Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Sedo.com

Been Hacked! Need Help!

Status
Not open for further replies.

Gerry

Dances With Dogs
Legacy Exclusive Member
Joined
Dec 3, 2006
Messages
14,985
Reaction score
1,302
Example of hacked site/page:

ceuq dot com/KinG.htm

This is appearing on other sites of mine.

Is this something that had been set in the themes downloaded? Is it in the server?

I need to get rid of these.

Any help is widely appreciated.
 

Johnn

Level 14
Legacy Exclusive Member
Joined
Apr 13, 2004
Messages
15,997
Reaction score
1,415
There are some free themes from WP would trigger the hack too. Do you rent the dedicated server or VPS or just suscribe to hosting plan?

PM me the info if you don't want to post here.
 

Bill F.

Level 4
Legacy Platinum Member
Joined
May 28, 2008
Messages
207
Reaction score
34
Download all the site files, and then search through them. First, for the obvious (what you can see), and then for altered php code (more difficult, and look for anything encrypted). And, of course, change your passwords - not just on this site, but on all sites.
Besides the themes, plug-ins can carry hacks, but they are usually less obvious than this one, and place spam links on your site.
Did you visit your hacker's Facebook page. Very generous of him to leave a calling card.
 

Johnn

Level 14
Legacy Exclusive Member
Joined
Apr 13, 2004
Messages
15,997
Reaction score
1,415
I would not recommend to download them to your PC.
Use Cpanel and check all the files and FOLDERS - The recent date should tell you what files/folders have been recently created/uploaded.

Agreed on changing the passwords.
Download all the site files, and then search through them. First, for the obvious (what you can see), and then for altered php code (more difficult, and look for anything encrypted). And, of course, change your passwords - not just on this site, but on all sites.
Besides the themes, plug-ins can carry hacks, but they are usually less obvious than this one, and place spam links on your site.
Did you visit your hacker's Facebook page. Very generous of him to leave a calling card.
 

Shane

Account Terminated
Legacy Platinum Member
Joined
Jul 6, 2012
Messages
1,720
Reaction score
354
Gerry I had the same problem a month of two ago. It's probably a security issue with one of your wordpress plugins. I was actually unable to removed the files so I had to wipe the entire server and start from scratch.
 

whitebark

Level 9
Legacy Platinum Member
Joined
Jul 9, 2006
Messages
3,026
Reaction score
26
There are other sites on your same shared hosting that are hosting nasties like JS/Obfuscus.AACB that don't appear to be your websites so it very well may be the entire account.

Whats lunar pages got to say about it?
 

chipmeade

Level 7
Legacy Exclusive Member
Joined
Mar 13, 2007
Messages
943
Reaction score
137
Look for hacked php commands in your wp folders. It is a big pain in the ass. You will need to check all the sites that you are hosting on that server. Not only on one affected.
 

Gerry

Dances With Dogs
Legacy Exclusive Member
Joined
Dec 3, 2006
Messages
14,985
Reaction score
1,302
Lunar Pages is the host, shared hosting. I am not going to like this at all. I am taking three classes and barely have time for them.

Pissy situation.
 

vinsdomains.com

Level 6
Legacy Platinum Member
Joined
Feb 21, 2012
Messages
517
Reaction score
109
Happened to me a couple months back and it was a number of php files that were altered. While the edit dates on the files made it clear which were touched, I decided to use my hosts backups and delete/reinstall all from the day before my hack. Crazy thing was it was over a dozen of my sites at once and I do suspect it was a plugin that let him in. I must say, I felt violated! Anyway, best of luck and back up often, including databases!
 

Gerry

Dances With Dogs
Legacy Exclusive Member
Joined
Dec 3, 2006
Messages
14,985
Reaction score
1,302
Okay, it appears NOT to be in the Server or cPanel of my host.

TroutFish dot org was a site project loaded but not developed yet. The page TroutFish dot org/KinG.htm does not exist.

The same is true for eComputes.com. No page extension like that exists as nothing has been done.

So it must be a malicious file in an add-on or actually embedded in some themes I've been using.
 

katherine

Country hopper
Legacy Exclusive Member
Joined
Jul 9, 2005
Messages
8,428
Reaction score
1,290
Probably a vulnerable wordpress plugin. Make sure is everything is up to date.
And restore from a backup perhaps. A backdoor might be left somewhere.
 

Gerry

Dances With Dogs
Legacy Exclusive Member
Joined
Dec 3, 2006
Messages
14,985
Reaction score
1,302
Probably a vulnerable wordpress plugin. Make sure is everything is up to date.
And restore from a backup perhaps. A backdoor might be left somewhere.
I do have a couple of sites with minimal plugins. I'll delete to see if the KinG.htm page disappears.

I am also suspicious of some of the themes I use being free. To be quite honest, that is where my strongest suspicion is.
 

Makis77

Level 8
Legacy Exclusive Member
Joined
Sep 22, 2006
Messages
1,021
Reaction score
22
#
 
Last edited:

Gerry

Dances With Dogs
Legacy Exclusive Member
Joined
Dec 3, 2006
Messages
14,985
Reaction score
1,302
After hours of looking inside templates for the files, I finally found the attachment.

I was wrong. It is installed in the cPanel. I have no idea how these installs got there but I have notified LunarPages. I had checked cPanel previously but never saw the file until I doublechecked again.

Okay, several hours wasted that I should have dedicated to studying.

Larger image:
 

Attachments

  • Picture1.jpg
    13.5 KB · Views: 56
Last edited:

EM @MAJ.com

Visit MAJ.com for domain forsale.
Legacy Exclusive Member
Joined
Sep 10, 2002
Messages
5,834
Reaction score
75
Hi Gerry,
How things going for you?

Hope your site is back up.
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members Online

Sedo - it.com Premiums

IT.com

Premium Members

MariaBuy

Our Mods' Businesses

UrlPick.com

*the exceptional businesses of our esteemed moderators

Top Bottom