
 
First is hosting:

You must choose a secure hosting of DDoS attacks.

Both are platforms:

Most platforms like wordpress is very easy to hack by wordpress expert.


Third plugin:

Plugins be slit driveway very easy to hack

Fourth is a fraud page:

It involves 14 easy ways to hack

Fifth is:

Theme, a theme that you download free, at risk to be hacked easily


Still other banayk, but that's all I know.

If you still have of action to your email account, you can rebuild your website with a new username and password
 
Your site is likely to have been compromised by a backdoor exploit such as a web shell. These can trigger phishing warnings in GTW. Did you use a nulled theme or a legitimate one? If you don't feel uncomfortable about sharing your site's URL, you can PM me and I'll take a look.
hello sir do you know how to use shell backdoor?
 
Back
Top