The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. White Hat / Black Hat SEO
    4. Wordpress keeps reinfected

    Wordpress keeps reinfected

    White Hat / Black Hat SEO
    10 5 422
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • maestrosonrisas
      maestrosonrisas last edited by

      hello my wordpress theme keeps reinfected

      i dont know were the virus is coming from, they upload archives on ftp and redirects all wordpress pages

      i installed this pluggin

      http://sucuri.net

      what is your opinion about this pluggin

      my wordpress is all actualized. Any ideas to spot reinfections

      1 Reply Last reply Reply Quote 0
      • Anita_Clark
        Anita_Clark last edited by

        If you can reload the site via FTP to a state prior to loading the plugin that would be the way to go...assuming the plugin is the problem.

        maestrosonrisas 1 Reply Last reply Reply Quote 0
        • maestrosonrisas
          maestrosonrisas @Anita_Clark last edited by

          i think the plugin is not the problem thats why i am asking information about that plugin.

          I have restored the web every two days  wich is the time between they can enter my ftp again.

          24 up 48 hours the time bettwen virus came back to wordpress and install new archives.

          I have change all the passwords, no clue what is happening

          1 Reply Last reply Reply Quote 0
          • BeardoCo
            BeardoCo last edited by

            Might be best to use someone that has specific knowledge of WordPress security to lock your site down. Plugins generally don't catch everything and certainly do not lock you down from further attacks.  There are a few steps that you can take to make sure your site won't be infected through simple scripts and brute force.  If you need a referral for a security guys let me know.

            maestrosonrisas 1 Reply Last reply Reply Quote 1
            • maestrosonrisas
              maestrosonrisas @BeardoCo last edited by

              Yes please give me some referrals

              1 Reply Last reply Reply Quote 0
              • MarakeshExpress
                MarakeshExpress last edited by

                Hi There,

                I previously dealt with 3 WordPress website that have got infected. Installing plugins like sucuri.net or http://vaultpress.com/ could be a solution but once the system is infected those won't necessary fix the problem

                Here's what to do:

                1. Delete all you plugin and check the theme for malware. If possible reinstall the theme with the original/updated version. See if that fixes the problem

                If not:

                Backup your database ( or even use a .xml export file)
                Backup your pictures (make sure you only keep files with extensions like .jpg, .jpeg, .gif, .swf, .png, .bmp )

                Delete all your wordpress folder

                Reinstall fresh version of wordpress

                Reinstall fresh version of theme

                Import data.xml or run database import from phpmyadmin

                Upload your images.

                If the problem persists, make sure your hosting environment is not the cause of the infection. Unfortunately one of my clients had a situation like those and we  had to change all his hosting...

                BUT: MOST LIKELY ONE OF THE PLUGINS WILL BE THE CAUSE

                UNINSTALLING AND DELETING ALL PLUGINS MIGHT JUST FIX THIS ISSUE.

                1 Reply Last reply Reply Quote 2
                • maestrosonrisas
                  maestrosonrisas last edited by

                  Tanks Alexandru, i will do that.

                  My host is the one who keeps saving me from this attack.

                  They adviseme to unistall sucuri pluggin. And look for virus on my computer (althouth i have a Mac) i run the only virus program i could find (dont now if you can tell me another for mac

                  1 Reply Last reply Reply Quote 0
                  • AndrewBeeston
                    AndrewBeeston last edited by

                    My first thoughts: I'd install something like WP Firewall, to help you monitor any changes in files and easily maintain security on the site. It should email you any time something is changed (can be annoying but it might provide a trail for you for how the site is getting changed).

                    It might not provide everything you need though, as already stated.

                    Have you been able to identify how the site is being altered? See if you can find some of the code that is being used and then do a web search for it.

                    I recently found that a few of our sites had been hacked using an exploit through Akismet - yeah Akismet. It was about 30 websites that got hacked - and the only common plugin was Akismet. So if it's happening over a couple of sites (I see you have a couple) look for patterns (same host, same plugins, same ftp details) and try and isolate the issue that way.

                    maestrosonrisas 1 Reply Last reply Reply Quote 2
                    • maestrosonrisas
                      maestrosonrisas @AndrewBeeston last edited by

                      I have askimet instalet.

                      They upload files like and introduced code like database.sql.php on htaccess

                      AndrewBeeston 1 Reply Last reply Reply Quote 0
                      • AndrewBeeston
                        AndrewBeeston @maestrosonrisas last edited by

                        Hmmm maybe some further reading is required. Here's potentially some helpful info for you on hardening WP, and other experiences with .htaccess hacks that might point you in a helpful direction.

                        http://codex.wordpress.org/Hardening_WordPress

                        https://www.google.com/search?q=htaccess+hack+wordpress

                        http://wordpress.org/support/topic/htaccess-hacked-redirects-to-russion-site

                        http://wordpress.org/support/topic/recurring-htaccess-hijack?replies=30

                        http://wordpress.org/support/topic/my-sites-htaccess-file-hacked-how

                        1 Reply Last reply Reply Quote 1
                        • 1 / 1
                        • First post
                          Last post
                        • WordPress Tags and SEO
                          donsilvernail
                          donsilvernail
                          0
                          3
                          91

                        • Pointless Wordpress Tagging: Keep or unindex?
                          EGOL
                          EGOL
                          0
                          17
                          397

                        • Best 301 redirection plugin for Wordpress?
                          ChristopherGlaeser
                          ChristopherGlaeser
                          1
                          2
                          457

                        • How long we can keep 302 redirection for a webpage url?
                          MickEdwards
                          MickEdwards
                          0
                          2
                          418

                        • WordPress Plugin Backlinks?
                          Atomicx
                          Atomicx
                          0
                          5
                          308

                        • Subdomains vs. Subfolders Wordpress Multisite
                          allancurtis301
                          allancurtis301
                          0
                          8
                          10.1k

                        • How do you keep a record of your onsite SEO changes
                          Laurean
                          Laurean
                          0
                          7
                          702

                        • Blogspot or Wordpress.com Redirect?
                          RyanKent
                          RyanKent
                          0
                          2
                          643

                        Get started with Moz Pro!

                        Unlock the power of advanced SEO tools and data-driven insights.

                        Start my free trial
                        Products
                        • Moz Pro
                        • Moz Local
                        • Moz API
                        • Moz Data
                        • STAT
                        • Product Updates
                        Moz Solutions
                        • SMB Solutions
                        • Agency Solutions
                        • Enterprise Solutions
                        • Digital Marketers
                        Free SEO Tools
                        • Domain Authority Checker
                        • Link Explorer
                        • Keyword Explorer
                        • Competitive Research
                        • Brand Authority Checker
                        • Local Citation Checker
                        • MozBar Extension
                        • MozCast
                        Resources
                        • Blog
                        • SEO Learning Center
                        • Help Hub
                        • Beginner's Guide to SEO
                        • How-to Guides
                        • Moz Academy
                        • API Docs
                        About Moz
                        • About
                        • Team
                        • Careers
                        • Contact
                        Why Moz
                        • Case Studies
                        • Testimonials
                        Get Involved
                        • Become an Affiliate
                        • MozCon
                        • Webinars
                        • Practical Marketer Series
                        • MozPod
                        Connect with us

                        Contact the Help team

                        Join our newsletter
                        Moz logo
                        © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                        • Accessibility
                        • Terms of Use
                        • Privacy