My 5 Month Old Blog Hacked. Bloggers Beware!

23 replies
I visited my blog late last night and I finished writing a post I wanted to publish this morning, but when I tried logging into my WordPress dashboard this morning I found out my blog had been hacked.

And the suprising thing is that I took steps a couple of weeks ago or so to make my blog hack-free.

So to all you guys out there who own one website or blog. Beware! Do all you can to prevent hacking(though I now have reasons to believe your site cannot be completely hack-proof). Don't use the same or similar passwords in all your accounts.
For proof visit Behind The Scene With Leading Online Entrepreneurs - Blogging For Profits or click ANY of the links in my signature.

Or does anyone out there know how I can get my blog back? It has just started growing big.
#beware #blog #bloggers #hacked #month
  • Profile picture of the author TheKing
    Hello

    your cpanel or ftp details working ?
    {{ DiscussionBoard.errors[3684849].message }}
    • Profile picture of the author Manuelcrc
      Originally Posted by punjabi View Post

      Hello

      your cpanel or ftp details working ?
      Yes I just logged into my cpanel and informed my web hosting company.
      Signature

      [B]Get free resources for Entrepreneurs and Startups.

      Check out our collection of Product and Business Reviews?

      {{ DiscussionBoard.errors[3684862].message }}
      • Profile picture of the author TheKing
        Originally Posted by Manuelcrc View Post

        Yes I just logged into my cpanel and informed my web hosting company.
        Ok ,, i m sure hacker only changed index file ,,,
        if you want then i can look into it and ll try to restore your blog

        let me know
        {{ DiscussionBoard.errors[3684907].message }}
        • Profile picture of the author Steve Faber
          Originally Posted by punjabi View Post

          Ok ,, i m sure hacker only changed index file ,,,
          if you want then i can look into it and ll try to restore your blog

          let me know
          That's what they did when they hacked mine; deleted the index file. I was using an account with a domain and an add on domain running in the same file structure, so they nuked both blogs. One of them was fairly well backed up. On the other, I was an idiot, and failed to make backups. I lost it all. There were only about 12 posts, but there was quite abit of customization done that is time consuming to redo.

          Always make regular backups and keep them in a secure location.
          Signature
          For Killer Marketing Tips that Will Grow Your Business Follow Me on Twitter Now
          After all, you're probably following a few hundred people already that aren't doing squat for you.....
          {{ DiscussionBoard.errors[3688047].message }}
  • Profile picture of the author omrishabbat
    [DELETED]
    {{ DiscussionBoard.errors[3684884].message }}
    • Profile picture of the author Manuelcrc
      Originally Posted by omrishabbat View Post

      This is really frightening... I am working real hard on my blog and the thought that one day someone will ruin it all...
      What version of Wordpress were you using? I heard that the last version is much more secured.
      I use the latest version. I update every time a new one is released.
      Signature

      [B]Get free resources for Entrepreneurs and Startups.

      Check out our collection of Product and Business Reviews?

      {{ DiscussionBoard.errors[3684896].message }}
  • Profile picture of the author erichammer
    Lesson learned from all this: keep a backup of your blog at all times. This way recovery is relatively painless.
    Signature
    Why waste your time hiring a cheap writer? Cheap writers don't write stuff that converts!

    Get the conversions you need and deserve with my professional, viral writing services.

    Free SEO included at no additional charge!
    {{ DiscussionBoard.errors[3684916].message }}
  • Profile picture of the author AllanWard
    Originally Posted by Manuelcrc View Post

    And the suprising thing is that I took steps a couple of weeks ago or so to make my blog hack-free.
    I'm interested to know what you did to make it hack-free. Is there anything more you could have done that you now know about?
    {{ DiscussionBoard.errors[3684942].message }}
  • Profile picture of the author marketwarrior06
    Banned
    at first don't share any kind of information about your blog, mail, affiliate account anything with your friends. friends are the main enemy remember it. i am experienced in this problem.
    don't worry if one is lost don't stop working and don't loose hope. may be better is waiting for you in future.
    {{ DiscussionBoard.errors[3684970].message }}
  • Profile picture of the author niffybranco
    BackUP BackUP BackUP............There is no such thing as Hack Free even the pentagon that spends millions of dollars on cyber security gets hacked not to talk of someone paying $49.95 a month or less for hosting ............. BackUP BackUP BackUP do this daily and you will not loose you work if you eventually get hacked.
    {{ DiscussionBoard.errors[3684977].message }}
  • Profile picture of the author lkcheng
    I was wondering why people target your blog to hack.
    {{ DiscussionBoard.errors[3685043].message }}
  • Profile picture of the author TPFLegionaire
    Have you checked your PC for possible virus or trojan infections?


    Securing your blog is not going to do any good if your passwords can be "sniffed" by a Trojan.

    Good luck in restoring everything
    {{ DiscussionBoard.errors[3685090].message }}
    • Profile picture of the author Manuelcrc
      Originally Posted by TPFLegionaire View Post

      Have you checked your PC for possible virus or trojan infections?


      Securing your blog is not going to do any good if your passwords can be "sniffed" by a Trojan.

      Good luck in restoring everything
      Thanks. It's working fine now. I had to delete my theme and I have to do some tweaking.
      Thanks y'all.
      Signature

      [B]Get free resources for Entrepreneurs and Startups.

      Check out our collection of Product and Business Reviews?

      {{ DiscussionBoard.errors[3685363].message }}
    • Profile picture of the author JBrooks
      Originally Posted by TPFLegionaire View Post

      Have you checked your PC for possible virus or trojan infections?


      Securing your blog is not going to do any good if your passwords can be "sniffed" by a Trojan.

      Good luck in restoring everything
      I second this. there are some real nasty viruses about, I had to do a full clean re-install of our operating system at work because of one, not fun at all.

      do you have all necessary anti-virus programs installed?
      {{ DiscussionBoard.errors[3685412].message }}
  • Profile picture of the author JBrooks
    what steps did you take to make your blog hack-free?
    {{ DiscussionBoard.errors[3685401].message }}
  • Profile picture of the author pikeman
    Yep, I back up on a regular basis, and the host keeps backups too. If you have your wp-content files and the database then you can roll back. If they get ftp login then they can make a real mess. A client once had Gumblar virus, stole his ftp details and then uploaded loads of stuff. Nasty.
    {{ DiscussionBoard.errors[3685402].message }}
    • Profile picture of the author Hamida Harland
      Looks like you got it up and running again okay. I had about half my blogs on one hosting account hacked this time last year - it was probably one of the most stressful days I've had online!

      Luckily I had everything backed up properly, but it took me ages to 'hack proof' all my blogs. I'm sure they're never 100% hack proof no matter what you do, but hopefully it won't happen again any time soon.
      Signature
      {{ DiscussionBoard.errors[3685422].message }}
      • Profile picture of the author Manuelcrc
        Originally Posted by Hamida Harland View Post

        Looks like you got it up and running again okay. I had about half my blogs on one hosting account hacked this time last year - it was probably one of the most stressful days I've had online!

        Luckily I had everything backed up properly, but it took me ages to 'hack proof' all my blogs. I'm sure they're never 100% hack proof no matter what you do, but hopefully it won't happen again any time soon.
        Yeah thanks. It's sure very stressful to lose one blog let alone multiple blogs. Really glad I got it back.
        Signature

        [B]Get free resources for Entrepreneurs and Startups.

        Check out our collection of Product and Business Reviews?

        {{ DiscussionBoard.errors[3685475].message }}
  • Profile picture of the author pikeman
    One extra bit of security, if you have a static IP address, make your wp-admin directory and the wp-login.php page only accessible to your IP. Also, some webhosts allow you to whitelist IP's to log in to the control panel. This way having your password does not help. A pain if your ISP changes your IP, but makes it much more secure.

    There is a plugin that works in a similar way and will help if your IP changes, although I have not used this, do everything through htaccess. - WordPress › WP Login Security « WordPress Plugins
    {{ DiscussionBoard.errors[3685462].message }}
  • Profile picture of the author pikeman
    Oh, and if your admin account is still "admin", change it. Create a new user, make that user an administrator, then login as them and delete Admin account.
    {{ DiscussionBoard.errors[3685468].message }}
  • Profile picture of the author WAWarrior
    "Backup", "Security"," Virus protection"... those are some of the keywords I registered from this thread. Thanks for sharing the experience.
    {{ DiscussionBoard.errors[3685513].message }}
  • {{ DiscussionBoard.errors[3687853].message }}
  • Profile picture of the author DennisM
    Here's a tip,

    DO NOT use your normal, everyday PC when accessing your hosting account.

    I use a Linux operating system called Ubuntu. Don't let the word scare you. This Linux version acts and looks like MS Windows. What you do is get this pre loaded on a USB thumb drive. Linux OS even has a browser and Open Office preloaded so now you can connect to youor webhost and work on your blog.

    What you do is plug in the USB drive and reboot your PC. You're now running Linux in your PC memory (there's no install required and completely runs off the USB drive!)

    When you're done just remove the USB drive and reboot your PC back into Windows XP/7 etc. This is relatively safe as when you reboot the PC everything is erased from memory.

    You can purchase a full operating system thumb drive on eBay for 10 bucks! (NO Aff. link)

    http://cgi.ebay.com/NEW-UBUNTU-10-10...item56438d7914

    This works for me and I've NEVER had any hack problems. I just make sure I never log into my hosting accounting on my main computer as there's potentially more risk.

    Give it a try!

    Dennis
    {{ DiscussionBoard.errors[3688259].message }}
    • Profile picture of the author TPFLegionaire
      Originally Posted by DennisM View Post

      Here's a tip,

      DO NOT use your normal, everyday PC when accessing your hosting account.

      I use a Linux operating system called Ubuntu. Don't let the word scare you. This Linux version acts and looks like MS Windows. What you do is get this pre loaded on a USB thumb drive. Linux OS even has a browser and Open Office preloaded so now you can connect to youor webhost and work on your blog.

      What you do is plug in the USB drive and reboot your PC. You're now running Linux in your PC memory (there's no install required and completely runs off the USB drive!)

      When you're done just remove the USB drive and reboot your PC back into Windows XP/7 etc. This is relatively safe as when you reboot the PC everything is erased from memory.

      You can purchase a full operating system thumb drive on eBay for 10 bucks! (NO Aff. link)

      NEW UBUNTU 10.10 LINUX DESKTOP OS 32 BIT 4GB USB FLASH | eBay

      This works for me and I've NEVER had any hack problems. I just make sure I never log into my hosting accounting on my main computer as there's potentially more risk.

      Give it a try!

      Dennis


      Good thinking but maybe....

      you could also run ubuntu on a salvaged laptop or PC, something a few years old that doesn't consume too much electricity...I mean...Rebooting is a right pain in the butt and put unnecessary stress on the machine.

      or if you could run an instance of ubuntu in a VM environement and log from there as needed without having to reboot anything.

      Glad to hear you have restored your blog.

      Cheers,
      {{ DiscussionBoard.errors[3688593].message }}

Trending Topics