My website was hacked last Thursday
-
My business website was hacked (for the 2nd time in 12 months) last Thursday and all data lost. I've been rebuilding the site and database since then but I'm still getting Hacking Warnings each day.
The latest warning says:
Dear Colin/Administrator,
Someone has attempted to inject SQL into your domain:
HACK DETECTED!
PHP TYPE
IP: 94.100.17.134
Scriptname: /index.cfm
PathInfo: /index.cfm
QueryString: src=http%3A%2F%2Fpicasa.com.oprst.in%2Fshow.php%3Fid%3D16907217My Technical advisro tells me the IP address is that of Inferno Solutions of The Netherlands.
I wonder if anyone has suffered hacking like this what steps they too and what I could do about the potential hackers?
Colin
-
Thanks very much Sarah and thanks for the link and recommendations. I'll look into it today.
Plus the Extended Validation.
That's really kind of you.
Kind regards,
Colin
-
Hi Colin,
Just an additional note, Verisign (now Symantec) - as well as performing daily malware scans - has a fantastic range of SSL certificates that encrypts your customers' info when using forms and for online payments. I noticed in your contact page that the connection is not secure.
http://www.trustico.co.uk/products/symantec/secure_site/symantec-secure-site-ssl-certificates.php
I've sent a link for a basic domain validated certificate, but if you want a green bar at the top of your website so your customers know that you are whom you say then have a look at the EV (extended validation) certificates.
Nice website, by the way, I'd love a Nile cruise!
Sarah.
-
Thanks for those tips and the advice Ryan.
I will take your advice and look at adding Verisign too.
I'm getting the site back into shape but have noticed a dip in ranking from 5th (after the last hack when we were 1st) to 7th today.
Hopefully the need to rebuild a lot of the data including titles and descriptions might help me in the long run to create a better site.
Thanks again for your time and help.
Colin
-
What I could do about the potential hackers?
A few tips:
-
If you are using any software on your site, ensure you keep up with the latest version. Normally you do not have to run out and update the moment a new release comes out, but you should have a plan in place to always update within 90 days of any release.
-
Ensure you share any passwords with the fewest number of people possible. You, your web developer and possibly your SEO consultant are the only ones which may need access to your web server. If anyone with a password changes (i.e. employee leaves, developer changes, etc) then change your password.
-
Do not use an easy to guess password such as "admin1" or "password1". Actually, both your username and password should be difficult to guess.
-
Do not use shared server hosting. If you are paying $10 or less per month for hosting, you are on a shared server. Upgrade to VPS or better. VPS hosting starts at around $35 but there are numerous advantages over shared hosting.
-
Use a service such as Verisign (now Symantec) to perform daily malware scans. If you purchase a Verisign SSL certificate, the service comes with the package.
-
Each type of hosting (Apache, nginx, Microsoft, etc) and website will have its own security recommendations. Make sure they are followed. On my dedicated server, there are some security scripts which have been written by my web host to enhance security. Additionally, there is code I add to the htaccess file on all sites which block common attacks.
With all of the above in mind, nothing can beat a thorough security check from an expert. There are companies that focus web security as their business. Such inspections are very expensive but they offer a lot of value. Also know that even the biggest companies in the world suffer security breaches. By following all of the above steps, you will clearly be a more difficult target then many other sites whereas right now it sounds like you are an easy target.
Good Luck.
-
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Reddit website, what do link provide to users? I'm little confused about do-follow and no-follow.
I share an example with you. Please check and tell me. Why MOZ tool saying this link is do-follow link. But actually the link is no-follow. Here is the link- https://www.reddit.com/r/Bloggers/comments/8i46q4/top_service_industries_who_should_opt_for/ OlCxIyS
Moz Pro | | sourav60 -
Advanced popup for WP website
Hi guys, I'm looking for advanced popup for WP website.
Moz Pro | | EdmondHong87
Im looking something with advanced filters. For example: Filter the visitors by the operation system (For mobile).Will show to new visitors, but exclude to returns visitors.
Will exclude visitors that sign up to the website.
Filter the traffic...Popup will show only to visitors from FB, Google organic etc... Well, i believe that you understand what i need...
Anyone know something like this ? Thank you!0 -
My website not getting organic hits
Hello Moz, I am enjoying being here i just bought moz pro, and am digging for what to change in my website, Apart from that I just wanna know why my website not getting rank in search engine, if someone can do quick audit for me it will be obligation on me. querease(dot)com
Moz Pro | | querease0 -
Are there any free (or paid) tools available online that download Meta Tags for ALL URL's of a website?
Hi, I am looking to run an On-Site audit for a website and I'm wondering if there are any tools available online that take the existing Meta Tags on ALL pages of a website and downloads them to a .CSV or .XLS. Would need Meta Title and Meta Description for all pages at the very least. Any suggestions are appreciated - looking for Free or Paid options. Thanks.
Moz Pro | | SEO5Team0 -
Help - Analyzing Web Traffic Across Multiple Websites
Hi Moz Community, Hope you can help. Is there any way to discover the most visited pages for a particular website, one that I do not administer? I wouldn't need exact numbers, just a relative breakdown of the "Most Visited" pages/sections. For example, if I was reviewing www.jcrew.com, I'd be interested in determining the 10/20/50 most visited pages/products. And just to provide another example, I would be interested in the 10/20/50 most visited pages/stories on www.buzzfeed.com. Any and all help is greatly appreciated. Thank you!
Moz Pro | | MountArashi0 -
Why is the SEOmoz crawler crawling the old version of our website?
Hello, I'm a new SEOmoz member. On Dec. 2nd, after completely redesigning our website, we migrated to a new hosting company by switching our DNS to the new server. The vast majority of the URLs have changed and we configured redirects of the old URLs to the new ones. Although, this task is not completed yet. After the migration, I created an account on SEOmoz to be able to track our progress and find the issues to fix to optimize our SEO. For some reason, in the SEOmoz reports it is the old URLs that show up. Unless the crawler does not actually crawl the pages and only uses the indexed pages to generate its report, I don't understand how could this possible. Anyone has a clue? When will the new URLs be indexed by SEOmoz and the major search engines? Thanks for your help!
Moz Pro | | Gestisoft-Qc0 -
Open Site explorer (last 1-3 updates) shows new and wierd results
Hi Moz'ers! I have a questions for you guys. Can you explain why the website "Netspiren" has a lower "domain Authority" than "Duft og Natur"? See screenshot. I know it's a tough question without a detailed analysis, but looking at OSE's data, does the mozrank,moztrust, C-block don't reflect the power of the Domain Authority. What's you take? BTW: "Netspiren" has always had more and better links, and also had a higher Domain Authority. Something about the Domain Authority changed since the past 1-3 OXE updates. Looking forward for your take on this! Have a good weekend! mnRPI.png
Moz Pro | | FrederikTrovatten220 -
In competitive domain analysis my website shows pages that I no longer have.
When I go to my campaign, link analysis, under competitive comparison/followed backlinks, the 5 pages under Anchor Text/Target URL, supposedly on my website, are not on my website anymore. I recently moved my domain name to another server (before signing up for seomoz) and deleted the forum associated with my website. Those 5 pages are all from that now extinct forum. What's going on?
Moz Pro | | ovistomih0