my website has been hacked

Discussion in 'Security' started by ali-2006, Apr 11, 2009.

  1. #1
    google has reported my website as a attack site

    when i open any page in it it redirect to another page which is full of bad scripts

    tell me what to do ?
     
    ali-2006, Apr 11, 2009 IP
  2. daredashi

    daredashi Well-Known Member

    Messages:
    667
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #2
    check your pc for virus. mostly your infected pc has uploaded malicious code to your site.
    check your .htaccess file. check index.html or index.htm files. you will find some iframe or 301 redirect code in that. just delete it and re upload clean files. go to google webmaster central and register your site to be removed from malicious sites.
     
    daredashi, Apr 11, 2009 IP
  3. ali-2006

    ali-2006 Peon

    Messages:
    621
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #3
    i have the whole website on my pc

    what should i do to make it don't get infected when i upload it

    and not just the index files
    all the htm & html files
     
    ali-2006, Apr 11, 2009 IP
  4. geekos

    geekos Well-Known Member

    Messages:
    3,365
    Likes Received:
    50
    Best Answers:
    0
    Trophy Points:
    140
    #4
    check the page source of your site, most of this redirect attack uses XSS/CSS attack. Just what daredashi said just reupload all your original files. If it does not work, you should report it to your hosting provider.
     
    geekos, Apr 11, 2009 IP
  5. ramarajit

    ramarajit Peon

    Messages:
    54
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I think Somebody hacked ur hosting account and spread the phising content.Please change ur hosting password more strong by using alphanumeric with symbols.Upload a fresh copy of website.before that please take backup of ur site.
     
    ramarajit, Apr 17, 2009 IP
  6. winnerz

    winnerz Well-Known Member

    Messages:
    3,325
    Likes Received:
    284
    Best Answers:
    0
    Trophy Points:
    155
  7. abbaby

    abbaby Banned

    Messages:
    21
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    scan your site with a good antivirus, check source code and try again to submit through google webmaster tool
     
    abbaby, Apr 17, 2009 IP
  8. Erratic-Evolutions

    Erratic-Evolutions Banned

    Messages:
    211
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    scan your computer with a good anti virus, wipe your account on the server, re upload your site and use a better password incase it was a hack.
     
    Erratic-Evolutions, Apr 17, 2009 IP
  9. hch9230

    hch9230 Peon

    Messages:
    50
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Check all your pages, which is embedded in the code, and replace with the text tool to replace all the illegal over the code
     
    hch9230, Apr 17, 2009 IP
  10. karli

    karli Guest

    Messages:
    22
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    take the backup of your file,
    change your hosting password with strong,
    check and clear the unless code for example (iframe, script code after html tag, css code) in all files, must in index,
    scan the all file using good antivirus,
    re upload clean files. go to google webmaster central and register your site to be removed from malicious sites.
     
    karli, Apr 18, 2009 IP
  11. bobs

    bobs Active Member

    Messages:
    83
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    98
    #11

    1) Remove all iframe code from your web pages and scan with quick heal anti virus.

    2) Don't save password in FTP client like Ws_ftp and cute ftp. Hecker cracker password from there.

    3) Change your ftp password to strong password.

    4) make sure to clean all pages properly

    5) You can aslo set permission to index page something like 444. no writing permission.

    6) Go to google webmaster tool and submit reconsideration request.
     
    bobs, Apr 18, 2009 IP
  12. WarezoPedia

    WarezoPedia Peon

    Messages:
    39
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    did you downloaded any file ? i also got attacked by a hacker he gave me a file but the file was bind and my site got attacked but my host provider set it. The hacker just editted my index.php page and changed the cpanel pass.
     
    WarezoPedia, Apr 18, 2009 IP
  13. jackio

    jackio Banned

    Messages:
    490
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #13
    In my opinion the server might be infected with malware. I know that some chinese malware are getting into servers using RFI and then propagating using bad configuration or public flaws on webservers, specially PHP escalation exploit. Try to contact your hosting provider so they can check for malware, checking logs or some kind of script running on cron...
    Also, if you have cPanel, some versions have an internal anti-virus on members account, it would be nice to check it also.
    If you need any more help or information about it, don't hesitate to contact me. Good luck :)
     
    jackio, Apr 18, 2009 IP
  14. Alex Brooks

    Alex Brooks Banned

    Messages:
    523
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #14
    You may have a security flaw, therefore reuploading the same files, without checking out how your website has hacked, its possible to exploit the website again and then you repeat the process. Figure out where the attack came from, bruteforce? virus? exploit? etc.
     
    Alex Brooks, Apr 18, 2009 IP
  15. delima

    delima Peon

    Messages:
    17
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    scary thought, I hope it won't happen to me
     
    delima, Apr 18, 2009 IP
  16. rliddle

    rliddle Peon

    Messages:
    248
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Check hackersmart in my signature. We had the same issues with some of our sites. Now, we not only find your problem, but can install a script to make sure you are notified immediately if it happens again.
     
    rliddle, Apr 20, 2009 IP
  17. H3llas

    H3llas Well-Known Member

    Messages:
    655
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    110
    #17
    H3llas, Apr 23, 2009 IP