The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Technical SEO Issues
    4. Hacking and security

    Hacking and security

    Technical SEO Issues
    14 4 262
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • PaddyDisplays
      PaddyDisplays @ClaireH-184886 last edited by

      If each site was on a different domain and were completely separate (separate ftp access, separate mysql database access,  no master/common username and passwords etc)  then that might point to a problem with the hosting side, but to be honest it really hard to know, with our proper investigation.

      Since your not technically minded you would be better getting someone with more technical knowledge to review you current setup to see if it was the hosts failing or it was the way you have your sites set up, there is just too many unknowns to get conclusive help from a forum.

      Hope that helps

      ClaireH-184886 1 Reply Last reply Reply Quote 0
      • ClaireH-184886
        ClaireH-184886 @PaddyDisplays last edited by

        ok thanks. The sites all have their own access but are all on the dedicated server. they can all be gained through a whm where we can change cpanel passwords and usernames but besides that they have no connection.

        PaddyDisplays 1 Reply Last reply Reply Quote 0
        • PaddyDisplays
          PaddyDisplays @ClaireH-184886 last edited by

          I'm not an expert (but have some experience) , but if they are truly separated, and the word press sites were up to date but were hacked too, then there is something very wrong.

          ClaireH-184886 1 Reply Last reply Reply Quote 0
          • ClaireH-184886
            ClaireH-184886 @PaddyDisplays last edited by

            i am waiting for the hosting company to get back to me, they have been working on this now for over 24 hours, i have sent them some questions but they have said they cannot answer them yet. it seems strange that the wordpress sites were hacked and they were all hacked even though they all had seperate logins

            ClaireH-184886 1 Reply Last reply Reply Quote 0
            • ClaireH-184886
              ClaireH-184886 @ClaireH-184886 last edited by

              just got this from my hosting company

              Hello,

              1. The server was not hacked. The application on these account has been compromised. In order to have the exact reason and coding vulnerability which allowed this to happen you may contact certified developer as we do not offer development services at this point.

              2. Review the above. What we do is secure the service on the server by applying all the patches available for the same. The coding and the updates on your website functions and coding is your responsibility. The review and patching of any script you use for your website is development related task.

              3. Again you will have to request this from expert web developer as s/he may review the coding of your website and provide the reason why and how it has been compromised.

              4. Contact certified developer with proven feedback to review and patch your websites coding.

              5. The answer to this question you may check here:

              http://docs.cloudlinux.com/

              Should you have any further questions or comments please do not hesitate to contact us.

              Best regards,

              PaddyDisplays 1 Reply Last reply Reply Quote 0
              • PaddyDisplays
                PaddyDisplays @ClaireH-184886 last edited by

                Yeah standard, "its not our problem" response.

                As I said before, if the joomla site shared something like mysql database access then it was most likely not the hosts fault.

                I have seen hosts blame opensource cms when actually they were just trying to hide their issues.  Its going to be impossible to know until someone looks properly into it (which hosts will not do, which is fair enough).

                1 Reply Last reply Reply Quote 0
                • AlanMosley
                  AlanMosley last edited by

                  I don't think its the server, wordpress and other cms are continually hacked. The server can not stop much at all. your code needs stop most hacks, and since wordpress is used by so many, all some one needs to do is hack their own and then they can go out and hack all wordpress sites of the same version.

                  PaddyDisplays 1 Reply Last reply Reply Quote 0
                  • PaddyDisplays
                    PaddyDisplays @AlanMosley last edited by

                    What your saying is true, but I have never heard of anyone getting hacked (bar brute forcing password or poor passwords), if they keep upto date with the security fixes.

                    Some hosts eg dreamhost will auto update installs for you , so you don't have to worry about  updating.

