The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Intermediate & Advanced SEO
    4. Articles marked with "This site may be hacked," but I have no security issues in the search console. What do I do?

    Articles marked with "This site may be hacked," but I have no security issues in the search console. What do I do?

    Intermediate & Advanced SEO
    7 3 373
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Liggins
      Liggins last edited by

      There are a number of blog articles on my site that have started receiving the "This site may be hacked" warning in the SERP.

      I went hunting for security issues in the Search Console, but it indicated that my site is clean. In fact, the average position of some of the articles has increased over the last few weeks while the warning has been in place.

      The problem sounds very similar to this thread: https://productforums.google.com/forum/#!category-topic/webmasters/malware--hacked-sites/wmG4vEcr_l0 but that thread hasn't been touched since February. I'm fearful that the Google Form is no longer monitored.

      What other steps should I take?

      One query where I see the warning is "Brand Saturation" and this is the page that has the warning: http://brolik.com/blog/should-you-strive-for-brand-saturation-in-your-marketing-plan/

      1 Reply Last reply Reply Quote 0
      • CleverPhD
        CleverPhD last edited by

        It is hacked, you just have to look at the page as Googlebot.  Sadly, I have seen this before.

        If you set your user agent as Googlebot -  you will see a different page (see attached images).  Note that the  Title, H1 tags and content are updated to show info on how to Buy Zithromax.   This is a JS insertion hack where when the user agent is shown as Googlebot they overwrite your content and insert links to pages to help gain links.  This is very black hat and bad and yes scary.  (See attached images below)

        I use "User Agent Switcher" on FF to set my user agent - there are lots of other tools for FF and Chrome to do this.  You can also run a spider on your site such as screaming frog and set the user agent to Googlebot and you will see all the changed H1s and title tags,

        It is clever as "humans" will not see this, but the bots will so it is hard to detect.  Also, if you have multiple servers, you may only have 1 of the servers impacted and so you may not see this each time depending on what server your load balancer is sending you to.  You may want to use Fetch as Google in Webmaster console and see what Google sees.

        This is very serious, show this to your dev and get it fixed ASAP.  You can PM me if you need more information etc.

        Good luck!

        mI1yZjN.png qMLv3Wa.png?1

        Liggins 1 Reply Last reply Reply Quote 4
        • Liggins
          Liggins @CleverPhD last edited by

          Passed it on to the dev. Thanks for the response.

          I'll let you know if they run into any trouble cleaning it up.

          1 Reply Last reply Reply Quote 1
          • ThompsonPaul
            ThompsonPaul last edited by

            Just a heads-up that you'll want to get this cleaned up as quickly as possible, Matthew. Time really is of the essence here.

            Once this issue is recognised by the crawler as being widespread enough to trigger a warning in GSC, it can take MONTHS to get the hacked warning removed from the SERPS after cleanup.

            Get the hack cleaned up, then immediately start submitting the main pages of the site back to Fetch as Google tool to get them recrawled and detected as clean.

            I recently went through a very similar situation with a client and was able to get the hacked notification removed for most URLs within 3 and 4 days of cleanup.

            Paul

            1 Reply Last reply Reply Quote 1
            • Liggins
              Liggins last edited by

              Thank you, Paul. That was going to be my next question: what to do when the blog is clean.

              Unfortunately, the dev's are still frantically pouring through code hunting for the problem. Hopefully they find it soon.

              1 Reply Last reply Reply Quote 0
              • ThompsonPaul
                ThompsonPaul last edited by

                It looks like the devs have cleaned up most of the obvious stuff, Matthew, so I'd get to work resubmitting the pages that were marked as hacked but now longer show that issue.

                Do make sure the devs keep working on finding and cleaning up attack vectors (or just bite the bullet and pay for a year of Sucuri cleanup and protection) but it's important to get those marked pages discovered as clean before too much longer.

                Also of note - your site's server's Apache install is quite a bit out of date and you're running a very old version of PHP as well that hasn't been getting even security updates for over a year. Those potential attack vectors need to be addressed right away too.

                Good luck getting back into Big G's good graces!

                Paul

                P.S. Easy way to find the pages marked as hacked for checking/resubmission is a "site:" search e.g. enter **site:brolik.com **into a Google search.

                P.P.S. Also noted that you have many pages from brolik-temp.com also still indexed. The domain name just expired yesterday, but the indexed pages showed a 302-redirect to the main domain, according to the Wayback Machine. These should be 301s in order to help get the pages to eventually drop out of the SERPS. (And with 301s in place, you could either submit a "Change of Address" for that domain in Webmaster Tools/GSC or you do a full removal request. Either way, I wouldn't want those test domain pages to remain in the indexes.

                1 Reply Last reply Reply Quote 1
                • Liggins
                  Liggins last edited by

                  Thanks, Paul. We started resubmitting the cleaned pages yesterday. I passed your comments about the Apache install and the old version of PHP to the devs as well.

                  At the very least, this is a great learning experience for us. It's great to have such a helpful community.

                  1 Reply Last reply Reply Quote 0
                  • 1 / 1
                  • First post
                    Last post
                  • Huge spike in "access denied" in search console
                    fbchris
                    fbchris
                    0
                    3
                    336

                  • [Very Urgent] More 100 "/search/adult-site-keywords" Crawl errors under Search Console
                    CleverPhD
                    CleverPhD
                    0
                    6
                    341

                  • Google WMT/search console showing thousands of links in "Internal Links"
                    vtmoz
                    vtmoz
                    0
                    3
                    109

                  • Need to update Google Search Console profile for http to https change. Will a "change of address" option suffice or do we need to create a new GSC profile?
                    DmitriiK
                    DmitriiK
                    0
                    2
                    93

                  • Google Search Console > Security Issues
                    BritneyMuller
                    BritneyMuller
                    0
                    3
                    385

                  • Can a "site split" cause a drastic organic search decline?
                    MattAntonino
                    MattAntonino
                    0
                    3
                    216

                  • Why does old "Free" site ranks better than new "Optimized" site?
                    WhatUpHud
                    WhatUpHud
                    0
                    5
                    100

                  • Alexa site title shows as "302 Found" on search result pages
                    john4math
                    john4math
                    0
                    3
                    661

                  Get started with Moz Pro!

                  Unlock the power of advanced SEO tools and data-driven insights.

                  Start my free trial
                  Products
                  • Moz Pro
                  • Moz Local
                  • Moz API
                  • Moz Data
                  • STAT
                  • Product Updates
                  Moz Solutions
                  • SMB Solutions
                  • Agency Solutions
                  • Enterprise Solutions
                  • Digital Marketers
                  Free SEO Tools
                  • Domain Authority Checker
                  • Link Explorer
                  • Keyword Explorer
                  • Competitive Research
                  • Brand Authority Checker
                  • Local Citation Checker
                  • MozBar Extension
                  • MozCast
                  Resources
                  • Blog
                  • SEO Learning Center
                  • Help Hub
                  • Beginner's Guide to SEO
                  • How-to Guides
                  • Moz Academy
                  • API Docs
                  About Moz
                  • About
                  • Team
                  • Careers
                  • Contact
                  Why Moz
                  • Case Studies
                  • Testimonials
                  Get Involved
                  • Become an Affiliate
                  • MozCon
                  • Webinars
                  • Practical Marketer Series
                  • MozPod
                  Connect with us

                  Contact the Help team

                  Join our newsletter
                  Moz logo
                  © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                  • Accessibility
                  • Terms of Use
                  • Privacy