Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Our Wordpress Site Has Been Hacked

Featured Replies

Our WordPress site has been hacked.... and our original designer has disappeared.

Any budget minded Guru available to assist?

See: www.gostudyaustralia.co.th

You have your FTP and mySQL details right?

And a DB backup?

as bangkockney said, the above is necessary, as well as a backup of the files themselves if the site was using modified files or a custom theme.

administration panel and/or SSH login details would also be useful.

Those sql injections can be pure evil. Did you update to the latest wp?

PM me if you need assistance. I work on wp, but not 100% guru like other 12 year olds . I have a few wp sites online.

Those sql injections can be pure evil. Did you update to the latest wp?

PM me if you need assistance. I work on wp, but not 100% guru like other 12 year olds . I have a few wp sites online.

at least SQL injections are easy to fix and fend off!

ftp password spying is more common these days

  • Author

You have your FTP and mySQL details right?

And a DB backup?

Have all the original accessible from the server. Latest WP has been installed. I had no involvement in the setting up of this site and designer cannot be located. Believe I can FTP.

See if your host can restore is first step ... Then if so change all passwords and make sure everything is up to date.

  • Author

See if your host can restore is first step ... Then if so change all passwords and make sure everything is up to date.

Had server delete account and then restored from a backup of 1 month ago. Situation remains the same.

Yeah to restore the backup would be a quick solution but if you dont have it just export the content, import to a new WP installation and install new theme.

I can help fix if needed but not tonight. If still problems send me a message and with the access details can sort the issue tomorrow.

Host lots of wordpress sites and maintain around 20 web servers, this is all second nature.

Latest WP has been installed.

I dont think so:

meta name="generator" content="WordPress 3.3.1"

I cant see anything very serious with this. Just delete the content of the hacked page from the back-end, point the front page to whatever it used to be and do all the updates that Wordpress warns you about so clearly (how come people cant see these?). Then see what happens.

Signed: your friendly neighbourhood 12 year old.

See if your host can restore is first step ... Then if so change all passwords and make sure everything is up to date.

Had server delete account and then restored from a backup of 1 month ago. Situation remains the same.
Then you've got something installed that has known vulnerabilities.

Deactivate any third party plugins and custom code.

Deactivate until they have resolved the issue with the hack that has occurred, once it has been sorted reactivate.

This is part of an email I received from my web host today.


There is currently a global, distributed effort to attack WordPress
websites with low quality administrator passwords. This attack is highly
organised, using over 90,000 IP addresses in an attempt to guess the
administrator password for WordPress sites, and the attacks are
affecting web hosts right around the world. xxxxxx is deploying
a series of counter-measures to help protect our customers against
these attacks. However, due to the nature of the attacks, the best
course of action is for customers to ensure their WordPress sites are up
to date, have strong admin passwords and incorporate some additional
form of security to protect their site's admin section.


As the first important step in protecting your site, we encourage you
to ensure your WordPress admin password is one that conforms to the
strong password guidelines provided by WordPress.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.