WordPress.org

Forums

[resolved] Web site hacked (5 posts)

  1. okeeffe.e
    Member
    Posted 1 year ago #

    My website seems to be hacked. A link to a facebook page of a toy retailer appears on every page of my website:

    http://www.eoinokeeffearchitects.com

    The link appears as "Mytoys Gutschein"

    I have tried to locate and remove the hack for the last 24 hours, with not luck!

    Please help!

    Thank you.

  2. Jesin A
    Member
    Posted 1 year ago #

    Hackers who add such links don't do it in plain text they either use base64_decode() or strrev() along with eval().

    First change all your passwords and switch your theme to Twenty Thirteen or Fourteen. See if the link disappears. If it does search for any of these functions in the elegentWhite files.

    If you can't find any such code in the theme files deactivate all plugins. If you still get these links go to dashboard > Updates and click the "Re-install Now" button. This will overwrite existing core files so that any files that were modified by the hacker are undone.

    I suspect this to be the work of a plugin which is hooking into the the_title filter to show links under every post title.

    Looking in the HTML code I also find two more links and some CSS to hide this with absolute positioning.

  3. okeeffe.e
    Member
    Posted 1 year ago #

    Jesin, Thanks a million! That found the hack, in one of the plug ins which is now deleted.

    I really appreciate you help!

  4. Jesin A
    Member
    Posted 1 year ago #

    Great to hear that!!

    Make sure you install plugins only from trusted sources. If it is a premium plugin you should pay for it and get it only from the official site.

    There are many sites which give away premium plugins for free at the cost of embedded hidden links or even worse backdoors.

    Can you share the name of the plugin so that others would also stay away from it.

    Also mark this topic as resolved.

  5. okeeffe.e
    Member
    Posted 1 year ago #

    Topic resolved.

    I'll check the plug in name and revert with it.

Topic Closed

This topic has been closed to new replies.

About this Topic