                    ClaireH-184886 1 Reply Last reply Reply Quote 0
                    • ClaireH-184886
                      ClaireH-184886 @PaddyDisplays last edited by

                      will have to look at dreamhost and see how much they charge for dedicated server. do they offer managed dedicated server. also the hosting company is not taking any responsibility.

                      would you expect the hosting company to let you know that your site has been hacked or is it down to yourself to know

                      PaddyDisplays 1 Reply Last reply Reply Quote 0
                      • PaddyDisplays
                        PaddyDisplays @ClaireH-184886 last edited by

                        I have only used dreamhosts shared hosting, don't know about dedicated.

                        "would you expect the hosting company to let you know that your site has been hacked or is it down to yourself to know"

                        Generally no, that you be your responsibility (or if your have a maintenance contact with the web developer).

                        Again dreamhost has some cool auto safe guards eg one of my clients had malware/virus on his pc and was sending out spam, they auto reset the password when it was picked up.  I also think they have other auto features to inform you about hacking, but its guaranteed service, its just a bonus they do.

                        I'm not saying you should go with dreamhost, I'm just telling you what they can/have done, (i have only use a few host companies)  but I'm sure there are alot of hosts that do that too (maybe even more).

                        1 Reply Last reply Reply Quote 0
                        • altecdesign
                          altecdesign last edited by

                          The wordpress hacking was almost surely due to having outdated version of WP, or having a vulnerable plugin installed.  There are a few helpful plugins you can use to secure your WP site, plugins like (http://wordpress.org/plugins/better-wp-security/).

                          also a couple things to note, you should also take basic measures to project the site by changing the default table prefixes of your DB from _wp,  create a new admin user and delete the default "admin" accoun & limit access to your wp-admin section in your .htaccess file.... these security plugins will give you a whole checklist of items to "secure".

                          1 Reply Last reply Reply Quote 1
                          • 1 / 1
                          • First post
                            Last post
                          • Manual action due to hack
                            Joe_Stoffel
                            Joe_Stoffel
                            0
                            8
                            96

                          • Secure and non-secure Schema.org Markup?
                            RoxBrock
                            RoxBrock
                            0
                            3
                            539

                          • Ecommerce and Secure Checkout
                            BlueprintMarketing
                            BlueprintMarketing
                            0
                            4
                            134

                          • Have my SERP listings been hacked?
                            evolvingSEO
                            evolvingSEO
                            0
                            7
                            503

                          • Site Got Hacked! Need Help!
                            irvingw
                            irvingw
                            0
                            3
                            386

                          • Secure Vs Non-Secure Redirects
                            AlanMosley
                            AlanMosley
                            0
                            2
                            357

                          • Website hacked
                            KeriMorgret
                            KeriMorgret
                            0
                            10
                            554

                          • RSS Hacking Issue
                            Kerry22
                            Kerry22
                            0
                            6
                            750

                          Get started with Moz Pro!

                          Unlock the power of advanced SEO tools and data-driven insights.

                          Start my free trial
                          Products
                          • Moz Pro
                          • Moz Local
                          • Moz API
                          • Moz Data
                          • STAT
                          • Product Updates
                          Moz Solutions
                          • SMB Solutions
                          • Agency Solutions
                          • Enterprise Solutions
                          • Digital Marketers
                          Free SEO Tools
                          • Domain Authority Checker
                          • Link Explorer
                          • Keyword Explorer
                          • Competitive Research
                          • Brand Authority Checker
                          • Local Citation Checker
                          • MozBar Extension
                          • MozCast
                          Resources
                          • Blog
                          • SEO Learning Center
                          • Help Hub
                          • Beginner's Guide to SEO
                          • How-to Guides
                          • Moz Academy
                          • API Docs
                          About Moz
                          • About
                          • Team
                          • Careers
                          • Contact
                          Why Moz
                          • Case Studies
                          • Testimonials
                          Get Involved
                          • Become an Affiliate
                          • MozCon
                          • Webinars
                          • Practical Marketer Series
                          • MozPod
                          Connect with us

                          Contact the Help team

                          Moz logo
                          © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                          • Accessibility
                          • Terms of Use
                          • Privacy