+ Reply to Thread
Results 1 to 10 of 10

Thread: Site Hacked... any ideas?

  1. #1
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5

    Site Hacked... any ideas?

    Lovely surprise as I went to the wp-admin for my site, found that it's been hacked by some Turkish guy.

    It was the latest build of WP, so not sure about the security flaw that let him in, though a brief Google search suggests that it may have something to do with the Linux instalation server side.

    Anyone have any ideas on how to fix this?


    *In my hurry I noticed I've posted this in the wrong forum. Clinton or a moderator, please move it if you so wish. Also, its this site that's been hacked.
    Last edited by mgallone; March 28th, 2011 at 3:07 PM. Reason: Additional info

  2. #2
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5
    (Apologies for the rapid double post)

    I've found that I can access my WP dashboard if I go through the plesk panel at the host. Doesn't look like I've lost my site, just that it's being blocked/overode from display by this 'hacked' message.

  3. #3
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    7,281
    Blog Entries
    30
    Thanks
    3,907
    Thanked 2,646 Times in 1,500 Posts
    Rep Power
    101
    Before you fix it, change all your passwords. Not just to the site but to the server/CP/email at this domain/everything. Sorry if it seems obvious, but it's surprising how often people aren't thorough enough with changing passwords after such an attack.
    Show your support - Like us on Facebook

  4. The Following User Says Thank You to Clinton For This Useful Post:

    mgallone (March 28th, 2011)

  5. #4
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5
    So surprising that I've only just done it after your suggestion... geez, my mind's racing in so many different directions its just not going straight Cheers for that, Clinton.

  6. #5
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    7,281
    Blog Entries
    30
    Thanks
    3,907
    Thanked 2,646 Times in 1,500 Posts
    Rep Power
    101
    Now find the last backup of your site on your hard disk or ask your host for the last copy they made. Check it for scripts and other nasties and then replace all existing content with that copy.
    Show your support - Like us on Facebook

  7. The Following User Says Thank You to Clinton For This Useful Post:

    mgallone (March 28th, 2011)

  8. #6
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5
    Right, progress update...

    I've found and removed the offending script and HTML file using an FTP program. Now, if you look at the page its just showing the Apache test confirmation message. Hmm. I may have to completely remove WP and start over before uploading the backup.

  9. #7
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5
    And done.

    Turns out in removing the script I also got rid of the WP index.php, which had been modified. All seems well now for the time being.

    Cheers for your help Clinton.

  10. #8
    Premium Member
    Join Date
    Aug 2010
    Location
    Adelaide
    Posts
    2,553
    Blog Entries
    6
    Thanks
    1,345
    Thanked 1,570 Times in 840 Posts
    Rep Power
    52
    Sorry to be late to the party,
    your server has been hacked.
    No matter what you do now the guy who hacked the server can undo any changes and re infect the site.

    2b-intune.com
    1st-car.co.uk
    4-specialpigeonsonly.com

    these are just 3 sites on your server and each one has been infected.

    NOTE: Please DO NOT look at these sites if you don't know what you are doing they could be running scripts to infect your pc.

  11. The Following 2 Users Say Thank You to grynge For This Useful Post:

    Clinton (March 28th, 2011), mgallone (March 28th, 2011)

  12. #9
    Dormant Account
    Join Date
    Apr 2010
    Location
    Staffordshire
    Posts
    271
    Thanks
    57
    Thanked 29 Times in 23 Posts
    Rep Power
    5
    Thanks for checking that out- wouldn't have had the faintest idea how to do that.

    I've done a bit more research on this guy (I don't want to use his name in case it turns up in Google and draws his attention to EP... though I'm sure these servers are orders of magnitude better than the ones used for that site... but I digress ) and it seems that he/she drops that modified index onto a bunch of sites, but does nothing else. I have no idea why this is the case, but it seems very odd, and I'll be contacting the hosting provider to let them know if they aren't already aware.

  13. #10
    Premium Member
    Join Date
    Aug 2010
    Location
    Adelaide
    Posts
    2,553
    Blog Entries
    6
    Thanks
    1,345
    Thanked 1,570 Times in 840 Posts
    Rep Power
    52
    Quote Originally Posted by mgallone View Post
    Thanks for checking that out- wouldn't have had the faintest idea how to do that.
    This is DEFINITELY a hosting company problem. Somehow the whole server has been compromised.

    You need to do a reverse-dns on the ip and it normally shows you other domains hosted on the 1 server. I can give you a list of the ones I found just PM me. I found about 390 sites hosted on the same ip as yours and each one I looked at around 15 random ones (sorry don't have time to look at all of them) all of them had the same guys message.

    I gather because there is no payload this guy is just after infamy. I only saw youtube code as the infect message (tho it is possible he has found a way to infect via youtube?)

+ Reply to Thread

Similar Threads

  1. I think my site was hacked
    By MrP in forum Website 101
    Replies: 13
    Last Post: February 19th, 2011, 10:01 PM
  2. Looking for ideas
    By grynge in forum General & Miscellaneous
    Replies: 6
    Last Post: December 16th, 2010, 3:41 PM
  3. Any ideas on a value for this site?
    By sparesman in forum Selling a Website, Blog, Domain or Business
    Replies: 5
    Last Post: July 30th, 2010, 11:10 AM
  4. Replies: 22
    Last Post: July 22nd, 2010, 7:08 AM
  5. I've been hacked.
    By Andy in forum General & Miscellaneous
    Replies: 7
    Last Post: May 28th, 2010, 3:05 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts