{"id":25956,"date":"2020-12-21T03:04:07","date_gmt":"2020-12-20T19:04:07","guid":{"rendered":"https:\/\/web.mwwsb.com.my\/pjci\/?post_type=kb&#038;p=25956"},"modified":"2022-09-08T21:41:39","modified_gmt":"2022-09-08T13:41:39","slug":"help-my-website-was-hacked","status":"publish","type":"kb","link":"https:\/\/www.casbay.com\/guide\/kb\/help-my-website-was-hacked","title":{"rendered":"Help, my website was hacked!"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"25956\" class=\"elementor elementor-25956\" data-elementor-post-type=\"kb\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-986eb12 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"986eb12\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3dfd540\" data-id=\"3dfd540\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4be5eb9 elementor-widget elementor-widget-heading\" data-id=\"4be5eb9\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-medium\">The most common reasons for a hacked (defaced) website include: <\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3873c54 elementor-widget elementor-widget-text-editor\" data-id=\"3873c54\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u2013\u00a0<strong>Outdated web application<\/strong>.<\/p><p>Every popular web application (Joomla, WordPress, PhpBB\u2026) has had security problems and that\u2019s why you have to use always the latest version.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5204570 elementor-widget elementor-widget-text-editor\" data-id=\"5204570\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u2013<strong>\u00a0Outdated web application extension<\/strong>.<\/p><p>If you have installed any third-party extensions, you have to keep them up-to-date just as you keep your main web application. Very often users neglect this fact and outdated extensions become easily exploited by intruders.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9c77665 elementor-widget elementor-widget-text-editor\" data-id=\"9c77665\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>\u2013\u00a0<strong>Weak\u00a0<\/strong><strong>user\/administrator<\/strong><strong>\u00a0passwords<\/strong>.<\/p><p>You must ensure that all users have strong passwords, especially the admin and the ones who can create content for your site. For this reason, make sure to have updated antivirus software and scan your computer for viruses regularly.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9215581 elementor-widget elementor-widget-text-editor\" data-id=\"9215581\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p><span class=\"word\">Please\u00a0<\/span><span class=\"word\">be\u00a0<\/span><span class=\"word\">sure\u00a0<\/span><span class=\"word\">that\u00a0<\/span><span class=\"word\">if\u00a0<\/span><span class=\"word\">your\u00a0<\/span><span class=\"word\">website\u00a0<\/span><span class=\"word\">has\u00a0<\/span><span class=\"word\">been\u00a0<\/span><span class=\"word\">hacked,\u00a0<\/span><span class=\"word\">it\u00a0<\/span><span class=\"word\">is\u00a0<\/span><span class=\"word\">not\u00a0<\/span><span class=\"word\">linked\u00a0<\/span><span class=\"word\">to\u00a0<\/span><span class=\"word\">server\u00a0<\/span><span class=\"word\">safety.<\/span>\u00a0Our servers have advanced security modules (such as Apache mod_security, Suhosin PHP hardening, PHP open_basedir protection and others).\u00a0 Which would most likely show, that the issue would lie in your website.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-91c2372 elementor-widget elementor-widget-image\" data-id=\"91c2372\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"873\" height=\"519\" src=\"https:\/\/www.casbay.com\/guide\/wp-content\/uploads\/2021\/02\/you-ve-been-hacked_a8c62ff4-6db8-11ea-9530-7febd198d354-e1608529169437.png\" class=\"attachment-full size-full wp-image-32378\" alt=\"Help, my website was hacked!\" srcset=\"https:\/\/www.casbay.com\/guide\/wp-content\/uploads\/2021\/02\/you-ve-been-hacked_a8c62ff4-6db8-11ea-9530-7febd198d354-e1608529169437.png 873w, https:\/\/www.casbay.com\/guide\/wp-content\/uploads\/2021\/02\/you-ve-been-hacked_a8c62ff4-6db8-11ea-9530-7febd198d354-e1608529169437-300x178.png 300w, https:\/\/www.casbay.com\/guide\/wp-content\/uploads\/2021\/02\/you-ve-been-hacked_a8c62ff4-6db8-11ea-9530-7febd198d354-e1608529169437-768x457.png 768w\" sizes=\"(max-width: 873px) 100vw, 873px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a688e62 elementor-widget elementor-widget-heading\" data-id=\"a688e62\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What do I do if my Website is Hacked?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d90138a elementor-widget elementor-widget-text-editor\" data-id=\"d90138a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>There are lots of various types of website hacks.