December 28, 201411 yr Hi All, I don't usually use Wordpress and it seems that my clients website has been hacked and blacklisted by Google (see below email). Does anyone know what to do when your site is riddled with viruses/malware etc? Is there a way to recover it? The back up I have is ancient, and I am very reluctant to use it unless I have to... Subject: Malware notification regarding phoenixayahuasca.com Dear site owner or webmaster of phoenixayahuasca.com, We recently discovered that some of your pages can cause users to be infected with malicious software. We have begun showing a warning page to users who visit these pages by clicking a search result on Google.com. Below are some example URLs on your site which can cause users to be infected (space inserted to prevent accidental clicking in case your mail client auto-links URLs): http://phoenixayahuasca .com/http://www.phoenixayahuasca .com/ Here is a link to a sample warning page:http://www.google.com/interstitial?url=http%3A//phoenixayahuasca.com/ We strongly encourage you to investigate this immediately to protect your visitors. Although some sites intentionally distribute malicious software, in many cases the webmaster is unaware because: 1) the site was compromised2) the site doesn't monitor for malicious user-contributed content3) the site displays content from an ad network that has a malicious advertiser If your site was compromised, it's important to not only remove the malicious (and usually hidden) content from your pages, but to also identify and fix the vulnerability. We suggest contacting your hosting provider if you are unsure of how to proceed. StopBadware also has a resource page for securing compromised sites:http://www.stopbadware.org/home/security Once you've secured your site, you can request that the warning be removed by visitinghttp://www.google.com/support/webmasters/bin/answer.py?answer=45432and requesting a review. If your site is no longer harmful to users, we will remove the warning. Sincerely, Google Search Quality Team
December 28, 201411 yr Check their plugins etc for known issues and make sure they are up to date Most the time it was because of files that have been injected into the server, so the first thing I would do is to do a backup of the whole site, including the database, then I would draw out the database and template on the server setting them aside, lastly to would delete the whole lot. Next job would be to try to make sure this would not happen again, change all passwords, including the database, I would use a very exaggerated and long password for the database and server in order to prevent hacking techniques like rainbow tables. Then upload a fresh copy of Wordpress and re-integrate the template and database, if the issues still exists I would look into the database for rogue code and remove it. If after all that there are still issues, they still have access to the server and it may be a host problem so you need to either change or have words with them, but not before checking the server records and double checking the plugins, - to check the plugins I would uninstall them all for a month, if nothing happens I would re activate one at a time.
December 28, 201411 yr To add to the response above try and avoid plugins on WP too unless you can absolutely guarantee their quality. Poorly written plugins are what can make WP insecure, and everything a plugin does you can do yourself. Not saying never use them, but be very selective on the ones you do.
January 14, 201511 yr Definitely install a security plugin such as iThemes Security to prevent this from happening in future. Being widely used, WordPress sites are common targets for hackers.
Create an account or sign in to comment