by motley
54 replies
Hey all,

My Hostgator account was hacked last night. Hackers had put an index.html file with a java script in every folder in the public_html directory. It resulted in that when a visitor come to my site he/she could see the page as on the screenshot below.

I used whole my morning to remove this c**p. After that I changed the password to my hosting account.

Should I do anything else in addition? Should I inform my hosting provider about this?

Thanks for any suggestion,

Dmitrij
#hacked #hosting
  • Profile picture of the author hoangminhnhat
    I think you should contact your hosting manager for more information,
    {{ DiscussionBoard.errors[4743448].message }}
  • Profile picture of the author Karan Goel
    Congratulation!!



    Nah.. Just kidding.

    I understand what you're going through. The same happened to my 3 times in 1 week! :O

    What I did was get on my hosting provider, speak a little heavily. They ran an exploit scanner for the whole server, and found at least 3k instances of malicious codes. Within hours, they removed each and every piece of sh*t from there.
    Signature
    Penalty Safe, Long Term, 100% Whitehat Backlinks
    Love your site? Then check out SafeSpokes!
    ~_~_~_~_~_~_~_~_~_~_~_~_~_~_~_~_~_~_~_
    karan996@irchiver.com karan997@irchiver.com
    {{ DiscussionBoard.errors[4743474].message }}
    • Profile picture of the author Ed Micah
      Originally Posted by Karan Goel View Post


      What I did was get on my hosting provider, speak a little heavily. They ran an exploit scanner for the whole server, and found at least 3k instances of malicious codes. Within hours, they removed each and every piece of sh*t from there.
      That's exactly what I did a few months ago.
      {{ DiscussionBoard.errors[4743499].message }}
  • Profile picture of the author retsced
    Hey motley,

    The same thing happened to me a couple of months ago and i spent a couple of hours deleting all the crap from my .php files. I don't see the benefit of contacting your host provider as i don't think there is any anything they can do on their part. Of course i may be wrong though :rolleyes: (obviously don't listen to me as others have had some luck with their providers)

    Just make sure all your plugins are up to date and if you have any themes with bad scripts make sure to delete them. I found out in the end that it was a bad theme that caused the problem on my end.

    That's all i know mate, but once all the .php files were cleaned up i have had no issues since.
    Signature
    Strong Men and Women put themselves in harms way
    for the freedoms weak people give away for safety
    {{ DiscussionBoard.errors[4743493].message }}
  • Profile picture of the author John Romaine
    Let me guess, wordpress?
    Signature

    BS free SEO services, training and advice - SEO Point

    {{ DiscussionBoard.errors[4743923].message }}
    • Profile picture of the author Newman8r
      Originally Posted by ramone_johnny View Post

      Let me guess, wordpress?
      lol.... I hate the fact that WP is becoming the internet explorer of CMS
      {{ DiscussionBoard.errors[4744250].message }}
  • Profile picture of the author shulink
    don't contact. My hosting provider suspended my account and all my websites was down after they found out my php files were hacked without notifying me. So I had to contact them to find out the reason and reuploaded the clean files in order for the sites to be back up.
    {{ DiscussionBoard.errors[4744278].message }}
  • Profile picture of the author Kevin_Hutto
    You should have a backup of all your sites at a secondary hosting account with another company. That way if something like this happens, you can just point to the new account.
    {{ DiscussionBoard.errors[4744294].message }}
  • Profile picture of the author Bruce NewMedia
    Sorry to hear about this...had pretty much exactly the same thing happen months ago....caused quite a mess. I would advise changing passwords, not just due to this event, but on a regular basis. I also would tell the host what happened.
    _____
    Bruce NewMedia
    {{ DiscussionBoard.errors[4744464].message }}
  • Profile picture of the author gillw254
    Better immediately contact Hosgator Support for this.. they may give you some good suggestion...
    {{ DiscussionBoard.errors[4744594].message }}
  • Profile picture of the author globalpro
    If you contact Host Gator, they should be able to access the server logs and tell you when, where and what files were exploited. It may end up being some script you like, but is not worth the time and aggravation.

