Wordpress Website hacked

Discussion in 'WordPress' started by sahirfarid, Apr 21, 2012.

  1. #1
    Dear Experts!

    My wordpress website is hacked by a group N30 and they have changed the admin passwords. I need your kind response to retrieve my website back.

    Regards
     
    sahirfarid, Apr 21, 2012 IP
  2. sahirfarid

    sahirfarid Active Member

    Messages:
    240
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #2
    Here is the screenshot of the homepage..

    untitled.JPG
     
    sahirfarid, Apr 21, 2012 IP
  3. krishmk

    krishmk Well-Known Member

    Messages:
    1,376
    Likes Received:
    40
    Best Answers:
    0
    Trophy Points:
    185
    #3
    Looks like they have added a new index file (this doesnt looks like wordpress).
    Remove all the files via FTP. Install a fresh version of wordpress or upload the backup files (if you believe its safe).

    Change your FTP/cpanel password. Use latest version of Wordpress. Also inform your Host about this hack.
     
    krishmk, Apr 21, 2012 IP
  4. sahirfarid

    sahirfarid Active Member

    Messages:
    240
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    51
    #4
    Yes, I have restored it now but I wanna know how it happened and what should I do to avoid this issue again.
     
    sahirfarid, Apr 21, 2012 IP
  5. little acorns

    little acorns Peon

    Messages:
    25
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    that's crazy if you find out how it happened please share :)
     
    little acorns, Apr 21, 2012 IP
  6. hackrepair

    hackrepair Member

    Messages:
    47
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    40
    #6
    Hi,
    I would start by reviewing your FTP login logs. If you are not sure what this is, then ask your host, "My site was hacked and I can you help me check my FTP logs to see if anyone has uploaded files other than me in the past week?"
     
    hackrepair, Apr 21, 2012 IP
  7. adbox

    adbox Well-Known Member

    Messages:
    906
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    155
    Digital Goods:
    1
    #7
    What I do when I get hacked is I delete any untrustworthy plugins.

    Delete all unused themes from my theme directory and consider changing my theme to the default one until I'm sure I'm clean and not being re-infected.

    Then I check theses files for oddities:
    index.php
    wp-config.php
    wp-settings.php

    I check for and delete these files because they are malicious:
    /wp-admin/js/config.php
    /wp-admin/common.php
    feed_file.php
    feed-files.php
    udp.php
    /wp-content/uploads/r1.php
    /wp-content/uploads/lib.php
    /wp-content/uploads/am3.php
    /wp-content/uploads/create.php
    timthumb.php

    Then I check my .htaccess file to see if it was hacked.
    Then I check my wp-content/uploads/ directory and subdirectory for oddities

    I make sure all the blogs on my host are updated and repeat the process for any blog I suspect has been compromised...
    most of the time all blogs on a host will be compromised if one is...

    But it might be better to just delete all your wordpress files for each site and reupload them along with trustworthy plugins and themes.

    Hassle!

    Then after everything is restored I change my passwords to something temporary until I can prove that I'm not being hacked again.
     
    adbox, Apr 22, 2012 IP
  8. BuenaBe

    BuenaBe Peon

    Messages:
    30
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    contant your hosting provider..i using hostgator and they have security team
     
    BuenaBe, Apr 22, 2012 IP
  9. raoraj

    raoraj Well-Known Member

    Messages:
    849
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    110
    #9
    most of such hacker change index.php or .htaccess files.
    Adbox posted some good steps about this.

    take regular backup of your wordpress blog.
     
    raoraj, Apr 22, 2012 IP
  10. onlinebu

    onlinebu Greenhorn

    Messages:
    27
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    11
    #10
    Exactly same here. I was with Just Host, and had over 30 sites look like that one at one time. Been with Hostgator for years now without any troubles.
     
    onlinebu, Apr 24, 2012 IP