Site hacked

goalseeker

Premium Member
Premium Member
Joined
Dec 12, 2019
Messages
33
Reaction score
60
Hi, I hope someone can help and give me some pearls of wisdom! Over the last ten years, I have built and managed a website for a small Association of European Counsellors. I have been lucky as the site has existed this long with no trouble to speak of. However, just over a week ago the site was hacked into and malware spread across files and databases and I am faced with trying to get rid of the malware completely closing all the back doors I can, ( I am unsure what a back door is). I may have a doctorate in Marketing and Sales but it was achieved before there was an Internet, I should say I am now 79. The Association has no money it ticks over from year to year in the true meaning of not-for-profit. There is not a member who is computer literate to help me and I am totally self-taught. For goodness sake I used a typewriter and pen and ink, if we went Tik-Tok it was because the clock was too loud!

Does anyone know where I can turn to? To have the site cleaned completely. I say completely because I know if I leave even one piece of spurious coding I am inviting the hacker back in. I know the site cannot be made 100% secure but I believe there are ways to secure it as much as possible. I have read the details from a number of companies who will clean the site but their fees are way too high for the association. I think the members believe I can do it myself. I cannot even get at the login screen and I do not know how to get around that but I understand it is possible.

I have used WordPress as a platform and Hostgator as a hosting company. Hostgator will only introduce me to a third party who will clean the site but in addition to their high one-off fee, they want an annual subscription to their service.

The income raised by the association pays for a part-time administrator and the rest of the officers including me offer their services on a voluntary basis. If anyone has any ideas how I may solve this problem any advice will be greatly appreciated.

Kind regards
 
You need a professional, they will find it and plug the exploit

But if you need to start yourself there are exploit scanning websites.

I googled this one Full Site Scan
Website Scanner Online - Find Site Vulnerabilities Fast

Wordpress Exploit Scanner (googled this too)
WPSec.com | Online WordPress Security Scan for Vulnerabilities

Things to try:

* check all open ports.
* scan fles for virus and malware.
* make sure all the software you are using is up to date, especially things like Wordpress, Joomla, and other CMS software.
* Wordpress and CMS's is a nightmare, its one of the most hacked systems, so you must keep them up to date.
* check the Wordpress plugins, when was it last updated... did you update them? out of date and poorly written plugins are another real issue and a quick way in for hackers
 
Last edited:
That sounds really frustrating. Well done for maintaining it for so long.

Do you think you can find someone at a local school/university doing computer science who would offer their help?
Thanks, M8 for taking time out to try to help, a good idea we have a couple of Unis with Business Schools attached could be worth a try if I go down on my mobility scooter I could get the sympathy vote also ;)
 
You need a professional, they will find it and plug the exploit

But if you need to start yourself there are exploit scanning websites.

I googled this one Full Site Scan
Website Scanner Online - Find Site Vulnerabilities Fast

Wordpress Exploit Scanner (googled this too)
WPSec.com | Online WordPress Security Scan for Vulnerabilities

Things to try:

* check all open ports.
* scan fles for virus and malware.
* make sure all the software you are using is up to date, especially things like Wordpress, Joomla, and other CMS software.
* Wordpress and CMS's is a nightmare, its one of the most hacked systems, so you must keep them up to date.
* check the Wordpress plugins, when was it last updated... did you update them? out of date and poorly written plugins are another real issue and a quick way in for hackers
Thanks, M8 for taking time out to try to help it is appreciated and your message offers a fairly comprehensive follow-through which I will do. Thanks again and keep safe
 
Thanks, M8 for taking time out to try to help it is appreciated and your message offers a fairly comprehensive follow-through which I will do. Thanks again and keep safe
I should have said that I am paranoid about keeping both WordPress and Plugins up to date, but I have not checked some files using the 'C' panel like wp-config ect to make sure they are up to date. I have got a list of those folders which are used as backdoors (there is me being technical - don't know what it means but hey-ho) Thank you again for all your help it really is appreciated.
 
Back
Top