    Thanks,

    John
    {{ DiscussionBoard.errors[4744734].message }}
    • Profile picture of the author CoolAndAwesome
      Originally Posted by globalpro View Post

      If you contact Host Gator, they should be able to access the server logs and tell you when, where and what files were exploited. It may end up being some script you like, but is not worth the time and aggravation.

      Thanks,

      John
      Exactly. Just the fact you "cleaned" or deleted files is not enough.

      You need to have them examine HOW your website was hacked so that you can toughen it where it was weak.
      {{ DiscussionBoard.errors[4795477].message }}
      • Profile picture of the author Lloyd Buchinski
        Originally Posted by CoolAndAwesome View Post

        You need to have them examine HOW your website was hacked so that you can toughen it where it was weak.
        See post 43
        Signature

        Do something spectacular; be fulfilled. Then you can be your own hero. Prem Rawat

        The KimW WSO

        {{ DiscussionBoard.errors[4795564].message }}
        • Profile picture of the author motley
          Originally Posted by Lloyd Buchinski View Post

          Actually the title of your topic bothered me since I first saw it. Just read the thread to make sure, of course you now know that it wasn't your hosting that was hacked. It was your blog.

          You can edit that if you go to your original post and click on advanced edit.
          I'm sorry my topic has bothered you, but I don't think I have to change anything in the topic title. My hosting account was hacked through some of my blogs. Not a blog was hacked, but many blogs, html sites and script based sites at my account was affected. Hackers found a way to my account using week passwords, that I wasn't so clever to change after receiving a MNS pack.
          Originally Posted by londoncoffee View Post

          When your host is secure again, take a look at http://www.websitedefender.com as it seems like a good free service. They also offer a free Secure Wordpress Plugin.
          Thank you!
          Originally Posted by CoolAndAwesome View Post

          Exactly. Just the fact you "cleaned" or deleted files is not enough.

          You need to have them examine HOW your website was hacked so that you can toughen it where it was weak.
          I have learned this lesson )) Look above.
          Originally Posted by Lloyd Buchinski View Post

          See post 43
          Right.
          {{ DiscussionBoard.errors[4795676].message }}
  • Profile picture of the author motley
    Guys, thanks for replying.

    It's not a Wordpress issue, I guess. I have many wordpress installations as well as many prismotubes, html and script based landing pages. The harmful index.html file was put into every directory of the public_html directory, not into wordpress only. After removing of all that index.html, everything works well. I hope the php files is not affected.

    I agree with those who suggest to inform Hostgator. I've done it recently. I have already received this email from hostgator:
    I have started scanning the account for further malware. This will take some time to complete as there are over 1000000 files on the account to scan. I have set the ticket to reopen in eight hours. We will review the results and update you again then.
    No heavy conversation was needed ))

    Brian, thank you for the links.
    {{ DiscussionBoard.errors[4745628].message }}
    • Profile picture of the author globalpro
      Originally Posted by motley View Post

      It's not a Wordpress issue, I guess. I have many wordpress installations as well as many prismotubes, html and script based landing pages. The harmful index.html file was put into every directory of the public_html directory, not into wordpress only. After removing of all that index.html, everything works well. I hope the php files is not affected.
      The index file is almost always the one that gets replaced, so that's not unexpected. The hack will replace every index file, so those are the ones to focus on.

      Host Gator will do you right. Have been through this before and they came through with flying colors.

      Thanks,

      John
      {{ DiscussionBoard.errors[4746318].message }}
  • Profile picture of the author G Abbas
    If it is your hostgator account that was got hacked i mean somone had access to your user name and password than its good to scan your Pc with any good antivirus, so to be sure you are not victom of any keylogger or RAT..
    {{ DiscussionBoard.errors[4745784].message }}
  • Profile picture of the author Wisden Writers
    First of all you need to know the reason "How you got hacked"
    Scan each folder properly, Your Databases as well, many times hackers put some stuff in your DB and your posts will show some text links ( It happens in Wordpress Mostly )
    Even Paypal Blog Got such problem and a Text Link of ( Pe**S Enl*******N) was there for over 10 days.

