A lot of Wordpress blogs hosted at Godaddy.com is hacked!

Discussion in 'WordPress' started by datatrond, May 17, 2010.

  1. #1
    That includes my new personal blog on Godaddy.com that was not launched yet. It was running the newest Wordpress version, it had "noindex" and no incoming links.. I had even protected the site from beeing found/viewed by using an offline script and used very complex usernames and passwords.. How could this happen? :mad:
     
    datatrond, May 17, 2010 IP
  2. deluxdon

    deluxdon Catch Me If You Can...!!!™ Staff

    Messages:
    25,482
    Likes Received:
    1,943
    Best Answers:
    32
    Trophy Points:
    480
    #2
    Have you contacted godaddy about this issue ? What they replied ??

    DON.
     
    deluxdon, May 17, 2010 IP
  3. Boogy

    Boogy Active Member

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    73
    #3
    This problem has been going on for a long time....My sites and client sites have also been hacked. This is not isolated to Wordpress, as one of my sites is custom coded and same issue.

    The quick fix would be to do a restore from within Godaddy's hosting control panel. To do this, login to your hosting panel and click the big square button that says my files. Then history. Select a date and then restore. You might need to call Godaddy to make sure this goes smoothly.

    Also, don't try complaining to them, they will deflect...this is their integrity at stake. Just know, that it's not necessarily anything you did wrong.

    What you can do right is install the security scan plugin : wordpress.org/extend/plugins/wp-security-scan/

    It tells you a few things you can set right before anything bad happens. Try to replicate for none Wordpress sites.

    hope this helps
     
    Boogy, May 17, 2010 IP
  4. Boogy

    Boogy Active Member

    Messages:
    36
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    73
    #4
    By the way..it's most likely malware...which basically throws a popup window to your user and faking a security scan. Hopefully it's not eating your files or database.
     
    Boogy, May 17, 2010 IP
  5. lelkoun

    lelkoun Active Member

    Messages:
    288
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    60
    #5
    lelkoun, May 17, 2010 IP
  6. DrVillain

    DrVillain Peon

    Messages:
    63
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    1 key things to do is make sure your files anr't WORLD READABLE. this is how a lot of these mass attack on WP happens, you scan a shared servers home dirs for /wp-configs.php that you can read and then do the SQL stuff or whatever.
     
    DrVillain, May 17, 2010 IP
  7. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #7
    I agree that this is not new. I have also had a client recently have his (Go Daddy hosted) Wordpress site hacked. As much as I hate them for hosting, I can't say that this is specific to Go Daddy since you do have control over your own Wordpress security.

    What was their response? Did you contact them about it?
     
    hmansfield, May 18, 2010 IP
  8. RiArose

    RiArose Peon

    Messages:
    44
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Are you sure it's happening due to GoDaddy or Wordpress? Have you explored any possibility of using unreliable plugins from untrusted developers? If you aren't aware, there are some plugins in wordpress.org where developer himself says "Using it is not recommended"! So if you used any plugins like that, it may cause problems for you.
     
    RiArose, May 22, 2010 IP
  9. boscof

    boscof Peon

    Messages:
    90
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I am not hacked!I am luchy!
     
    boscof, May 22, 2010 IP
  10. etali

    etali Well-Known Member

    Messages:
    1,215
    Likes Received:
    43
    Best Answers:
    0
    Trophy Points:
    105
    #10
    I've noticed this happening a lot. Several of my clients have been hit (they were on Hostgator, though) I think it's more likely to be malware than the hackers targetting a specific host in most cases.

    Or, possibly brute-force attacks - was your CPanel password a dictionary word, or something easy to guess?

    I hope you haven't lost anything too serious. I know it's a pain to clean up a hacked Wordpress :(
     
    etali, May 23, 2010 IP
  11. Serious Workers

    Serious Workers Well-Known Member

    Messages:
    2,785
    Likes Received:
    65
    Best Answers:
    2
    Trophy Points:
    195
    #11
    Yes, there are several problems going on with Godaddy hosting right now. And many of the blogs are getting Malware codes injected.
     
    Serious Workers, May 23, 2010 IP
  12. Sales4u2

    Sales4u2 Peon

    Messages:
    36
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    My site was also hacked before, i added a security plugin to my site and my site is already running 1 month now and i had no problems.
     
    Sales4u2, May 24, 2010 IP
  13. ilook

    ilook Well-Known Member

    Messages:
    1,602
    Likes Received:
    15
    Best Answers:
    1
    Trophy Points:
    165
    #13
    It's because a lot people use warez plugins/themes.
    And these people deserve it!
     
    ilook, May 27, 2010 IP
  14. hmansfield

    hmansfield Guest

    Messages:
    7,904
    Likes Received:
    298
    Best Answers:
    0
    Trophy Points:
    280
    #14
    So true. Using bootleg or warez premium themes and plug ins can really "F" up your site. So many are loaded with scripts, adware, and viruses. Do you really think people load this stuff up for download out of the goodness of their hearts? Hell no, they know that people like to beat the system, so it's an easy way to infect computers and websites.

    I agree, they do deserve it.
     
    hmansfield, May 27, 2010 IP
  15. datatrond

    datatrond Active Member

    Messages:
    213
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    73
    #15
    I have only installed paid extensions!
    I never use Warez plugins/themes and do not recommend anyone to do this either.
    I buy all themes from Woothemes.

    The thing that makes this very strange is that it was 100 % up to date.
    No outdated plugins, theme, wordpress version and so on..

    I did use the Godaddy wordpress installer. I did not upload the files through FTP.
     
    datatrond, May 30, 2010 IP
  16. Oranges

    Oranges Active Member

    Messages:
    2,610
    Likes Received:
    92
    Best Answers:
    0
    Trophy Points:
    90
    #16
    Yes few of my blogs hosted on Daddy was hacked too last week, and few of my friends and clients are also facing same problem with Godaddy.
    Even though i use them for just few blogs, but looks like gotta move on!
     
    Oranges, May 30, 2010 IP