Weird message above my header

COBNETCKNN

Regular Member
Joined
Sep 3, 2015
Messages
205
Reaction score
62
Hello there blackhat world... So I got this message above my header and I don't know how it came there... can It be some plugin which I installed or what? and how to remove this because I don't want to advertise for free on my site :D

MEYOada


https://prnt.sc/m369r0

thanks in advance :)
 
That sounds like an untipical way to spam a website - most of the hackers try to hide their links. I think your site is hacked because this will be a really strange plugin if it puts a message with link in the header... i haven't seen such a thing before.

The best thing you can do here is just to export all of your content, delete this site and create a brand new, clean WP. Then install the theme and import the content. And try to secure your site. At first try to not installing any plugins that you don't really need, block the wp-content access, disable xmlrpc functions, block executing scripts in the uploads, secure the wp-admin by changing the directory link and use better passwords.

I cannot tell more without seeing your website.
 
can't believe what I'm reading... I will be really pissed if I would need to backup everything, delete site and make new one... don't know what to say, thank you guys for pointing out the problem, will try first to contact hosting service and then will decide what to do... I just made this site maybe 2 weeks ago...
 
Last edited:
Let me know how it pans out for you. I wish you the best of luck :)

just did ccleaner run to clean all shit from my browsers and it disappeared... I knew something is fishy here because message didn't appear on desktop epic privacy browser neither on mobile only on mozilla and chrome which I use on my desktop... it seems like ccleaner fixed it, we will see... thanks anyways guys... much obliged ;)
 
just did ccleaner run to clean all shit from my browsers and it disappeared... I knew something is fishy here because message didn't appear on desktop epic privacy browser neither on mobile only on mozilla and chrome which I use on my desktop... it seems like ccleaner fixed it, we will see... thanks anyways guys... much obliged ;)
It's possible that the banner appears intermittently based on the IP, I wouldn't rule out a hacked site just yet.

If your hosting has daily backups (most do), you should be able to download the backup directly and compare the file edit dates. Also, are you using any nulled themes/plugins? Are you using any security plugins to change the login URL and stop brute-force attacks?
 
If you’re stuck, look up securi Wordpress plugin / service. It’s paid but they’ll clear it for you and provided ongoing protection and support.
 
It's possible that the banner appears intermittently based on the IP, I wouldn't rule out a hacked site just yet.

If your hosting has daily backups (most do), you should be able to download the backup directly and compare the file edit dates. Also, are you using any nulled themes/plugins? Are you using any security plugins to change the login URL and stop brute-force attacks?

it's true that I'm using free theme named "ribbon lite"... and I don't use any special plugins to change the login url, can you recommend one or they are the ones who are causing the problem? :D
 
If you’re stuck, look up securi Wordpress plugin / service. It’s paid but they’ll clear it for you and provided ongoing protection and support.
The people nowadays just install a plugin when they need to change something on their sites. Searching the interned for a solution where they need to copy and paste a code into their sites is really unpopular although it's the best way. Think of how the site was hacked
At first try to not installing any plugins that you don't really need, block the wp-content access, disable xmlrpc functions, block executing scripts in the uploads, secure the wp-admin by changing the directory link and use better passwords.
I really think that is the best way. I have never installed a security plugin in my 10 years experience and i haven't a hacked site since 10 years...:)
 
try look in your wordpress themes or plugins and look for that massage or dont use nulled wp plugins and themes
 
Back
Top