    Hostgator offer great support they will do everything on your behalf. Contact them and relax.
    {{ DiscussionBoard.errors[4746076].message }}
  • Profile picture of the author perzefi
    If you are using wordpress, and you have installed any premium theme downloaded from warez sites then that's might be the reason !
    Or maybe you have used a plugins that has bugs !
    Anyway don't forget to update wordpress to the current version which is 3.2.1 right now
    {{ DiscussionBoard.errors[4746181].message }}
  • Profile picture of the author Vincent Abrugar
    I notice a lot of Wordpress sites using woo themes where hack and got a malware.

    It is important to always have a backup of site files and database.
    {{ DiscussionBoard.errors[4746721].message }}
  • Profile picture of the author Riggs
    motley can you PM me the Javascript code if you still have it (I wont be able to reply but if you don't understand JS I can take a look at what it was trying to do). As G Abbas already said, it might be worth running a reliable malware scanner on your computer in case you're infected with anything malicious. I recommend Malwarebytes Anti Malware (it's free).

    If you need help let me know (add Skype). I originally came here from HackForums so if you want me to have a quick look around and see if the perpetrator decided to brag about it I'll need to know the domain name.
    Signature
    {{ DiscussionBoard.errors[4746779].message }}
    • Profile picture of the author motley
      Originally Posted by G Abbas View Post

      If it is your hostgator account that was got hacked i mean somone had access to your user name and password than its good to scan your Pc with any good antivirus, so to be sure you are not victom of any keylogger or RAT..
      Thanks for suggestions. I do not use any antivirus - I'm a mac user. You were right about others who had access to my user name and password. I ordered a ten micro niche sites pack some time ago and had to grant access to my hosting account to a guy who did all installations. But this guy has tons of good reviews and I don't thinks he is guilty. But of course, his computer could be hacked. I have to inform him about this.
      Originally Posted by Wisden Writers View Post

      First of all you need to know the reason "How you got hacked"
      Scan each folder properly, Your Databases as well, many times hackers put some stuff in your DB and your posts will show some text links ( It happens in Wordpress Mostly )
      Even Paypal Blog Got such problem and a Text Link of ( Pe**S Enl*******N) was there for over 10 days.

      Hostgator offer great support they will do everything on your behalf. Contact them and relax.
      Hostgator's still scanning my account. I trust them.
      Originally Posted by perzefi View Post

      If you are using wordpress, and you have installed any premium theme downloaded from warez sites then that's might be the reason !
      Or maybe you have used a plugins that has bugs !
      Anyway don't forget to update wordpress to the current version which is 3.2.1 right now
      I never use warez themes on my sites, and as I have mentioned above not only wordpress sites were hacked. All wordpress sites are updated.
      Originally Posted by globalpro View Post

      The index file is almost always the one that gets replaced, so that's not unexpected. The hack will replace every index file, so those are the ones to focus on.

      Host Gator will do you right. Have been through this before and they came through with flying colors.

      Thanks,

      John
      Fortunately, most of my sites use index.php file to start, so they haven't been replaced by a fake index.html. But as soon as index.html file had higher priority than index.php, all my sites used hackers's file to open a page. I just needed to remove all that index.html. I had lost one landing page only because it used a index.html file witch was replaced.
      Originally Posted by Riggs View Post

      motley can you PM me the Javascript code if you still have it (I wont be able to reply but if you don't understand JS I can take a look at what it was trying to do). As G Abbas already said, it might be worth running a reliable malware scanner on your computer in case you're infected with anything malicious. I recommend Malwarebytes Anti Malware (it's free).

