-
18 December 2015, 4:54 am
#1
Negative SEO Hacked
Bleugh. Someone got into all the sites on my control panel and dumped tens of thousands of html files into various directories. Backlinks to those files are now starting to appear by the thousand of on MajesticSEO.
I have a Wordpress developer hired to try and tighten everything up. I hope once the html files are gone that the links won't hurt my rankings. Does anyone have any input on this, or experience with it happening?
-
-
18 December 2015, 5:26 am
#2
Never seen this before. I guess the fix is delete the whole thing and restore from a backup? Once the dodgy html files are gone then the links are dead links anyway. But it's still a negative SEO attack so might wana get disavowing all the dodgy links/domains that have appeared on your majetic.
-
The Following 2 Users Say Thank You to RacingJim For This Useful Post:
Vrindavan (25 December 2015), zuutroy (18 December 2015)
-
18 December 2015, 6:40 pm
#3
FIRST....change ALL passwords. CPanel, ftp, and all wordpress as well as database passwords if you have them.
In some cases you might have to change the wordpress and database passwords after a restore, unless you change them inside the dump files. If so change them IMMEDIATELY after the restore, waiting could allow access by the same individual again.
Double chenck to make sure there were not additional users added to cpanal access or ftp as well as wordpress.
There are a few threads in the public areas here at the GPWA which discuss security plugins I suggest AllInOmeWPSecurity and WordFence also in highly recommended by others. (there is another also I think by name exscapes me now someone else will likely post it)
Another thing that might be a help is to limit cpanel access to a single ip, or small number of ip's for yourself and any developers you have, if you have a static ip you normally work from. Your host can often help with this if needed.
Rick
Universal4
-
The Following 2 Users Say Thank You to universal4 For This Useful Post:
-Shay- (18 December 2015), zuutroy (19 December 2015)
-
18 December 2015, 8:59 pm
#4
I'd go as far as deleting the entire hosting account and re-creating a new one, just to make sure that no dodgy files remain in the system. Then I'd re-upload and restore from my backups.
-
The Following User Says Thank You to sweetbet For This Useful Post:
zuutroy (19 December 2015)
-
19 December 2015, 7:10 am
#5
Cheers for the comments. Got a really good guy off Upwork who has secured one cpanel and is working on the other. He's restored everything on fresh WP installs and added an extra layer of password protection to the wp-admin. Just have to hope the spammy links don't cause much harm. Have disavowed them all and they're pointing to nonexistent files now.
Couple of the sites got flagged by Google for malware but thankfully the main one didn't.
-
-
19 December 2015, 4:38 pm
#6
If the wp-admin login stays in the same default place, brute force attacks will never stop.
Since the cpanel was compromised, hopefully the database passwords is or will be changed since they certainly could be compromised.
Glad you got some of it figured out.
Rick
Universal4
-
-
20 December 2015, 7:41 am
#7
Everything's been cleaned up now, including DB passwords etc. Got a fright this morning when loads of my most profitable pages were ranking nowhere. Turns out that everything that Google crawled when the sites were down for maintenance was instantly de-indexed. I resubmitted in WMT and they came back about 2 hours later.
Now all I have to do is hope that all the spammy links pointing to files which no longer exist don't hurt me!
Make sure you've got super strong Wordpress passwords people.
-
-
20 December 2015, 7:43 am
#8
May I ask... how did you notice what happened?
-
-
20 December 2015, 8:23 am
#9
I got a bandwidth exceeded error on one of the sites so I logged in to cpanel to see what happened and saw all off the html files sitting there.
-
-
21 December 2015, 4:51 am
#10
You may get a lot of 404 errors in Google search console if Google has indexed those files/URLs. Keep an eye on that - if they ever appear as errors in your indexed profile, i would suggest you get a list of the dodgy URLs and add them as 410's in your htaccess files - 410 server response stands for 'Gone' forever and will therefor encourage Google to deindex those pages.
-
The Following User Says Thank You to martinseomcgarry For This Useful Post:
universal4 (21 December 2015)
-
21 December 2015, 1:05 pm
#11
There's a couple of hundred showing as 404s in WMT. I'll do that. Thanks!
-
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules