The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Technical SEO Issues
    4. Site Blacklisted

    Site Blacklisted

    Technical SEO Issues
    13 4 262
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • littlesthobo
      littlesthobo last edited by

      Good morning.

      Just done my WMT ritual morning check and one of my sites has been blacklisted for malware.

      It's a wordpress site - I've run various scans, e.g. http://sitecheck.sucuri.net/scanner/ and also installed wordfence and scanned with that and wordfence produced some offending files which I have now deleted.

      I've also installed website defender in the hope that it wont happen again.  I'm pretty good with staying on top of updates and rarely let a few days pass without upgrading new version of wordpress or plugins etc.  I've also checked my users to make sure no new admins or anything and also changes passwords.

      I've asked for a review from Google and just wondered how long these reviews take?

      Also, has anybody got any advice, is there anything else I should be doing?

      Thanks

      1 Reply Last reply Reply Quote 0
      • SEOAndy
        SEOAndy last edited by

        in my experience, and i've a fair bit with WP, the majority of malware comes from plugins which get updated and become infected themselves. Wordfence certainly can help with this problem, but a regular securi scan will too.

        My advice is deactivate and uninstall any plugins you don't really need or use - this will make the site faster and more secure.

        Once the malware has gone you can do as you have and ask for relisting or wait it out, google will come back and check. Manual reviews will take a few days to come back I believe, though it depends on the nature of the malware - if its believed to be complex it will be manual if its just one file being "naughty" a robot may scan your site to take a look that it's gone and it could be up in 24-48 hours.

        Bondara 1 Reply Last reply Reply Quote 3
        • loopyal
          loopyal last edited by

          Hello Jo.

          Do you know exactly how they got in?

          If not, here is one possibility:

          Check to see if you have a copy of timthumb.php

          If you do, and it is an old version, it has a vulnerability you must fix, otherwise it will happen again.

          Here is information about that, including a scanner that should find and fix that problem.

          <cite>wordpress.org/extend/plugins/timthumb-vulnerability-scanner/</cite>

          1 Reply Last reply Reply Quote 2
          • Bondara
            Bondara last edited by

            I think you have already done quite a bit.

            I suppose just be a little more selective which plugins you install, some have holes in and once the word is out about particular holes in certain plugins these people will come looking for blogs with it installed.

            1 Reply Last reply Reply Quote 1
            • Bondara
              Bondara @SEOAndy last edited by

              Agree

              1 Reply Last reply Reply Quote 0
              • littlesthobo
                littlesthobo last edited by

                Thanks all for your responses, much appreciated.

                I installed the timthumb vulnerability scanner and it says no instances were found.

                I'm going to go through and ditch the unnecessary plugins...I use woocommerce and they have  recent upgrade but its not compatible with my theme so I can't update it, which is a giant pain.  I hope its not that.

                Thanks for your help.

                Bondara 1 Reply Last reply Reply Quote 0
                • Bondara
                  Bondara @littlesthobo last edited by

                  I just want to reiterate what Andy said about sitespeed as well, try to have as little plugins as possible.

                  When you visit a WP site and its super slow, its usually because they have gallery plugins and all sorts running which sucks the life out of the sitespeed.

                  Anyway, good luck seems as though you know what your doing anyway.

                  littlesthobo 1 Reply Last reply Reply Quote 1
                  • littlesthobo
                    littlesthobo @Bondara last edited by

                    Thanks, I'm not so sure!  I'm a freelancer and I wok on my own so I have nobody to really bounce ideas off, so this community is great for that.  Glad to know I'm doing it right 🙂

                    I'm not a bit lover of plugins and I try to keep to a minimum, but I've removed anything unessential - even my beloved Flare sharing buttons, for now anyway.

                    I'll let you know when Google come back to me 🙂

                    1 Reply Last reply Reply Quote 1
                    • loopyal
                      loopyal last edited by

                      Jo,

                      before you removed the bad files, did you check the dates?

                      If you have logs, you could go back to see when those files were first accessed.

                      Then go backwards looking for activity that doesn't look normal.