\u00a0 Hacks can be malicious such as placing a virus on your website that your visitors may get. The hacks can also just change the text on your front page. It is extremely important to determine the hacking of your website, how it was hacked, and then how to restore the site to its status prior to the back.<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7f60166 elementor-widget elementor-widget-heading\" data-id=\"7f60166\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Has my website been hacked?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-384cdca elementor-widget elementor-widget-text-editor\" data-id=\"384cdca\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>Some website hacking is obvious, while others are more subtle.\u00a0 Signs that your website has been hacked:<\/p><ul><li><strong>The front page is &#8220;defaced.&#8221;<\/strong>\u00a0 When you visit your website, instead of your page there is a completely different page.\u00a0 Often these pages will have a &#8220;hacked by&#8230;.&#8221; message on them.<\/li><li><strong>No longer able to log in to any of your admin pages.<\/strong>\u00a0 This happens when you are having trouble logging into your CMS administrator login and your cPanel. So, it is possible that the hacking on your site was successful and the passwords were changed.<\/li><li><strong>Get a Google Warning when visiting your website.\u00a0 <\/strong>Google would scan all websites for malicious coding. When you visit your site through a Google search or in Firefox\/Chrome it will display a red warning page.<\/li><li><strong>The computer anti-virus software warns you when you visit your website.<\/strong> There is a virus or trojan that your website is attempting to install on your computer if your anti-virus warns you about it.<\/li><li><strong>A page that previously loaded now suddenly unable to load.<\/strong>\u00a0 This is less common. However, it could happen where a hacker has modified for example a database on your website that made the site no longer function properly. In this case, you may get a &#8220;can not connect to database&#8221; or similar message when loading a page.<\/li><\/ul><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9148ac5 elementor-widget elementor-widget-heading\" data-id=\"9148ac5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How do I scan my site for Malware?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-04c00cb elementor-widget elementor-widget-text-editor\" data-id=\"04c00cb\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>There are lots of tools available online. By using them, you can easily scan your website for malware\/exploits. Below is a few of the most popular:<\/p><ul><li><a href=\"http:\/\/www.avg.com.au\/resources\/web-page-scanner\/\" target=\"_blank\" rel=\"noopener\">AVG Online web page scanner<\/a><\/li><li><a href=\"http:\/\/webhostinghub.com\/sucuri\" target=\"_blank\" rel=\"noopener\" class=\"broken_link\">Sucuri<\/a><\/li><li><a href=\"http:\/\/scanurl.net\/\" target=\"_blank\" rel=\"noopener\">ScanUrl<\/a><\/li><\/ul><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5b805c7 elementor-widget elementor-widget-heading\" data-id=\"5b805c7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How was my website hacked?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e5f34f9 elementor-widget elementor-widget-text-editor\" data-id=\"e5f34f9\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>The more common methods used to hack websites include:<\/p><ul><li>Hacked cPanel or FTP password<\/li><li>Code injection &#8211;\u00a0<a href=\"http:\/\/en.wikipedia.org\/wiki\/Code_injection\" rel=\"noopener\">http:\/\/en.wikipedia.org\/wiki\/Code_injection<\/a><\/li><li>Remote File Inclusion &#8211;\u00a0<a href=\"http:\/\/en.wikipedia.org\/wiki\/Remote_File_Inclusion\" rel=\"noopener\">http:\/\/en.wikipedia.org\/wiki\/Remote_File_Inclusion<\/a><\/li><\/ul><p>If your password has been hacked, generally this will lead to your front page being &#8220;defaced&#8221;. This is because the hackers will upload their own index page.\u00a0 If you use software such as WordPress, ZenCart, or other programs, often time the hacks are done through an exploit in those programs.\u00a0 In many cases, if you use a CMS program the database will be hacked as well and you will need to restore it.\u00a0<\/p><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bc56871 elementor-widget elementor-widget-heading\" data-id=\"bc56871\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How do I fix my website that is hacked?