site hacked

Discussion in 'WordPress' started by aspire, Aug 24, 2012.

  1. #1
    A site of mine has been hacked. Site is wordpress based.

    homeimprovementandhomecare.com

    I unable to find a solution to restore it

    (I have replaced the index.php with a fresh copy but that hasn't helped)

    I think that there's file that has been manipulated but unable to determine as to which

    Please help with this.
     
    aspire, Aug 24, 2012 IP
  2. hackrepair

    hackrepair Member

    Messages:
    47
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    40
    #2
    Your best course of action is first contact your host and get them to recover your website from backup. Once you have a clean copy in place then run (don't walk) in making sure all your stuff is updated, all user/passwords changed, etc. Most hacked sites I work on are due to outdated plugins or theme.

    Then I recommend you make sure all is upgraded. Sadly, nowadays it's rare for hackers to not leave back door scripts in place (allowing hacker to hack your site again in future).

    You'll need to review every file on your website respectively to ensure none are out of place or were installed by hacker.
     
    hackrepair, Aug 24, 2012 IP
  3. Philvault

    Philvault Active Member

    Messages:
    1,284
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    80
    #3
    I've always recommended to keep your own backup and not rely entirely on your host. I'm not aware of any host who does everyday backup. Majority of my sites are WP and xCloner has been very efficient to backup everything from the databases to individual files.
     
    Philvault, Aug 24, 2012 IP
  4. aspire

    aspire Well-Known Member

    Messages:
    4,003
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    175
    #4
    The host is upwebhosting.com and they had responded they can't do anything. It is not part of their TOS to help with hacked sites ! And they can't restore either. Pathetic.
     
    aspire, Aug 24, 2012 IP
  5. raoraj

    raoraj Well-Known Member

    Messages:
    849
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    110
    #5
    i guess you have the ftp working.
    try deleting .htaccess file.
    change all your account passwords.
    update wordpress and all plugins
     
    raoraj, Aug 25, 2012 IP
  6. Ray Baron

    Ray Baron Member

    Messages:
    148
    Likes Received:
    10
    Best Answers:
    3
    Trophy Points:
    43
    #6
    The first thing to do is to take the site offline so it doesn't get blacklisted by Google. Just put a "maintenance" page up while you work through fixing it.

    JingoBD appear to be garden variety script kiddie "hackers" that can be defeated by keeping the WP code up to date and taking a few other, simple precautions.

    If you have a backup, go back to just before the hack and update the site and all plugins immediately upon getting the site back online.

    Once up, I would find a better host because once a site is hacked, script kiddies will keep coming back to the site. There are several things you can do with WordPress to make it more secure. PM me and I can give you some hints to make the site more secure.
     
    Ray Baron, Aug 25, 2012 IP
  7. elitestar47

    elitestar47 Peon

    Messages:
    15
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    SIMPLEST SOLUTION
    _________________

    contact your host to recover your CPanel password, or if you haven't lost that, just compress everything from your Cpanel, take it to your desktop extract it, again put it in a zip file and upload again, just extract on server, all fixed...

    I recently got my own site hacked and a message like you was showing which was saying " Hacked by Cyber Team ". I just followed the steps above and got all fixed.

    Please try once.

    Thanks,
    Best Regards,
    Team - Elite.
     
    elitestar47, Aug 26, 2012 IP
  8. Ray Baron

    Ray Baron Member

    Messages:
    148
    Likes Received:
    10
    Best Answers:
    3
    Trophy Points:
    43
    #8
    Are you saying that you just zipped your site, unzipped it on your desktop, zipped it up again, uploaded and unzipped on your server?

    Where is the step to clean out the infected code?
     
    Ray Baron, Aug 26, 2012 IP
  9. anup_tcrti

    anup_tcrti Guest

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    My client's site already has the warning message from Google. What should be done now?Do let me know. Thanks - Anoop Vattoly, Tecriti Consulting
     
    anup_tcrti, Aug 27, 2012 IP
  10. Ray Baron

    Ray Baron Member

    Messages:
    148
    Likes Received:
    10
    Best Answers:
    3
    Trophy Points:
    43
    #10
    1. Take it offline.

    2. Restore a backup from pre-hack. Update all code immediately.

    3. Notify Google via Webmaster tools that your site has been fixed.
     
    Ray Baron, Aug 27, 2012 IP
  11. Smartyy

    Smartyy Peon

    Messages:
    70
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Open your cpanel and change your wordpress password and username through phpmyadmin. After you have gain access to your wp site than delete the current theme and install a new one.
     
    Smartyy, Aug 31, 2012 IP