My old website getting pharmy/viagra hack , please help

Discussion in 'HTML & Website Design' started by coolraghav, Jun 14, 2013.

  1. #1
    this keeps on happening, one of my websites keep getting pharmacy/viagra bulk links hack.

    google says "site may have been compromised"
    normal user doesn't see anything, only the google crawls it.

    site is normal html and first index page is PHP. tell me what should I do to fix this issue or if someone can fix it for me.

    CHMOD correctly.

    Thanks
     
    Last edited: Jun 14, 2013
    coolraghav, Jun 14, 2013 IP
  2. deathshadow

    deathshadow Acclaimed Member

    Messages:
    9,732
    Likes Received:
    1,999
    Best Answers:
    253
    Trophy Points:
    515
    #2
    I'd have to see the code being used to provide any sort of meaningful help -- but...

    have you rotated the FTP passwords?
    Is that PHP using EVAL in any way shape or form?
    Are you using 'include' or 'require' on a $_POST or $_GET value?
    Have you cleaned the directory of any modified files?
    When you 'erase' the hacked copy, are you sure the files you put in their place aren't hacked?

    ... and are you self-hosting, or relying on shared? If the latter it could be some other site on the server that's screwing with yours.
     
    deathshadow, Jun 14, 2013 IP
  3. jumpinjack

    jumpinjack Active Member

    Messages:
    347
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    60
    #3
    You might have a virus on your computer which is leaking your FTP password.

    Scan with malwarebytes.org and at least one other anti-virus program, see if you find anything.
     
    jumpinjack, Jun 14, 2013 IP
  4. coolraghav

    coolraghav Well-Known Member

    Messages:
    326
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    130
    #4
    no there is no virus on my computer only happens to this site. as i'm not using anything php related now so i have changed my index.php to index.html , hope that cannot be injected. its probably some newsfeed.
    I need to hire someone who can fix this issue. :S anyone?
     
    coolraghav, Jun 15, 2013 IP