krokonoster
Member
Posted 2 years ago #
I got hacked (by some Hammad) twice in the past week (Landing page replaced with some obscure page with arab writing).
Not sure where to look for a solution. My Host? (Who is rubbish by the way, and about to be replaced). WordPress?
Can only hope the hacker did not get my wp-config, use my password, into my database and did things there also.
Any advice / tips?
gestroud
Member
Posted 2 years ago #
Delete and replace all WordPress files and folders EXCEPT wp-config and wp-content.
Change ALL of your passwords.
Look into using some security plugins.
http://wordpress.org/extend/plugins/exploit-scanner/
http://wordpress.org/extend/plugins/wp-security-scan/
http://wordpress.org/extend/plugins/wp-ban/
Add an index file to any folder that does not have an index file of any type. index.html or index.php should work.
Read this article
http://codex.wordpress.org/Hardening_WordPress