WordPress hack

Discussion in 'WordPress' started by Cintra, Nov 2, 2012.

  1. #1
    I have recently had a WordPress site hacked. My hosting company have found no evidence of where the site was hacked. Can anyone advise how to prevent hacking of any WordPress site? Have taken down the hacked site.
     
    Cintra, Nov 2, 2012 IP
  2. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #2
    What do you mean by saying that your site was "hacked"? What happened to your site?
     
    Devtard, Nov 2, 2012 IP
  3. Plugger

    Plugger Active Member

    Messages:
    228
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    60
    #3
    Plugger, Nov 2, 2012 IP
  4. Cintra

    Cintra Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    The site in question was one I had neglected for 2 or 3 months, and I was intending to take it down anyway. However, someone had managed to sign in as a User, but certainly not through me. When I checked further, there were about 50 or so additional 'Users', and countless 2 or 3 line new 'Posts' dating back to the beginning of October. Needless to say I immediately closed the site down.
     
    Cintra, Nov 3, 2012 IP
  5. deluxdon

    deluxdon Catch Me If You Can...!!!™ Staff

    Messages:
    25,481
    Likes Received:
    1,943
    Best Answers:
    32
    Trophy Points:
    480
    #5
    Always keep your wp version up to date (latest version) to avoid hacking IMO.

    DON.
     
    deluxdon, Nov 3, 2012 IP
  6. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #6
    It is possible that someone knew your WP admin/FTP/MySQL password or you were using plugins/themes with backdoors/security holes.

    Keep your plugins/themes updated, download them only from reliable sources and just to be sure change your passwords if you use them somewhere else.
     
    Devtard, Nov 3, 2012 IP
  7. mccomf

    mccomf Active Member

    Messages:
    517
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    53
    #7
    WP Safety Scan

    The WP Security Scan extension and won’t let you know whether your website has been hacked, but it will test for possible attack vectors and vulnerabilities, and offer strategies for fixes.The easiest way to make sure that there are no recognized exploits that hackers can use is to keep your software program as up-to-date as possible.

    Google’s Safe Looking Diagnostic

    Google has a service that allows site owners to see whether or not they contemplate a site to be dangerous to visit. Copy the following URL into your browser handle bar and change the half following ‘?website=’ together with your web site’s URL.

    http://www.google.com/safebrowsing/diagnostic?web site=google.com/

    Sucuri

    Sucuri offer a free website scanning service that can catch major issues, and a paid for monitoring and cleanup service that may assist if you’re hacked.

    Using these tools together will help you make sure that your site remains safe.
     
    mccomf, Nov 3, 2012 IP
  8. Cintra

    Cintra Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Many thanks for all your advices, I will be taking more care in future regarding updates, etc
     
    Cintra, Nov 3, 2012 IP