I think my WordPress got hacked

9 replies
So last week I was checking out comments on my Wordpress account when I started getting weird comments that were just jibberish. I received 5 of these and I sent them to my spam folder. Then two nights ago my website was acting funny. The You tube video didn't load, some of my links didn't work, and one of my links changed the font size on the screen when it tried to load.

It works now, but I'm wondering, do these hackers go in and mess up my site for a while and then restore it to normal?
#hacked #wordpress
  • Profile picture of the author Sergiu FUNIERU
    Some of the things you described happened to me also. Although I have the latest WordPress version, I still receive some strange comments, totally unrelated to my blog's content.

    If the css file doesn't load fast enough, you might see no colors, strange colors, different font sizes and so on.

    I've never heard of hackers who will restore what they changed , but I'd be concerned only if the site wasn't working for more than 3 days in a row.

    Sergiu FUNIERU
    {{ DiscussionBoard.errors[3156822].message }}
    • Profile picture of the author eccentric
      hi wardo74,

      Recently i happened to visit a website where i got this information related to your query:

      "A number of blogs using the popular WordPress platform have reportedly been targeted in the ongoing cyber offensive recently. The websites hosted by different providers have been affected; these include Bluehost, GoDaddy, DreamHost and Media Temple. Besides, some other management systems based on PHP have also been targeted by hackers (Zen Cart eCommerce, for example).

      The targeted WordPress websites were infected with specific scripts that apart from installing malware on the systems also prevent Google Chrome and Firefox browsers (in one word - those using Safe Browsing API from Google) from sounding a warning if user tries to access the site. The way it works is when the search bot designed by Google meets an infected page, it responds by just returning the malicious code. This masking strategy uses the browser switch which is usually used by designers to return the specific code to meet the requirements of functional variations in various browsers, including Firefox and IE.

      5 Steps to Secure a WordPress Blog or Website

      Hacking the WordPress blog or website can reduce to zero all money and efforts spent to make it attractive, popular and good-working. That is why security is the prior aspect of online resource maintenance. The following tips will help to gain appropriate security.

      1. Constantly Update your WordPress Package
      Web-based software always contains bugs that can be used by hackers as a hole in your security. WordPress programmers constantly improve their products, fixing various vulnerabilities and code shortcomings. Keep abreast of the updates and use the latest version of web-based software for creating websites - it will help to avoid various attacks. The latest versions of WordPress contain optional automatic update feature. Use it to be up-to-date.
      2. Only Strong Passwords!
      Don't forget to change the user password in your WP account for something unique and difficult for repeating. Don't use your personal information like name or birth date, try to make up a combination of symbols not connected with some exact facts or people. And it is useful to change the password regularly - every half year or so. You can use some programs that will help to generate unique strong passwords regularly.
      3. Use Secret Keys in your WP-Config File
      Adding a secret key to wp-config.php file is obviously helpful thing that protects your configuration settings from unauthorized modifying. This file contains information like MySQL database name address and password - a key access data that is worth protection, if you don't want your website or blog to be hacked or stolen.
      4. Use Htaccess for Limiting the Access
      .htaccess file allows setting the access rights to various directories. With the help of it you can limit the access to your website folders. You can even set the IP address from which the information can be accessed. For more 'how to' explanations visit AskApache tutorial.
      5. Control the File Permissions
      Sometimes the default permissions set during WordPress installation or in accordance with hosting requirements are not acceptable in terms of security. That is why you need to check them manually and change via FTP client or in the admin panel of your hosting. To find out what is acceptable or not, look through the WordPress Codex."


      Hope this helps!

      Eccentric
      {{ DiscussionBoard.errors[3156892].message }}
  • Profile picture of the author wardo74
    eccentric,

    Thanks for the info. I will definately be doing that!

    Ward
    {{ DiscussionBoard.errors[3162692].message }}
    • Profile picture of the author hilaryaustin
      if you are still doubting that someone knows your password you better change it right away. Just to be safe update your wordpress with the latest wordpress version. And regarding the new password think of something unique and something strong.
      {{ DiscussionBoard.errors[3162803].message }}
    • Profile picture of the author eccentric
      Originally Posted by wardo74 View Post

      eccentric,

      Thanks for the info. I will definately be doing that!

      Ward
      You're more than welcome

      Cheers,
      Eccentric
      {{ DiscussionBoard.errors[3169453].message }}
      • Profile picture of the author wtatlas
        Hello,

        The unrelated comments are probably just spam. I get them all the time. As L D Carter said above they're just from a lot of idiots trying to get backlinks. I often get 20 at a time saying something like "What a wonderful insightful post" and they're left on my Privacy Policy page!

        One thing I would add to the post about securing your WordPress blog is to make a back up of everything on your site regularly. Then if the worst comes to the worst you can simply replace the whole site.
        Signature

        {{ DiscussionBoard.errors[3169526].message }}
  • Profile picture of the author Lazy
    Here's a link to the 500 most common passwords on the internet. Make sure yours isn't one of them:

    What’s My Pass? » The Top 500 Worst Passwords of All Time
    Signature
    WARRIORS ONLY: Get up to 100,000 verified high PR backlinks as soon as tomorrow! RAVE REVIEWS!

    {{ DiscussionBoard.errors[3162817].message }}
  • Profile picture of the author Manuelcrc
    I also see those very unrelated comments...and they get deleted
    Signature

    [B]Get free resources for Entrepreneurs and Startups.

    Check out our collection of Product and Business Reviews?

    {{ DiscussionBoard.errors[3162871].message }}

Trending Topics