Website hack
-
I got this email warning from Wordfence:
A user with username “username removed” who has administrator access signed in to your WordPress site.
User IP: 179.60.149.104
User hostname: 179.60.149.104
User location: Managua, NicaraguaI then got this email warning from Wordfence:
A user with username “username removed” deactivated Wordfence on your WordPress site.
User IP: 179.60.149.104
User hostname: 179.60.149.104
User location: Managua, NicaraguaThe username was correct (I have removed it) but I live in the UK. I do not know how they found my password – it was a “strong” password suggested by WordPress, 15 randon digits.
They managed to hack my site so the home page showe a fake Cloudfare screen instructing the users to “prove their credentials” by going through a process which would download a malicious file onto their computer. I could not access any page on my website and I could not login to the control panel
The way that I found to restore my website was to rename the Wordfence file in the plugins folder using Filezilla. So the malicious code was “hidden” in the Wordfence folder.
When I regained control I found that there was an update to Wordfence which I installed. My website seems to be working OK now
I have changed passwords and am now using 2FA
Has anybody else suffered from this hack?
Have I done enough to subvert it or am i still vulnerable?
The page I need help with: [log in to see the link]
You must be logged in to reply to this topic.