      If you need help let me know (add Skype). I originally came here from HackForums so if you want me to have a quick look around and see if the perpetrator decided to brag about it I'll need to know the domain name.
      Thanks. I'm going to send you that file. Please, check your PM inbox.
      {{ DiscussionBoard.errors[4747718].message }}
      • Profile picture of the author junabestano
        To Whom It May Concern,

        I may say that there is no such hosting is 100% secure. Once data is placed online, there is always chances that it can be hacked. Very rare when you get issue with your hosting.

        For me, my own better way of having a preventive maintenance is to mirror my site into my local disk periodically. And when running out of time fixing codes in any of my pages of my site, then I'll just have to clone the copy in my local hard drive.

        Sometimes, it is always easier to re-install than repairing issues.

        Hope this could help us you as well.
        Signature

        Your Virtual Assistant - Building Your Business Online

        {{ DiscussionBoard.errors[4747907].message }}
  • Profile picture of the author Ryan Rieth
    That's a bummer man. I never had our server hacked but I would contact HostGator about it. I've had 3 other hosts before I went to HostGator and HostGator has by far been the best I have used. They have excellent support and have always been more then happy to help with any problems I had. I'm sure they will help you out. I'll never use a different host now.
    {{ DiscussionBoard.errors[4747960].message }}
  • Profile picture of the author motley
    Guys, I'm tired of it!

    After I posted the last message here, the HG support team had scanned my account and removed all cr*p. It was three files in the CTR theme at one of my sites. I worked great after that.

    But today I was working with one of my sites when I got a 500 server error. I checked other sites and it was the same. I checked all directories at the public_html directory and found two wrong Heal.html and HeaL.html files in each of them. I removed them all and changed a password to my account. I helped a bit, but after a short time I was attacked again. This time ALL index.php files at ALL sites (not WP only) was replaced by hackers's index.php.

    I have submitted a ticket to HG support team again. Waiting...
    {{ DiscussionBoard.errors[4790069].message }}
    • Profile picture of the author Sarevok
      Originally Posted by motley View Post

      Guys, I'm tired of it!

      After I posted the last message here, the HG support team had scanned my account and removed all cr*p. It was three files in the CTR theme at one of my sites. I worked great after that.

      But today I was working with one of my sites when I got a 500 server error. I checked other sites and it was the same. I checked all directories at the public_html directory and found two wrong Heal.html and HeaL.html files in each of them. I removed them all and changed a password to my account. I helped a bit, but after a short time I was attacked again. This time ALL index.php files at ALL sites (not WP only) was replaced by hackers's index.php.

      I have submitted a ticket to HG support team again. Waiting...
      Did you scan your local computer with an up to date anti-virus? What scanner did you use?

      Is your server private or shared?

      When was the last time you downloaded/ran an executable file that someone made for you?
      {{ DiscussionBoard.errors[4790525].message }}
      • Profile picture of the author motley
        Originally Posted by Sarevok View Post

        Did you scan your local computer with an up to date anti-virus? What scanner did you use?

        Is your server private or shared?

        When was the last time you downloaded/ran an executable file that someone made for you?
        I a mac user, so I do not use any antivirus.

        Server - Hostgator Baby Plan - as many others warriors use.

        I don't run .exe files, cz I can't do it on my mac.
        {{ DiscussionBoard.errors[4790555].message }}
        • Profile picture of the author Sarevok
          Originally Posted by motley View Post

          I a mac user, so I do not use any antivirus.

          Server - Hostgator Baby Plan - as many others warriors use.

          I don't run .exe files, cz I can't do it on my mac.
          What version of Mac OS are you operating?
          {{ DiscussionBoard.errors[4790594].message }}
        • Profile picture of the author Sarevok
          Originally Posted by motley View Post

          I a mac user, so I do not use any antivirus.

          Server - Hostgator Baby Plan - as many others warriors use.

          I don't run .exe files, cz I can't do it on my mac.
          It's startling that you wouldn't have any anti-virus, using ANY Operating System.

          I recommend scanning your system at once!!
          {{ DiscussionBoard.errors[4790616].message }}
        • Profile picture of the author zapseo
          Originally Posted by motley View Post

          I a mac user, so I do not use any antivirus.

          Server - Hostgator Baby Plan - as many others warriors use.

          I don't run .exe files, cz I can't do it on my mac.
          The very first Mac virus I ever saw was back in the late 1980s -- it was in a little "NeXT" application that could give you a NeXT-like interface on the Mac.

          Guess where I saw it?

          You got it -- when I was working at Apple.

          ALL software and ALL computers are vulnerable.

          You need to get yourself educated if you think that simply by running a Mac (or any Apple product) you are immune from viruses.

          Live JoyFully!

          Judy
          {{ DiscussionBoard.errors[4790632].message }}
          • Profile picture of the author cobwab
            Hi,
            I had a few of my WP sites hacked.

            I use Hostgator and they fixed them all.

            I installed these WP Plugins:

            Antivirus
            bad-behavior
            limit-login-attempts
            sabre
            secure wordpress
            semisecure-login-reimagined
            wp-security-scan

            I also got rid of the Admin login on all my WP sites - why give a hacker 50% of your login information? It's a good idea to change your passwords every 6 months or so.

            I have not had a problem since I began using these plugins and I have over 50 WP sites.

            However, HG did manage to lose one of my WP sites. It just vanished and they had no backup and neither did I so you need a back up plugin which schedules backups.

            Using Limit-Login-attempts can be dangerous if you forget your password.
            {{ DiscussionBoard.errors[4790747].message }}
  • Profile picture of the author globalpro
    Did you ask, or did they say, where the hacker got in from?

    The reason I ask, is when it happened to me way back when, I asked where the exploit was at and they told me it was an outdated theme I was using on one of my sites.

    Removed the theme and never had any more issues.

    Thanks,

    John
    {{ DiscussionBoard.errors[4790385].message }}
    • Profile picture of the author motley
      Originally Posted by globalpro View Post

      Did you ask, or did they say, where the hacker got in from?

      The reason I ask, is when it happened to me way back when, I asked where the exploit was at and they told me it was an outdated theme I was using on one of my sites.

      Removed the theme and never had any more issues.

      Thanks,

      John
      Thanks for asking John

      Here is a quote from their scan report:
      /home/my_name/public_html/domain_name.com/wp-content/themes/ctr-theme/domain.php: Atomicorp.honeypot.hex.php.cpanel.d0mains.351.UNOF FICIAL FOUND
      /home/my_name/public_html/domain_name.com/wp-content/themes/ctr-theme/1mass.php: Atomicorp.honeypot.hex.php.cmdshell.iTSecTeam.257. UNOFFICIAL FOUND
      /home/my_name/public_html/domain_name.com/wp-content/themes/ctr-theme/404.php: HG.PHP.Shell.UNOFFICIAL FOUND
      That's all

      Update for today's issue: the unwanted html files appear again soon after removal. I have found a file by the name defaced_files with a list of all affected directories in the public_html directory. I have removed it.
      {{ DiscussionBoard.errors[4790545].message }}
  • Profile picture of the author zapseo
    I LOVE HostGator.
    They are great.
    However -- I differ with them on a few points.
    They will say what caused the hack (maybe) -- and send you off doing a lot of things which may or may not help.
    They run a script which may modify a ton of files -- and the last time I saw the result of that script -- it actually removed essential lines from a few files.

    I guess it's like "water damage" from when the firemen put out the fire in your house.

    The FIRST thing you should do when your site has been hacked is TAKE IT OFFLINE.

    How do you do that ?

    Put up an index.html file in your domain root directory that says something like "Down for maintenance. Thanks for visiting, and please come back!"

    I argue with HG that they should be the first to be notified. (but I understand).

    Because I'd rather you contact someone like me.

    Because HG runs their scripts and are worried about the security of their company, not so much the security of your account.

    So they won't necessarily spend the time to find out where your infection really started from.

    And, until that's done, your site continues to be vulnerable.

    When they run their scripts, however, they destroy evidence -- (they have a similar complaint about what people like me do, when cleaning up sites ... difference is ... I can preserve the evidence for them...)

    I haven't read the entire thread, but just wanted to give you a head's up on things.

    I've cleaned up many, many hacked sites -- and so has my business partner, Nathan Briggs. Many of them have been on hostgator. You can contact us if you need help. (I respond best to skype IM: nextday-copy -- yes, I also do copywriting...strange mix, I know ... LOL. When requesting a contact, please indicate why you want to establish contact with me, as I regularly do not accept contact requests without that information, and will block people that I have not had contact from within a certain period of time if no relationship has been started.)

    Live JoyFully!

    Judy
    {{ DiscussionBoard.errors[4790610].message }}
  • Profile picture of the author GracefulSwan
    Man that sucks. Try not to use dodgy looking scripts and templates.
    {{ DiscussionBoard.errors[4790611].message }}
  • Profile picture of the author spearce000
    If you have shared hosting, hackers could be getting in via another account on the server. Check your file permissions to make sure none are set to 777, then go through your access log to see if any php scripts are being triggered remotely. If so, block the IP address they're using. That's what I did when I had a similar problem a while back. If it happens again, change hosting company.
    {{ DiscussionBoard.errors[4790751].message }}
    • Profile picture of the author Don Luis
      Banned
      I use SFTP to connect to the remote server. Since then, my websites never suffered from hacking attacks or viruses.
      {{ DiscussionBoard.errors[4790945].message }}
  • Profile picture of the author zapseo
    Using Limit-Login-attempts can be dangerous if you forget your password.
    That's what that "forgot password?" thingie is for.

    Llimiting login attempts is a standard security method for all kinds of software. Don't let a minor inconvenience that can be easily overcome stop you from using it. (I can't speak specifically to the particular plugin.)

    But use something like RoboForm or LastPass so it will encourage you to use stronger passwords.

    @Don Luis -- that's a good start -- but it wouldn't help any of the people who had (or have) vulnerable copies of timthumb.php

    Live JoyFully!

    Judy
    {{ DiscussionBoard.errors[4790985].message }}
    • Profile picture of the author motley
      Originally Posted by Sarevok View Post

      What version of Mac OS are you operating?
      It's a Snow Leopard 10.6.8
      Originally Posted by zapseo View Post

      I LOVE HostGator.
      The FIRST thing you should do when your site has been hacked is TAKE IT OFFLINE.

      How do you do that ?

      Put up an index.html file in your domain root directory that says something like "Down for maintenance. Thanks for visiting, and please come back!"

      Judy
      I did it on some sites. But HG says I shouldn't do anything with my account while they work on it.

      Originally Posted by GracefulSwan View Post

      Man that sucks. Try not to use dodgy looking scripts and templates.
      I never use this kind of scripts.
      Originally Posted by Sarevok View Post

      It's startling that you wouldn't have any anti-virus, using ANY Operating System.

      I recommend scanning your system at once!!
      I have just scanned my computer with the MacKeeper twice. There is nothing wrong with it.
      Originally Posted by zapseo View Post

      The very first Mac virus I ever saw was back in the late 1980s -- it was in a little "NeXT" application that could give you a NeXT-like interface on the Mac.

      Guess where I saw it?

      You got it -- when I was working at Apple.

      ALL software and ALL computers are vulnerable.

      You need to get yourself educated if you think that simply by running a Mac (or any Apple product) you are immune from viruses.

      Live JoyFully!

      Judy
      Yes, I should educate myself a little bit more
      Originally Posted by cobwab View Post

      Hi,
      I had a few of my WP sites hacked.

      I use Hostgator and they fixed them all.

      I installed these WP Plugins:

      Antivirus
      bad-behavior
      limit-login-attempts
      sabre
      secure wordpress
      semisecure-login-reimagined
      wp-security-scan

      I also got rid of the Admin login on all my WP sites - why give a hacker 50% of your login information? It's a good idea to change your passwords every 6 months or so.

