Help Me! My Site Has Been Hacked

Discussion in 'WordPress' started by bigmodo, Apr 13, 2011.

  1. #1
    people help me, my site at www.modospot.com has been hacked. what should i do? Help me. I can not login to the dashboard with my username and password.
     
    bigmodo, Apr 13, 2011 IP
  2. bigmodo

    bigmodo Well-Known Member

    Messages:
    520
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #2
    sad, no one wants to help me.
     
    bigmodo, Apr 13, 2011 IP
  3. bigmodo

    bigmodo Well-Known Member

    Messages:
    520
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #3
    i was initially worried that i get 404 error when i make a post in one of my sites, now it has been hacked. what kind of world is this!
     
    bigmodo, Apr 13, 2011 IP
  4. bigmodo

    bigmodo Well-Known Member

    Messages:
    520
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #4
    the site is powered by wordpress.
     
    bigmodo, Apr 13, 2011 IP
  5. WzForum

    WzForum Well-Known Member

    Messages:
    320
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    110
    #5
    remove all files / put back your backup / change all passwords / and protect your site...
     
    WzForum, Apr 13, 2011 IP
  6. safiweb

    safiweb Peon

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    This seems to be a defacement...he go hold of your ftp credentials, changed your index.php and using wp-config...changed the admin username/password. I will recommend the following:

    1)Scan your machine for any malware,virus,trojan etc
    2)Change all ftp and cpanel passwords
    3)Using phpmyadmin, you can recover your password by changing it on wp_users table
    4)If you have a backup of your site, delete all files and upload the back up OR else do a clean installation of Wordpress(latest) and import posts/pages
    5)Secure your site:

    - put wp-config above the public root folder
    - Install Bullet Proof Security Plugin
    - Delete install.php in wp-admin folder

    Also this a good read: http://codex.wordpress.org/FAQ_My_site_was_hacked
     
    safiweb, Apr 13, 2011 IP
  7. bigmodo

    bigmodo Well-Known Member

    Messages:
    520
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #7
    how can i put put wp-config above the public root folder???
     
    bigmodo, Apr 13, 2011 IP
  8. safiweb

    safiweb Peon

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    safiweb, Apr 13, 2011 IP
  9. irisw

    irisw Peon

    Messages:
    24
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Sorry to hear what happened to your site. In addition to the good advice posted above, I'd recommend you create a really strong password and use a tool like LastPass or KeePass to keep track of your passwords.
     
    irisw, Apr 13, 2011 IP
  10. pradimani

    pradimani Active Member

    Messages:
    306
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    53
    #10
    ha ha ha , just use forgot password and recover it.
    Its so easy.
     
    pradimani, Apr 14, 2011 IP
  11. safiweb

    safiweb Peon

    Messages:
    34
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    not that easy....most hackers always changes the administrator's email address together with the password. In doing so, use forgot password link...it will yield nothing.
     
    safiweb, Apr 14, 2011 IP
  12. lead2play

    lead2play Well-Known Member

    Messages:
    1,095
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    160
    #12
    if he clicks on forget password also, the password will be mailed to hacker, lol
     
    lead2play, Apr 14, 2011 IP