Results 1 to 11 of 11
  1. #1
    zuutroy's Avatar
    zuutroy is offline Private Member
    Join Date
    September 2011
    Posts
    69
    Blog Entries
    2
    Thanks
    18
    Thanked 28 Times in 21 Posts

    Default Negative SEO Hacked

    Bleugh. Someone got into all the sites on my control panel and dumped tens of thousands of html files into various directories. Backlinks to those files are now starting to appear by the thousand of on MajesticSEO.

    I have a Wordpress developer hired to try and tighten everything up. I hope once the html files are gone that the links won't hurt my rankings. Does anyone have any input on this, or experience with it happening?

  2. #2
    RacingJim is offline Public Member
    Join Date
    May 2013
    Posts
    1,898
    Thanks
    896
    Thanked 1,370 Times in 845 Posts

    Default

    Never seen this before. I guess the fix is delete the whole thing and restore from a backup? Once the dodgy html files are gone then the links are dead links anyway. But it's still a negative SEO attack so might wana get disavowing all the dodgy links/domains that have appeared on your majetic.

  3. The Following 2 Users Say Thank You to RacingJim For This Useful Post:

    Vrindavan (25 December 2015), zuutroy (18 December 2015)

  4. #3
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,927
    Thanks
    4,524
    Thanked 9,285 Times in 5,973 Posts

    Default

    FIRST....change ALL passwords. CPanel, ftp, and all wordpress as well as database passwords if you have them.

    In some cases you might have to change the wordpress and database passwords after a restore, unless you change them inside the dump files. If so change them IMMEDIATELY after the restore, waiting could allow access by the same individual again.

    Double chenck to make sure there were not additional users added to cpanal access or ftp as well as wordpress.

    There are a few threads in the public areas here at the GPWA which discuss security plugins I suggest AllInOmeWPSecurity and WordFence also in highly recommended by others. (there is another also I think by name exscapes me now someone else will likely post it)

    Another thing that might be a help is to limit cpanel access to a single ip, or small number of ip's for yourself and any developers you have, if you have a static ip you normally work from. Your host can often help with this if needed.

    Rick
    Universal4

  5. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    -Shay- (18 December 2015), zuutroy (19 December 2015)

  6. #4
    sweetbet's Avatar
    sweetbet is offline Public Member
    Join Date
    November 2012
    Posts
    2,824
    Blog Entries
    5
    Thanks
    898
    Thanked 1,574 Times in 1,086 Posts

    Default

    I'd go as far as deleting the entire hosting account and re-creating a new one, just to make sure that no dodgy files remain in the system. Then I'd re-upload and restore from my backups.

  7. The Following User Says Thank You to sweetbet For This Useful Post:

    zuutroy (19 December 2015)

  8. #5
    zuutroy's Avatar
    zuutroy is offline Private Member
    Join Date
    September 2011
    Posts
    69
    Blog Entries
    2
    Thanks
    18
    Thanked 28 Times in 21 Posts

    Default

    Cheers for the comments. Got a really good guy off Upwork who has secured one cpanel and is working on the other. He's restored everything on fresh WP installs and added an extra layer of password protection to the wp-admin. Just have to hope the spammy links don't cause much harm. Have disavowed them all and they're pointing to nonexistent files now.
    Couple of the sites got flagged by Google for malware but thankfully the main one didn't.

  9. #6
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,927
    Thanks
    4,524
    Thanked 9,285 Times in 5,973 Posts

    Default

    If the wp-admin login stays in the same default place, brute force attacks will never stop.

    Since the cpanel was compromised, hopefully the database passwords is or will be changed since they certainly could be compromised.

    Glad you got some of it figured out.

    Rick
    Universal4

  10. #7
    zuutroy's Avatar
    zuutroy is offline Private Member
    Join Date
    September 2011
    Posts
    69
    Blog Entries
    2
    Thanks
    18
    Thanked 28 Times in 21 Posts

    Default

    Everything's been cleaned up now, including DB passwords etc. Got a fright this morning when loads of my most profitable pages were ranking nowhere. Turns out that everything that Google crawled when the sites were down for maintenance was instantly de-indexed. I resubmitted in WMT and they came back about 2 hours later.
    Now all I have to do is hope that all the spammy links pointing to files which no longer exist don't hurt me!
    Make sure you've got super strong Wordpress passwords people.

  11. #8
    Triple7 is offline Private Member
    Join Date
    January 2015
    Posts
    2,872
    Thanks
    2,043
    Thanked 2,446 Times in 1,324 Posts

    Default

    May I ask... how did you notice what happened?

  12. #9
    zuutroy's Avatar
    zuutroy is offline Private Member
    Join Date
    September 2011
    Posts
    69
    Blog Entries
    2
    Thanks
    18
    Thanked 28 Times in 21 Posts

    Default

    I got a bandwidth exceeded error on one of the sites so I logged in to cpanel to see what happened and saw all off the html files sitting there.

  13. #10
    martinseomcgarry's Avatar
    martinseomcgarry is offline Private Member
    Join Date
    September 2013
    Location
    Leeds
    Posts
    86
    Thanks
    14
    Thanked 38 Times in 23 Posts

    Default

    You may get a lot of 404 errors in Google search console if Google has indexed those files/URLs. Keep an eye on that - if they ever appear as errors in your indexed profile, i would suggest you get a list of the dodgy URLs and add them as 410's in your htaccess files - 410 server response stands for 'Gone' forever and will therefor encourage Google to deindex those pages.

  14. The Following User Says Thank You to martinseomcgarry For This Useful Post:

    universal4 (21 December 2015)

  15. #11
    zuutroy's Avatar
    zuutroy is offline Private Member
    Join Date
    September 2011
    Posts
    69
    Blog Entries
    2
    Thanks
    18
    Thanked 28 Times in 21 Posts

    Default

    There's a couple of hundred showing as 404s in WMT. I'll do that. Thanks!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •