Hi there- I could probably post this on Wordpress but I find lots of those threads get lost and plus I always find answers through Sitepoint
I’m in a bit of a pickle. I have an account at bluehost on which I host about 10 of my friends’ websites. One of them told me that when they visit their website through a search engine, they’re redirected to some spam site. I thought it was just their browser, but it’s actually happening on each of the sites on that server. Who knows how long this has been going on, none of them actively monitor analytics.
My problem now is that I don’t know anything about security (chmod .htaccess). Everything that I’ve found goes into great detail about changing your permissions, passwords, fresh installs.
Does anyone have any suggestions here? Re-doing all of the 10 sites would be a goddamn nightmare… I know the site sucuri.net can fix it pretty quickly, how do they do it?? I might just have to run that, but it will be an expensive option…
Sorry for the vague details, I just don’t know what to provide here. Most of the php files have a base_64 decode in them which seems strange…
I think it was a timthumb.php security issue in one of the older versions. I didn’t update right away, and once I did- the damage was already done. Same with the other suggestions, I’ve since changed FTP passwords and run antivirus- but the affected files are still on my server.
Your Wordpress installation or one of its plugins could have been hacked. Or the server could have been hacked or maybe your hosting account hacked. There are lots of ways you could have been hacked. Of course, Wordpress is probably the most probable source of the security breach.
Delete all of your files and start fresh. Those hackers like to put multiple backdoors in all over the place just in case one of them is discovered so they can get back into your account.
I don’t know what kind of output validation Wordpress does. You might want to check your posts table in your database for any rogue scripts or iframes.