I've Been Hacked - How Do I fix It and Keep It From Happening Again?

13 replies
  • WEB DESIGN
  • |
Help me warriors!

One of my websites michelada recipes has been hacked and a viagra link has been placed in my header. I have tried inspecting the element to find the location of the code but cannot seem to locate it. It is hard to find because when I log in to my dashboard the links is no longer visible to me. If someone could please help me I would be eternally great-full. This site was seeing some good traffic and income but Google has dropped the site due to the hack.

Also,

How do I keep this from happening again? How did they hack my login?

Thanks
#fix #hacked #happening #help a newbie #wordpress
  • Profile picture of the author nhoudek
    Ok so here is what i've found out...

    My site was not hacked, I installed a hacked theme. Wordpress no longer carried my theme so I looked elsewhere for it. Once I changed the theme everything was good.

    Well not everything. Now I need to find another theme. I need an easily customize-able simlple theme.

    Any suggestions?
    {{ DiscussionBoard.errors[9356132].message }}
  • Profile picture of the author nhoudek
    Did you get the theme from the warez sites?
    the theme was Basic Simplicity. I downloaded it from the name.com site because it is no longer maintained in wordpress. That should have been a warning sign.

    I didn't want to mention the theme but I thought it would be best to warn anyone that is still using it.

    Anyhow, you'll find many simple, minimalistic free themes on https://wordpress.org/themes/search.php?q=minimalistic,
    Thanks!
    {{ DiscussionBoard.errors[9356406].message }}
  • Profile picture of the author Ekushey
    I see, this theme wasn't updated in a long time, and the hackers found an vulnerability in and exploited it to inject the spammy links on the to the site.

    Try using a theme that is widely used and made by an active developer to avoid this sort of problems in the future. Also, I'd suggest deleting the theme complete from your site instead of just keeping it disabled.
    Signature

    I'll solve your PHP, MySQL, WordPress or any website or server related problems.
    Hire me on Freelancer.com at an affordable rate with fast turnaround time.

    {{ DiscussionBoard.errors[9356419].message }}
    • Profile picture of the author nhoudek
      Will do. And it is already deleted.
      {{ DiscussionBoard.errors[9356492].message }}
      • Profile picture of the author pphillips001
        You should always browse through the source of third party WP themes. If there is anything dodgy-looking, then it usually sticks out like a sore thumb.

        Hope you get it sorted soon.

        Regards

        Paul
        {{ DiscussionBoard.errors[9356731].message }}
  • Profile picture of the author Soluweb
    Theme forest is a good option if you are looking for good options. By the way in order to avoid possible hackers in the future you must updated your CMS (Wordpress) constantly.
    {{ DiscussionBoard.errors[9357143].message }}
  • Profile picture of the author Charli
    I downloaded a GNU template and then I used this tool: Meta Tag Analyzer

    Discovered it was littered with male-ware. The plugin I used to search for malware did not detect it since it was imbedded deep within the template. I had 2 wordpress experts on Fiverr look at it and they couldn't figure it out. Had I not just checked the health of the website, I would have never known.

    By the way, my boss installed a plug-in and was dormant for a time. Then suddenly, it redirected his pages to a porn site. Just be careful what you install and check it against something, anything just to make sure it's okay.

    Charli
    {{ DiscussionBoard.errors[9357179].message }}
    • Profile picture of the author nhoudek
      I downloaded a GNU template and then I used this tool: Meta Tag Analyzer

      Discovered it was littered with male-ware. The plugin I used to search for malware did not detect it since it was imbedded deep within the template. I had 2 wordpress experts on Fiverr look at it and they couldn't figure it out. Had I not just checked the health of the website, I would have never known.
      Used the tool and no issues were found after updating the theme and deleting the old one. Theme is just temporary still looking

      Thanks!
      {{ DiscussionBoard.errors[9357295].message }}
  • Profile picture of the author Tywest01
    Also, you really need security installed on any Wordpress site because of their many vulnerabilities. After my last hacking incident, I installed three overlapping security plugins:

    Bulletproof Security
    Wordfence
    IThemes Security

    Give at least one of them a try.
    {{ DiscussionBoard.errors[9358036].message }}
  • Profile picture of the author WPExpert
    Originally Posted by nhoudek View Post

    How do I keep this from happening again? How did they hack my login?
    The biggest problem with trying to unhack your website is that the infection or code-injection or whatever it is that is the root of the problem, may well not have come from your website in the first place.

    And cheap shared hosting providers now regularly take the least cost route and simply block you from access until you get fed up with their endless and pointless automatic emails, and just drift away.

    Then they can wipe their hard disk and start again with a new piece of Internet real estate.

    The secret is to get someone who knows how to protect your site for you and avoid the issue in the first place.

    Sooner or later you will either learn how or find someone you can trust.

    Terence.
    Signature
    Sales & Marketing Websites | QloudPressâ„¢ - When Your Website Is Mission-Critical
    {{ DiscussionBoard.errors[9366886].message }}
  • Profile picture of the author nickrap13
    Do u keep backups of your sites often???

    If not, better do it.....
    Signature
    {{ DiscussionBoard.errors[9366925].message }}

Trending Topics