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-00387b5 elementor-widget elementor-widget-text-editor\" data-id=\"00387b5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>It is difficult to give an exact method to resolve a hacking issue. This is due to there are many different types of website hacks. However, you can correct your website by:<\/p><ul><li><strong>Restoring the backup of your website.<\/strong>\u00a0 The easiest way is to restore your site from a version that you saved prior to the site being hacked. If you have the automated backup service, you will need to restore your own backup of your website. You can do this through the cPanel.<\/li><li><strong>Removing the coding from the .htaccess file. <\/strong>\u00a0Often, if the code injection has hacked the site, you will see a &#8220;re-direct&#8221; in your .htaccess file in your public_html folder.\u00a0 Then, open your .htaccess file and look for any lines of coding that look suspicious. After that, delete the suspicious lines of coding, and then save your changes.<\/li><\/ul><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8dc48df elementor-widget elementor-widget-heading\" data-id=\"8dc48df\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What should I do to prevent my site from being hacked?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-649f5b1 elementor-widget elementor-widget-text-editor\" data-id=\"649f5b1\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"item-page\"><p>Depending on the cause of the hack, there are some actions you can take to help prevent hacks in the future, which are by:<\/p><ul><li><strong>Updating Software\/Plugins:<\/strong> If you are running a CMS, such as Joomla, WordPress, or Drupal, I recommend checking to make sure you updated it and any plugins\/Addons as security exploits may have been fixed by the developers. You can <a href=\"https:\/\/www.webhostinghub.com\/help\/learn\/website\/wordpress-tutorials\/how-upgrade-wordpress-using-softaculous\" rel=\"noopener\">update most programs from Softaculous<\/a>, but plugins\/themes will differ in how they are updated. Therefore, I recommend following the developer&#8217;s instructions.<\/li><li><strong>Changing any passwords for your account.\u00a0 <\/strong>We recommend it to always be your first step. In case your passwords were compromised, change your cPanel password, any FTP account passwords. If you use WordPress or a CMS change that password as well.\u00a0<\/li><li><strong>Updating Programs running on your hosting account. <\/strong>If you use third-party software to build your sites, such as WordPress or Joomla, make sure you are using the most up to date version. This is because the security exploits may have been fixed by the developers.<\/li><li><strong>Updating Programs running on your computer. <\/strong>\u00a0Hackers are able to access data on your computer. Through some programs, such as Adobe&#8217;s Flash, which include vulnerabilities, they can do this easily. They then sniff around and find data, such as FTP usernames and passwords that are in some programs. Be sure that you keep all of your software up to date. This is because most developers often release security patches.<\/li><\/ul><\/div><div id=\"dtahryp_container\" class=\"main_comment_submission_div\">\u00a0<\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The most common reasons for a hacked (defaced) website include: \u2013\u00a0Outdated web application. Every popular web application (Joomla, WordPress, PhpBB\u2026) has had security problems and that\u2019s why you have to use always the latest version. \u2013\u00a0Outdated web application extension. If you have installed any third-party extensions, you have to keep them up-to-date just as you [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"site-sidebar-layout":"no-sidebar","site-content-layout":"page-builder","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-gradient":""}}},"kbtopic":[117],"kbtag":[106],"mkb_version":[],"_links":{"self":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/25956"}],"collection":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb"}],"about":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/types\/kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/comments?post=25956"}],"version-history":[{"count":7,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/25956\/revisions"}],"predecessor-version":[{"id":37297,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kb\/25956\/revisions\/37297"}],"wp:attachment":[{"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/media?parent=25956"}],"wp:term":[{"taxonomy":"kbtopic","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtopic?post=25956"},{"taxonomy":"kbtag","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/kbtag?post=25956"},{"taxonomy":"mkb_version","embeddable":true,"href":"https:\/\/www.casbay.com\/guide\/wp-json\/wp\/v2\/mkb_version?post=25956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}