Diagnostics and recovery

Hacked sites and security recovery

Ask AI about this page

2 views 2 min read

Compromised sites are treated by Baidu as a security matter with immediate consequences, and the common forms — hijacking, injected content, mirrored copies — appear across several of its algorithms and policies.

What compromise looks like in search

  • Hijacking — visitors arriving from search are redirected elsewhere, or the back button is captured. Fenghuo covers this behaviour whether or not the owner caused it.
  • Injected pages — gambling, pharmaceutical or adult content published in a directory nobody maintains, usually invisible to anyone who reaches the site by typing its address.
  • Mirroring — the site’s content served on another domain, which Baidu names as a cause of index-volume loss because it can index the copy and reject the original.
  • Data theft — code harvesting visitor information, which is what the Tianwang algorithm was built for and is now also a legal exposure under Chinese data law.

How to find it

  1. Load the site as a search visitor: mobile user agent, arriving from a search result, no cookies. Injected redirects fire only in that state.
  2. Read the indexed page list in the platform. URLs nobody recognises are the finding — Baidu crawled them, so they exist.
  3. Enumerate subdomains and directories actually being served, not the ones the team remembers.
  4. Check the crawl exceptions report for unexpected patterns.
  5. Compare what the spider receives with what a browser receives — cloaked injections differ between them.

Recovery, in order

  1. Find the entry point before cleaning. Cleaning first means being reinfected within days.
  2. Patch, rotate credentials, remove unknown accounts and plugins.
  3. Clean the injected content and submit the removed URLs as dead links.
  4. Verify from the search-visitor perspective again.
  5. Submit feedback through the platform once the site is genuinely clean.

The prevention that matters

Old CMS installations in forgotten subdirectories are the usual entry point, and forgotten sections are also what Lantian penalises when a third party takes them over. Enumerating what the domain actually serves — and decommissioning what nobody maintains — is both a security measure and a search one.

Alien Road

How we apply this

Every case of injected content we have handled lived in a directory the client had forgotten they served, usually an old CMS. We enumerate from the platform’s index data rather than asking what exists, because the whole point is that nobody knows. And we find the entry point before cleaning: a cleaned site with an unpatched hole is reinfected inside a week, and the second flag is far more expensive than the first.

Related services

Share

© Copyright 2026 Alien Road. All rights reserved.