The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Technical SEO Issues
    4. Website hacked

    Website hacked

    Technical SEO Issues
    10 5 554
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Socialdude
      Socialdude last edited by

      Hi I've been asked to help a colleague with his website. It seems to be hacked. He recently received an e-mail from Google saying his adwords account was suspended 'due to high probability  his site may be hosting or distributing malicious software' I just checked his source and there seems to loads of weird on code on his pages, this would not have been but on by any members of the website owners.

      Please image attached when we try to access his website via google search

      I just contacted the hosting provider - does anyone have experience with this and how to prevent such hacking in the future. The site is build using HTML with no CMS.

      IjW19.jpg

      1 Reply Last reply Reply Quote 0
      • AlanMosley
        AlanMosley last edited by

        I have never had this happen, but i would guess that the code is probably added thought a rewite rule. See if the code is actualy on the pages via the fiels system. if not i would be looking for rewrite rules in the server settings.

        Socialdude 1 Reply Last reply Reply Quote 0
        • Socialdude
          Socialdude @AlanMosley last edited by

          I found this in the source code and it's placed on all pages and looks like the below there are about 10 paragraphs on each page: I just hope the hosting provider can help us out.

          6lkmW.jpg

          AlanMosley Socialdude 2 Replies Last reply Reply Quote 0
          • AlanMosley
            AlanMosley @Socialdude last edited by

            is it on the pages where you naviagte to them though the file system?

            does the website use a database?

            1 Reply Last reply Reply Quote 0
            • Socialdude
              Socialdude @Socialdude last edited by

              I'm not to sure to be honest I'm not a web designer / developer and don't have experience with databases.

              1 Reply Last reply Reply Quote 0
              • RyanKent
                RyanKent last edited by

                Web security is a very complex field which has literally hundreds of layers. You said the site was built using HTML. Is this an experienced developer with formal web development training who uses valid HTML code and has years of experience? Or is this a do-it-yourself kind of project?

                It's kind of like saying someone broke into your house. They could come through the front door, the back door, the side door, any window or slide down the chimney. They could have a key made or pick the lock or smash the lock. Security is a very comprehensive field which involves the web server itself, the website, the admin panel and more. There is not a Q&A response anyone can offer to address the many factors involved.

                You can pay for McAfee or a similar service to perform daily malware scans of your site and alert you to security issues. You can also move to a CMS and ensure you keep the latest updates and read their security guidelines.

                Socialdude 1 Reply Last reply Reply Quote 1
                • Socialdude
                  Socialdude @RyanKent last edited by

                  Cheers for your reply, as far as I know the site was built by an experienced developer but I couldn't really comment as I'm not sure. I must say the site is pretty old and it's not html validated.

                  We are currently looking to get the site build on a CMS either worpdress or modx.

                  Based on what you mentioned above I will just wait and see what the hosting company have to say with regards to this issue.

                  AlanMosley 1 Reply Last reply Reply Quote 0
                  • AlanMosley
                    AlanMosley @Socialdude last edited by

                    One way this can happen and your code you posted looks like a case I have seen happenn to a friend, is SQL injection. Where someone posts script into your database though inputs in your form. then when you request the data from the database it is executed.

                    Most newer technologies have fixed this hole, but older technologies are prone to it.

                    1 Reply Last reply Reply Quote 1
                    • ShaMenz
                      ShaMenz last edited by

                      Hi Socialdude,

                      A look at that code suggests that the most likely point of access has to be a file that is more than just regular HTML somewhere on your site. This means that somewhere, there must be at least one php file.

                      My first guess would be that there is a page with a PHP driven contact form which has been used to inject code into the site and propogate the malicious javascript into the other pages.

                      If you have a clean backup copy of all pages in the site (either with your friend or their developer), then the quickest fix is to upload your backup version.

                      If you don't have a backup, then you could try checking the Wayback Machine and see if there is a clean copy archived there which you can grab and upload to replace the hacked site.

                      If neither of those is an option, then the first thing to do is to find any pages in the site with the .php extension.

                      Rename the files by changing the file extension from .php to .txt. (If you are unsure of how to change the file extension, you can just open the files, save a copy with a .txt extension and then delete the .php version from the server)

                      You can now look at the file(s) that were PHP, see what has been added to the code and clean it up. You will then need to individually edit the HTML files and remove all of the bad javascript code. Now that you have everything cleaned up, create a complete backup of the site just in case you need it again in the future. Upload your clean copy and you should be good to go. 🙂

                      I would also go to Google Webmaster Tools & use "fetch as googlebot" to fetch and add the index page so that Google knows you are now OK to crawl again.

                      Hope that helps,

                      Sha

                      1 Reply Last reply Reply Quote 0
                      • KeriMorgret
                        KeriMorgret last edited by

                        Hi Socialdude,

                        Did you get this sorted out, or would you like some more advice still?

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post
                        • I have website how i rank this website? suggest me any idea.
                          TrentonGreener
                          TrentonGreener
                          0
                          2
                          66

                        • How To Cleanup the Google Index After a Website Has Been HACKED
                          N1ghteyes
                          N1ghteyes
                          0
                          5
                          4.5k

                        • How do I optimize a website for SEO for a client that is using a subdirectory as a seperate website?
                          KristinaKledzik
                          KristinaKledzik
                          0
                          4
                          132

                        • 5 minutes riddle of a hacked website - 2nd run
                          csabatoldi
                          csabatoldi
                          0
                          2
                          84

                        • Website Down
                          KevinBudzynski
                          KevinBudzynski
                          1
                          3
                          82

                        • Only my website homepage is appearing in search and the other indvidual pages are not coming up?This happened after the website revamp
                          MozAddict
                          MozAddict
                          0
                          6
                          165

                        • Websites being hacked & duplicated, what should we do?
                          Squall315
                          Squall315
                          0
                          3
                          317

                        • How to attach at text to image that other websites use from my website
                          melody-anne
                          melody-anne
                          0
                          2
                          489

                        Get started with Moz Pro!

                        Unlock the power of advanced SEO tools and data-driven insights.

                        Start my free trial
                        Products
                        • Moz Pro
                        • Moz Local
                        • Moz API
                        • Moz Data
                        • STAT
                        • Product Updates
                        Moz Solutions
                        • SMB Solutions
                        • Agency Solutions
                        • Enterprise Solutions
                        • Digital Marketers
                        Free SEO Tools
                        • Domain Authority Checker
                        • Link Explorer
                        • Keyword Explorer
                        • Competitive Research
                        • Brand Authority Checker
                        • Local Citation Checker
                        • MozBar Extension
                        • MozCast
                        Resources
                        • Blog
                        • SEO Learning Center
                        • Help Hub
                        • Beginner's Guide to SEO
                        • How-to Guides
                        • Moz Academy
                        • API Docs
                        About Moz
                        • About
                        • Team
                        • Careers
                        • Contact
                        Why Moz
                        • Case Studies
                        • Testimonials
                        Get Involved
                        • Become an Affiliate
                        • MozCon
                        • Webinars
                        • Practical Marketer Series
                        • MozPod
                        Connect with us

                        Contact the Help team

                        Join our newsletter
                        Moz logo
                        © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                        • Accessibility
                        • Terms of Use
                        • Privacy