WordPress Website Hacked

If your hosting company doesn't have your site backed up search your pages on Google and get your content back from the cached pages.
 
it happens on me too... i hired a freelancer to fixed the fcking error.. and all post came back... but i can't remove the casino thing on the head part on my site...
 
it happens on me too... i hired a freelancer to fixed the fcking error.. and all post came back... but i can't remove the casino thing on the head part on my site...


check the header.php u must have something there
 
There is better wordpress security plugin - free and does good job at securing sites from script kiddies. Also has backup. Set up is rather simple too.
 
I have installed plugins now. And also change the admin name.
 
Do you have the latest wordpress version? Perhaps the hackers found a vulnerability in the script.
 
Yes I have latest WordPress virsion
 
Try this:
Code:
http://www.blackhatworld.com/blackhat-seo/blogging/495526-guide-make-your-wordpress-blog-hackproof-complete-guide.html#post4821645
 
Need to install all?

For security plugin, you should go with these, man ... I recommend :
http://wordpress.org/extend/plugins/antivirus/
http://wordpress.org/extend/plugins/wordpress-firewall-2/
http://wordpress.org/extend/plugins/tac/
http://wordpress.org/extend/plugins/mute-screamer/
also, http://wordpress.org/extend/plugins/bulletproof-security/
 
@gogol: Really Nice information. Thumbs up

Try this:
Code:
http://www.blackhatworld.com/blackhat-seo/blogging/495526-guide-make-your-wordpress-blog-hackproof-complete-guide.html#post4821645
 
Some basic security ideas
Prevent wp-content, wp-content/plugins, wp-content/themes, wp-content/uploads from listing
Remove wp-version
Remove core update information for non-admins
Remove plugin-update information for non-admins
Remove theme-update information for non-admins
Database error reporting turned off
PHP error reporting turned off
Remove version information for scripts/stylesheets
Admin user name is not admin


sucuri is pretty good for a security plugin too, stop using nulled plugins and themes is the best idea! Some other ideas are
 
Last edited:
I do not understand why hacker hacked my website? And its not old website. it still new.
 


Nice one thanks.

But do you not keep locking yourself out with some of those security plugins?

Do you actually have all of those recommended security plugins currently installed on your site?
 
I do not understand how to remove them

Some basic security ideas
Prevent wp-content, wp-content/plugins, wp-content/themes, wp-content/uploads from listing
Remove wp-version
Remove core update information for non-admins
Remove plugin-update information for non-admins
Remove theme-update information for non-admins
Database error reporting turned off
PHP error reporting turned off
Remove version information for scripts/stylesheets
Admin user name is not admin


sucuri is pretty good for a security plugin too, stop using nulled plugins and themes is the best idea! Some other ideas are
 
my site was also hacked . did u use low sensitive username password ? username - admin / pass - admin ?
 
I do not understand why hacker hacked my website? And its not old website. it still new.

This is scary. I am newbie and thought to create a wordpress blog. So I have to read a lot for assistance about wordpress. Take heart, you'll get over that.
 
thats what you get with nulled themes :) . Also scan your site for mallware
sitecheck.sucuri (dott) net
 
Back
Top