✔ Site Hacked again!!
Completed by Hector M.
- Assigned to
-
Hector M.
- Due on
- Notes
-
Isaac
I am seeing that the site has been hacked once again.
Their Google search console is showing thousands of pages to the Canadian drugstore again.
Few examples below...
https://doceremedspa.com/mgpills/zovirax-website/86/
https://doceremedspa.com/mgpills/women-shouldnt-take-viagra/86/
We need to do this all over again. However, we must change something since they have hacked the site again.
Your thoughts?
Ivonne
please take note.
whitney.zelig@gmail.com
I could probably sell them a whole new website? Would that help?
I believe the latter may be more accurate.
Right now, Google is using a warning for many of the pages visitors find on search results. We will not be able to remove that warning until this is resolved.
Once they reply back the website has been cleaned. I will ask them if they were able to find the loophole this time or tell us how it happened. If they tells us they were able to find the loophole and give us a surity that these same hackers wouldn't be able to inject the website with the malicious script again. We can keep the website. But if they say they can't find the source from where the hack happened. I think it would be best if we go with a different premium service for cleaning the website or build a new website altogether.
If the script is in one of the files, wouldn't that transfer over even if we create a new site?
Can we get a list of all pluggins so I can check them for any vulnerability?
On the new website we wouldn't be using any of the files from the old website. It would be from scratch or else there would be no point.
This is already done by the security company and also by wpengine. While cleaning the website if they find out any plugin and it's latest version has any vunerability they ask us to immediately remove it from the website.
WPengine has confirmed the website has been cleaned now. They couldn't give a concrete reply regarding how this happened so if we can sell them a whole new website. We should do it. If they say NO let me know and I will set up a firewall on the website. That should help.
Thanks for the thorough explanation.
I think we should set up the firewall regardless of whether or not we sell them a new website. Because if they hacked it twice, there's a 98% chance they will be able to hack into it again. And let's remember that it hasn't even been 2 months since they last did it.
Selling and setting up the new website may take longer than 2 months so we would be hacked again.
do you concur or do you have another idea?
I can also ask shanes friend to help?
https://sucuri.net/website-security-platform/signup/#firewall
Thanks for confirming WZ.
So I have 2 CC's on file for Lori and Docere
Can you please let me know which one of these they might want us to use? Or if they want to use another one?
Question for you Isaac.
If we set up the Firewall, it will keep the hackers out from incoming new attacks. But what if the vulnerability is with a pluggin? Will the firewall still work?
I will prepare it for you and send it to you once I am done.
Can you please initiate a validate fix so we can get rid of all the Viagra hacked pages which are indexed?
Thanks.
Tagging you once again in case you missed the other one..
Please let me know when you initiate the fix.
Thanks.
My bad, I forgot you were on vacation.
So I resubmitted the sitemap. Have the other pages been removed?
I initiated validate fix as well.
Can you please check on the indexed pages for this client so you can then initiate the validate fix for them?
I am still seeing thousands of the spam pages marked as 404s
I will follow up in a few weeks.
Thank you.
Any idea why this validations are taking so long?
This particular one was started
I am updating the due date for another month.