      I have not had a problem since I began using these plugins and I have over 50 WP sites.

      However, HG did manage to lose one of my WP sites. It just vanished and they had no backup and neither did I so you need a back up plugin which schedules backups.

      Using Limit-Login-attempts can be dangerous if you forget your password.
      Not only WP sites was affected. I have many WP, Prismotube and other sites. The index.php file was modified/replaced with the wrong one in every first-level directory of my public_html directory.
      Originally Posted by spearce000 View Post

      If you have shared hosting, hackers could be getting in via another account on the server. Check your file permissions to make sure none are set to 777, then go through your access log to see if any php scripts are being triggered remotely. If so, block the IP address they're using. That's what I did when I had a similar problem a while back. If it happens again, change hosting company.
      Some files at Prismotube sites have to be set to 777. Access log... Can I find it via Awstats?
      Originally Posted by Don Luis View Post

      I use SFTP to connect to the remote server. Since then, my websites never suffered from hacking attacks or viruses.
      Thanks for your suggestion. I'm thinking about it.
      {{ DiscussionBoard.errors[4791539].message }}
  • Profile picture of the author zapseo
    Quote:
    Originally Posted by zapseo
    I LOVE HostGator.
    The FIRST thing you should do when your site has been hacked is TAKE IT OFFLINE.

    How do you do that ?

    Put up an index.html file in your domain root directory that says something like "Down for maintenance. Thanks for visiting, and please come back!"

    Judy


    I did it on some sites. But HG says I shouldn't do anything with my account while they work on it.
    Ask them nicely, sweetly ...

    Tell them you don't want it on your conscience that your sites could be distributing malware to your visitors -- and, while you respect their need for you to not touch anything -- is there something that could be done that wouldn't interfere with their investigations that would make it possible for you to sleep well, because you know your visitors won't be infected with malware (to the best of your knowledge?) -- and ... isn't there something they can do ?

    (BTW -- another choice would be to use the ipdeny feature in cpanel. Or get someone to create the .htaccess for you. This way the HG sec guys can still work, but other visitors will not be able to access your site for the time being. I used ipdeny with a client recently because he had been infected for so long, I felt that changing the db credentials and wp login were important before opening them up to the world.)

    Edited to add:
    Incidentally, if you want to use SFTP, you need to have ssh enabled. If you have a reseller account, HG will charge you $10 (I think per year) per subaccount to enable ssh on your subaccounts. I personally recommend that people with many domains consider getting vps or dedicated -- prices have come down quite a bit.

    Live JoyFully!

    Judy
    {{ DiscussionBoard.errors[4792059].message }}
    • Profile picture of the author motley
      Originally Posted by zapseo View Post

      Incidentally, if you want to use SFTP, you need to have ssh enabled. If you have a reseller account, HG will charge you $10 (I think per year) per subaccount to enable ssh on your subaccounts. I personally recommend that people with many domains consider getting vps or dedicated -- prices have come down quite a bit.

      Live JoyFully!

      Judy
      Thank you Judy

      I consider to get a reseller account as you and HG recommend me. While scan is still running, my account is up again. HG says that "the earliest shell found in this round of defacements was uploaded through a compromised WordPress admin password". HG team changed all WP passwords in my account. I found out by myself earlier that my sites were attacked through some WP micro niche blogs using CTR Theme. I found modified or injected php files into the CTR Theme folders. Now I consider whether abandon this theme or continue using it. All these blogs were purchased from a popular at the WF niche blog creating service. All of them used the same password. As I mentioned above, all passes are changed.
      {{ DiscussionBoard.errors[4794789].message }}
      • Profile picture of the author Lloyd Buchinski
        Originally Posted by motley View Post

        HG says that "the earliest shell found in this round of defacements was uploaded through a compromised WordPress admin password". HG team changed all WP passwords in my account. I found out by myself earlier that my sites were attacked through some WP micro niche blogs using CTR Theme.
        Actually the title of your topic bothered me since I first saw it. Just read the thread to make sure, of course you now know that it wasn't your hosting that was hacked. It was your blog.

