The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Technical SEO Issues
    4. Hacking and security

    Hacking and security

    Technical SEO Issues
    14 4 262
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ClaireH-184886
      ClaireH-184886 @PaddyDisplays last edited by

      ok thanks. The sites all have their own access but are all on the dedicated server. they can all be gained through a whm where we can change cpanel passwords and usernames but besides that they have no connection.

      PaddyDisplays 1 Reply Last reply Reply Quote 0
      • PaddyDisplays
        PaddyDisplays @ClaireH-184886 last edited by

        I'm not an expert (but have some experience) , but if they are truly separated, and the word press sites were up to date but were hacked too, then there is something very wrong.

        ClaireH-184886 1 Reply Last reply Reply Quote 0
        • ClaireH-184886
          ClaireH-184886 @PaddyDisplays last edited by

          i am waiting for the hosting company to get back to me, they have been working on this now for over 24 hours, i have sent them some questions but they have said they cannot answer them yet. it seems strange that the wordpress sites were hacked and they were all hacked even though they all had seperate logins

          ClaireH-184886 1 Reply Last reply Reply Quote 0
          • ClaireH-184886
            ClaireH-184886 @ClaireH-184886 last edited by

            just got this from my hosting company

            Hello,

            1. The server was not hacked. The application on these account has been compromised. In order to have the exact reason and coding vulnerability which allowed this to happen you may contact certified developer as we do not offer development services at this point.

            2. Review the above. What we do is secure the service on the server by applying all the patches available for the same. The coding and the updates on your website functions and coding is your responsibility. The review and patching of any script you use for your website is development related task.

            3. Again you will have to request this from expert web developer as s/he may review the coding of your website and provide the reason why and how it has been compromised.

            4. Contact certified developer with proven feedback to review and patch your websites coding.

            5. The answer to this question you may check here:

            http://docs.cloudlinux.com/

            Should you have any further questions or comments please do not hesitate to contact us.

            Best regards,

            PaddyDisplays 1 Reply Last reply Reply Quote 0
            • PaddyDisplays
              PaddyDisplays @ClaireH-184886 last edited by

              Yeah standard, "its not our problem" response.

              As I said before, if the joomla site shared something like mysql database access then it was most likely not the hosts fault.

              I have seen hosts blame opensource cms when actually they were just trying to hide their issues.  Its going to be impossible to know until someone looks properly into it (which hosts will not do, which is fair enough).

              1 Reply Last reply Reply Quote 0
              • AlanMosley
                AlanMosley last edited by

                I don't think its the server, wordpress and other cms are continually hacked. The server can not stop much at all. your code needs stop most hacks, and since wordpress is used by so many, all some one needs to do is hack their own and then they can go out and hack all wordpress sites of the same version.

                PaddyDisplays 1 Reply Last reply Reply Quote 0
                • PaddyDisplays
                  PaddyDisplays @AlanMosley last edited by

                  What your saying is true, but I have never heard of anyone getting hacked (bar brute forcing password or poor passwords), if they keep upto date with the security fixes.

                  Some hosts eg dreamhost will auto update installs for you , so you don't have to worry about  updating.

                  ClaireH-184886 1 Reply Last reply Reply Quote 0
                  • ClaireH-184886
                    ClaireH-184886 @PaddyDisplays last edited by

                    will have to look at dreamhost and see how much they charge for dedicated server. do they offer managed dedicated server. also the hosting company is not taking any responsibility.

                    would you expect the hosting company to let you know that your site has been hacked or is it down to yourself to know

                    PaddyDisplays 1 Reply Last reply Reply Quote 0
                    • PaddyDisplays
                      PaddyDisplays @ClaireH-184886 last edited by

                      I have only used dreamhosts shared hosting, don't know about dedicated.

                      "would you expect the hosting company to let you know that your site has been hacked or is it down to yourself to know"

                      Generally no, that you be your responsibility (or if your have a maintenance contact with the web developer).

                      Again dreamhost has some cool auto safe guards eg one of my clients had malware/virus on his pc and was sending out spam, they auto reset the password when it was picked up.  I also think they have other auto features to inform you about hacking, but its guaranteed service, its just a bonus they do.

                      I'm not saying you should go with dreamhost, I'm just telling you what they can/have done, (i have only use a few host companies)  but I'm sure there are alot of hosts that do that too (maybe even more).

                      1 Reply Last reply Reply Quote 0
                      • altecdesign
                        altecdesign last edited by

                        The wordpress hacking was almost surely due to having outdated version of WP, or having a vulnerable plugin installed.  There are a few helpful plugins you can use to secure your WP site, plugins like (http://wordpress.org/plugins/better-wp-security/).

                        also a couple things to note, you should also take basic measures to project the site by changing the default table prefixes of your DB from _wp,  create a new admin user and delete the default "admin" accoun & limit access to your wp-admin section in your .htaccess file.... these security plugins will give you a whole checklist of items to "secure".

                        1 Reply Last reply Reply Quote 1
                        • 1 / 1
                        • First post
                          Last post
                        • Manual action due to hack
                          Joe_Stoffel
                          Joe_Stoffel
                          0
                          8
                          96

                        • How To Cleanup the Google Index After a Website Has Been HACKED
                          N1ghteyes
                          N1ghteyes
                          0
                          5
                          4.5k

                        • Secure and non-secure Schema.org Markup?
                          RoxBrock
                          RoxBrock
                          0
                          3
                          539

                        • Ecommerce and Secure Checkout
                          BlueprintMarketing
                          BlueprintMarketing
                          0
                          4
                          134

                        • Site Got Hacked! Need Help!
                          irvingw
                          irvingw
                          0
                          3
                          386

                        • Secure Vs Non-Secure Redirects
                          AlanMosley
                          AlanMosley
                          0
                          2
                          357

                        • RSS Hacking Issue
                          Kerry22
                          Kerry22
                          0
                          6
                          750

                        Get started with Moz Pro!

                        Unlock the power of advanced SEO tools and data-driven insights.

                        Start my free trial
                        Products
                        • Moz Pro
                        • Moz Local
                        • Moz API
                        • Moz Data
                        • STAT
                        • Product Updates
                        Moz Solutions
                        • SMB Solutions
                        • Agency Solutions
                        • Enterprise Solutions
                        • Digital Marketers
                        Free SEO Tools
                        • Domain Authority Checker
                        • Link Explorer
                        • Keyword Explorer
                        • Competitive Research
                        • Brand Authority Checker
                        • Local Citation Checker
                        • MozBar Extension
                        • MozCast
                        Resources
                        • Blog
                        • SEO Learning Center
                        • Help Hub
                        • Beginner's Guide to SEO
                        • How-to Guides
                        • Moz Academy
                        • API Docs
                        About Moz
                        • About
                        • Team
                        • Careers
                        • Contact
                        Why Moz
                        • Case Studies
                        • Testimonials
                        Get Involved
                        • Become an Affiliate
                        • MozCon
                        • Webinars
                        • Practical Marketer Series
                        • MozPod
                        Connect with us

                        Contact the Help team

                        Join our newsletter
                        Moz logo
                        © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                        • Accessibility
                        • Terms of Use
                        • Privacy