                      That could tell you where the problem is.

                      littlesthobo 1 Reply Last reply Reply Quote 0
                      • littlesthobo
                        littlesthobo @loopyal last edited by

                        I didn't check the dates 😕  The site is less than a month old though.

                        When you say logs, I'm not entirely sure what I'm looking for.  I use cpanel so have access to various logs, but I have to admit, I haven't spent any time in there and now I'm conscious that this is something I need to educate myself on quick.

                        Any suggested resources for which logs to use for what?

                        loopyal 1 Reply Last reply Reply Quote 0
                        • loopyal
                          loopyal @littlesthobo last edited by

                          The webserver log is what you need.

                          You may be able to see that in Cpanel, depending on how it is configured.

                          The log may also be in the document root, updated daily and compressed.

                          If you haven't looked at logs before, it can be difficult to determine what is really going on in there.

                          1 Reply Last reply Reply Quote 1
                          • littlesthobo
                            littlesthobo last edited by

                            Thanks all for your help, I was de-blacklisted this afternoon - phew.

                            loopyal 1 Reply Last reply Reply Quote 1
                            • loopyal
                              loopyal @littlesthobo last edited by

                              That is good to hear, Jo.

                              Thanks for letting us know. feedback is good.

                              Be vigilant, because the hackers never stop.

                              My dedicated server constantly has hackers trying to break in, mostly chinese and russians. Complex passwords and countermeasures keep us safe, but it only takes one weak link somewhere to break it all down.

                              1 Reply Last reply Reply Quote 1
                              • 1 / 1
                              • First post
                                Last post
                              • Switching site from http to https. Should I do entire site?
                                rayvensoft
                                rayvensoft
                                1
                                5
                                592

                              • Linking shallow sites to flagship sites
                                Harbor_Compliance
                                Harbor_Compliance
                                0
                                3
                                110

                              • I noticed all my SEOed sites are getting attacked constantly by viruses. I do wordpress sites. Does anyone have a good recommendation to protect my clients sites? thanks
                                inboundauthority
                                inboundauthority
                                0
                                8
                                266

                              • If you are organizing the site structure for an ecommerce site, how would you do it?
                                danatanseo
                                danatanseo
                                0
                                2
                                323

                              • How can you get the right site links for your site?
                                Plorex
                                Plorex
                                0
                                7
                                701

                              • I am Posting an article on my site and another site has asked to use the same article - Is this a duplicate content issue with google if i am the creator of the content and will it penalize our sites - or one more than the other??
                                Alex-Harford
                                Alex-Harford
                                0
                                4
                                524

                              • How do I set up a site review for a password protected site?
                                jsturgeon
                                jsturgeon
                                0
                                2
                                968

                              • Some sites like bbc.co.uk place the most important category links at the bottom of the page while other sites will place the whole site map there. What are the benefits (or not) of both approaches?
                                Christy-Correll
                                Christy-Correll
                                0
                                6
                                1.0k

                              Get started with Moz Pro!

                              Unlock the power of advanced SEO tools and data-driven insights.

                              Start my free trial
                              Products
                              • Moz Pro
                              • Moz Local
                              • Moz API
                              • Moz Data
                              • STAT
                              • Product Updates
                              Moz Solutions
                              • SMB Solutions
                              • Agency Solutions
                              • Enterprise Solutions
                              • Digital Marketers
                              Free SEO Tools
                              • Domain Authority Checker
                              • Link Explorer
                              • Keyword Explorer
                              • Competitive Research
                              • Brand Authority Checker
                              • Local Citation Checker
                              • MozBar Extension
                              • MozCast
                              Resources
                              • Blog
                              • SEO Learning Center
                              • Help Hub
                              • Beginner's Guide to SEO
                              • How-to Guides
                              • Moz Academy
                              • API Docs
                              About Moz
                              • About
                              • Team
                              • Careers
                              • Contact
                              Why Moz
                              • Case Studies
                              • Testimonials
                              Get Involved
                              • Become an Affiliate
                              • MozCon
                              • Webinars
                              • Practical Marketer Series
                              • MozPod
                              Connect with us

                              Contact the Help team

                              Join our newsletter
                              Moz logo
                              © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                              • Accessibility
                              • Terms of Use
                              • Privacy