        You can edit that if you go to your original post and click on advanced edit.
        Signature

        Do something spectacular; be fulfilled. Then you can be your own hero. Prem Rawat

        The KimW WSO

        {{ DiscussionBoard.errors[4795447].message }}
  • Profile picture of the author Aubaine
    Sorry to hear about the trouble! I would definitely take it offline immediately and post a "Down for Maint." page. You don't want to have your customers/followers checking out your page and seeing that. That may spook some people. And definitely heed Judy's words, she is spot on from what my past experience is with HG/hacked sites.
    {{ DiscussionBoard.errors[4792124].message }}
  • Profile picture of the author Alex Kage
    Hostgator was recently hacked, at least some of their servers.
    {{ DiscussionBoard.errors[4792315].message }}
    • Profile picture of the author zapseo
      Originally Posted by Sparda View Post

      Hostgator was recently hacked, at least some of their servers.
      That would sure explain why this poor man has been without his sites working for 7 days after contacting HG!

      Large hosting companies make for juicy hacker targets..you get so much more for your efforts!

      Live JoyFully!

      Judy
      {{ DiscussionBoard.errors[4792344].message }}
  • Profile picture of the author anthony2
    I agree with changing your password on a regular basis.
    Also using letters, numbers and even using a least one
    capital letter in your password.
    Signature
    "I Leveled The Playing Field And Removed Every Roadblock
    To Helping You Make Maximum Profits In Minimum Time"
    Click Here Now To Find Out How!
    {{ DiscussionBoard.errors[4795181].message }}
  • Profile picture of the author williamtan
    The same thing happened to my Hostgator account previously. My main site index file was replaced with some terror__t related materials. Contacted HG and they were fast to recover a backup to put things back in order.

    Too be fair, the responsibility shouldn't be put onto HG. In fact, any account on a shared server might path the way for the hacker to enter. Or it can be just entry via the root access etc.

    Important thing here is - always backup your files.
    {{ DiscussionBoard.errors[4795217].message }}
  • Profile picture of the author londoncoffee
    When your host is secure again, take a look at http://www.websitedefender.com as it seems like a good free service. They also offer a free Secure Wordpress Plugin.
    {{ DiscussionBoard.errors[4795291].message }}
  • Profile picture of the author Doherty192
    Just have your host company run a sweep. Problem solved. Worked for me at hostgator anyway!
    {{ DiscussionBoard.errors[4795690].message }}
    • Profile picture of the author motley
      Originally Posted by Doherty192 View Post

      Just have your host company run a sweep. Problem solved. Worked for me at hostgator anyway!
      They have removed everything related to this attack. I hope - forever.
      {{ DiscussionBoard.errors[4795731].message }}
      • Profile picture of the author Lloyd Buchinski
        Originally Posted by motley View Post

        My hosting account was hacked through some of my blogs. Not a blog was hacked, but many blogs, html sites and script based sites at my account was affected. Hackers found a way to my account using week passwords, that I wasn't so clever to change after receiving a MNS pack.
        Sorry, guess I assumed too much or didn't read carefully enough. Good luck mopping up the mess.

        best wishes
        Signature

        Do something spectacular; be fulfilled. Then you can be your own hero. Prem Rawat

        The KimW WSO

        {{ DiscussionBoard.errors[4796383].message }}
        • Profile picture of the author motley
          Originally Posted by Lloyd Buchinski View Post

          Sorry, guess I assumed too much or didn't read carefully enough. Good luck mopping up the mess.

          best wishes
          Don't be sorry, you didn't say anything wrong

          And thank you for your wishes
          {{ DiscussionBoard.errors[4796492].message }}
  • Profile picture of the author TheHotChick
    Banned
    What would prevent this from happening in the future?
    {{ DiscussionBoard.errors[4796516].message }}

Trending Topics