![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
Think I've Been Hacked - Need Help & Advice
So I think one of my websites has been hacked.
When you go to the home URL it opens some random site that's not mine which then redirects about 4 times before finishing on a random advert that changes each time. I can still login via FTP and everything seems normal there. Other sites I run hosted on the same server are unaffected. The site runs on Wordpress. What is the quickest and easiest way to locate the hack and remove it? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
It seems like it's something to do with a domain hack rather than server side. I initially thought my domain had expired but there is a year to run yet.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
🚨 PBBC International 🚨
Industry Role:
Join Date: Apr 2010
Location: /👁\
Posts: 9,932
|
Burn everything and salt the earth. Only then will you be cleansed of the evil that has cursed you.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
VIP
Industry Role:
Join Date: Jul 2013
Posts: 22,112
|
First thing, change all the passwords (vps, login into site et cetera).
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Step 1
Delete wordpress Step 2 That's it. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
Confirmed User
Industry Role:
Join Date: Feb 2005
Posts: 1,699
|
Quote:
Is it happening due to javascript being injected in your hompage (check the HTML of the page), or because of a hacked .htaccess file? Once you figure out how the redirect is happening, you can try and figure out what is causing it and plan how to deal with it. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
Quote:
I just did a who.is on the domain and it's still showing my details but the site status shows as inactive whatever that means. I have looked through a few files (index.php, home.php, footer.php) and can't find anything strange. Also, all the files (within the themes folder) all show as last modified at some point last year. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
This is the first page that loads hstraffa.com
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
Is it domain name injection?
Looking though my pages on Google I have come across a Russian page within the /videos folder. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
Now found 30 of the damn Ruskie pages.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Friends of Venus founder
Industry Role:
Join Date: Jul 2010
Posts: 1,965
|
which .htaccess file? You should have one in your wp-admin folder that only allows your IP.
__________________
Email: freedom6995 . protonmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
So, from the looks of it all these pages that have been created are from the same folder /video directory.
I thought, sweet delete the directory and problem solved. The trouble is I can't find this directory through FTP so I can only presume it's a category?? Does anyone know how to view categories in phpmyadmin so I can delete this /video folder. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Friends of Venus founder
Industry Role:
Join Date: Jul 2010
Posts: 1,965
|
Quote:
Order allow,deny Allow from (your IP here)
__________________
Email: freedom6995 . protonmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Quote:
Code:
<IfModule mod_rewrite.c> RewriteEngine on RewriteCond %{REQUEST_URI} ^(.*)?wp-login\.php(.*)$ [OR] RewriteCond %{REQUEST_URI} ^(.*)?wp-admin$ RewriteCond %{REMOTE_ADDR} !^123\.123\.123\.123$ RewriteRule ^(.*)$ - [R=403,L] </IfModule> |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Confirmed User
Industry Role:
Join Date: Jan 2013
Posts: 566
|
These guys always place backdoors. scan your server with https://ispprotect.com/ if it's a linux box.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Confirmed User
Industry Role:
Join Date: Feb 2005
Posts: 1,699
|
Quote:
https://codex.wordpress.org/WordPress_Taxonomy |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Friends of Venus founder
Industry Role:
Join Date: Jul 2010
Posts: 1,965
|
Only need to ftp in to set that up. Good place to start...
__________________
Email: freedom6995 . protonmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
Still need help.
The content generated that is probably causing the issue is from a directory called "video" however I can find no video directory using FTP. I then thought maybe it's a video category but I can't find one of them either. I have even gone into phpmyadmin and been through all the posts and I can't find any of the posts Google says I have. Anyone any ideas? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 | |
StraightBro
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,232
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Friends of Venus founder
Industry Role:
Join Date: Jul 2010
Posts: 1,965
|
Backup? Wtf is a backup?
__________________
Email: freedom6995 . protonmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
So Fucking Banned
Industry Role:
Join Date: Jul 2016
Posts: 4,613
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |