• 101DreamVacations

    (@101dreamvacations)


    Around 11:30am our website went down, when it came back up there were some vulgar words appearing as a link but not an actual link on our mobile version. We contacted our host and installed a security program that we were told should take care of our problem. It did take off the words and everything seemed fine. On 4/18/2015 around 10:00pm I noticed a site page popping up on our website like it was a page that was part of our website that was a porn site, we called ipage (our host) and once we finally got through they noticed another problem, they called it a deny access attack where there was so much traffic hitting our site that we had been denied access. Once the fixed that problem they couldn’t find the other issue so they thought the security program found and fixed it. Ipage researched it and found no unusual or suspicious information. They could not find any IP address that would have done it. We hung up and then at around 12:11am CST our site was shut down again by what Ipage is calling a deny access attack again we called them they got our site up, looked for any clues as to who it may be that is doing this and found nothing. Around 3:00am CST we checked the site again and our homepage was bringing up a gay porn site. Once again we called Ipage and they fixed that and while they were fixing that they say our site immediately getting around 400 hits but they could not see where they were coming from or anything and the site was shut down again by too many hits within an hour.

    our site is http://www.101dreamvacations.com

Viewing 15 replies - 1 through 15 (of 20 total)
  • alexandre.gomiero

    (@alexandregomiero)

    Hi,
    I`m with the same problem at iPage (our host) and I have already to consider to buy the Site Lock offered by them.
    Ten websites administraded by me was infected and very poor technical information given by iPage, only a list of files infected (all of wordpress installed there).

    I think it is an isolated iPage problem, isn`t it?
    A lot of insistance to buying SiteLock looks like strange.

    Thread Starter 101DreamVacations

    (@101dreamvacations)

    I would think if that was the problem once we bought site lock from them you would think the problem would go away because they wouldn’t want me coming on forums and saying site lock didn’t fix my problem completely.

    Clayton James

    (@claytonjames)

    @101dreamvacations

    Just so we’re on the same page: You were already hacked before you purchased the SiteLock service, correct?

    Thread Starter 101DreamVacations

    (@101dreamvacations)

    yes.

    WPyogi

    (@wpyogi)

    Clayton James

    (@claytonjames)

    Which package did you purchase, and did it include removal of malware in the package subscription? If so, did that also include database inspection and repair and complete remediation of sites that are already compromised? If yes, then you may want to contact SiteLock support and see what they have to say.

    Other wise, it might be helpful if you review your site and ftp access logs for anything out of the ordinary. Or if iPage is managing it for you, then you need to crack a whip under them, because the ambiguous nature of the details (judging solely from the lack of details provided of course) surrounding the “fixes” they made for you is a bit distressing. There should be some factual account of what was changed/fixed in their analysis of the issue.

    Some additional reference material if you need it: You can run your URL through this service and examine the results. (although SiteLock may now prevent that service from working properly for you) http://sitecheck.sucuri.net/scanner/
    This should be a good starting point for general info: FAQ My site was hacked
    There are links to additional resources at the bottom of that article.
    Some additional frequently recommended resources to help you:
    http://wordpress.org/support/topic/268083#post-1065779
    http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/
    http://ottopress.com/2009/hacked-wordpress-backdoors/
    http://www.unmaskparasites.com/
    http://blog.sucuri.net/2012/03/wordpress-understanding-its-true-vulnerability.html
    And there is some great information in this article: Hardening WordPress

    Thread Starter 101DreamVacations

    (@101dreamvacations)

    We have the “fix” package. I contacted Ipage about what ports are open and they wouldn’t tell me, but they did disable the FTP.

    I will start going through all of this information. I am looking through everything on my site right now. Ton of information and I feel sick.

    Lazlo369

    (@lazlo369)

    Alexandre

    I had a similar problem with my site , hosted on Ipage( Cialis ad under the title) .
    I have removed a an encrypted code from the beginning of the functions.php file inside the theme.(It was a very obvious to see what needed to be taken out.)
    Now the ad is gone, but I am not sure if it is a permanent fix or not.
    I presume if the site is hacked it can happen again.
    Of course I do not know if you were hacked the same way, but it might be worth a try

    @lazlo369 please follow through the links posted by WPYogi.
    download files and run them through a Malware scanner. online service by name of virustotal works great for me

    seems quite weird that ipage is pushing to sell their sitelock service rather than securing their servers. for a normal wordpress website setup with correct file permissions, there is no need of a third party service to furthur secure your wordpress.

    Lazlo369

    (@lazlo369)

    Thanks Laliz
    I did read through the pages suggested by WPYogi, and find them very very informative. I have ran the scanners, didn’t find anything, reinstalled WordPress, no help.
    But, the fix I did to the function.php file worked and I am keeping my fingers crossed.

    Lazlo

    But, the fix I did to the function.php file worked and I am keeping my fingers crossed.

    you mean to say none of scanners caught this encrypted code in functions.php file?

    if you still have infected function.php file can you run it through
    https://www.virustotal.com/

    Lazlo369

    (@lazlo369)

    No, I used two scanners from the web and installed two scanners plugins.
    None of them showed anything.

    Hi, Ive been having the same problem. My website is also hosted by Ipage. The scanned it and told me to download infected.txt. Most of them were images which I deleted but there is one file functions.php from my theme. Exactly like Lazlo369 described, but in my case some rude words are displayed in the tagline and create a link to what I don’t know as I am not clicking on it.
    Does anyone know if it is safe to delete this functions.php file without affecting my website?
    Also I wonder whether Ipage actually infected or made it easier for hackers just so we have to buy this Sitelock software, which was the first thing they told me to do.
    Any advice I would appreciate. Thanks!

    Other than cleaning the phpfiles I assume you changed password of your users and check for hidden folders (e.g beginning with a .) where theyve managed to upload backdoors and what not.

    I recommend installing some form of two step authentication (google auth) for people with administrative rights on the blog.

    @cy93,

    Please create a new post. This one is over a month old is is not likely directly related to your issue.

Viewing 15 replies - 1 through 15 (of 20 total)
  • The topic ‘My site has been hacked’ is closed to new replies.