{"id":24866,"date":"2015-02-18T00:00:00","date_gmt":"2015-02-18T00:00:00","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/case-studies-fixing-hacked-sites\/"},"modified":"2015-02-18T00:00:00","modified_gmt":"2015-02-18T00:00:00","slug":"case-studies-fixing-hacked-sites","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/case-studies-fixing-hacked-sites\/","title":{"rendered":"Case Studies: Fixing Hacked Sites"},"content":{"rendered":"<p class=\"gargardate\">Wednesday, February 18, 2015<\/p>\n<p>\n  Every day, thousands of websites get hacked. Hacked sites can harm users by serving malicious<br \/>\n  software, collecting personal information, or redirecting them to sites they didn&#8217;t intend to<br \/>\n  visit. Webmasters want to fix hacked sites quickly, but unfortunately recovering from a hack can<br \/>\n  be a complicated process.\n<\/p>\n<p>\n  We&#8217;re trying to make the process of recovering from a hack easier for webmasters with features like<br \/>\n  <a href=\"https:\/\/search.google.com\/search-console\/security-issues\" class=\"external-link\">Security Issues<\/a>,<br \/>\n  <a href=\"https:\/\/developers.google.com\/web\/fundamentals\/security\/hacked\" class=\"external-link\">Help for Hacked Sites<\/a>, and<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/threads?hl=en&#038;thread_filter=(category:security_malware_hacked)\" class=\"external-link\">a section of our forum just for hacked sites<\/a>.<br \/>\n  Recently we talked to two webmasters with hacked sites to learn more about how they were able to<br \/>\n  fix their sites. We&#8217;re sharing their stories with the hope that they might provide ideas to other<br \/>\n  webmasters who have been victims of hacking. We&#8217;re also using these stories and other feedback for<br \/>\n  improving our documentation for hacked sites to make the process easier for everyone going<br \/>\n  forward.\n<\/p>\n<h2 id=\"case-study-1:-restaurant-website-with-multiple-hack-injected-scripts\" tabindex=\"-1\">Case Study #1: Restaurant website with multiple hack-injected scripts<\/h2>\n<p>\n  A restaurant website using WordPress received a message from Google in their Webmaster Tools<br \/>\n  account, alerting them that their site had been altered by hackers. To protect Google users, the<br \/>\n  website was labelled as hacked in Google&#8217;s search results. The webmaster of the site, Sam, looked<br \/>\n  at the source code and noticed many unfamiliar links on the site with pharmaceuticals terms such<br \/>\n  as &#8220;viagra&#8221; and &#8220;cialis.&#8221; She also noticed many pages where the meta description tags (in the<br \/>\n  HTML) had added content such as &#8220;buy valtrex in florida.&#8221; There were also hidden <code>div<\/code><br \/>\n  tags (also in the HTML) of many pages that linked to many sites. None of these links were added<br \/>\n  by Sam.\n<\/p>\n<p>\n  Sam removed all of the hacked content she found and filed a reconsideration request. The request<br \/>\n  was rejected but in the message she received from Google, she was advised to check for any<br \/>\n  unfamiliar scripts in the any PHP files (or any other server files), as well as changes to the<br \/>\n  <a href=\"https:\/\/httpd.apache.org\/docs\/trunk\/howto\/htaccess\" class=\"external-link\"><code>.htaccess<\/code><\/a><br \/>\n  file. These files are likely to have scripts added by the hackers that modify the site. These<br \/>\n  scripts typically only show the hacked content to search engines, while hiding the content from a<br \/>\n  normal user. Sam checked out all of the <code>.php<\/code> files and compared them to the clean<br \/>\n  copies she had in her backup. She found new content added to her <code>footer.php<\/code>,<br \/>\n  <code>index.php<\/code>, and <code>functions.php<\/code>. When she replaced those files with the<br \/>\n  clean backups, she could no longer find any hacked content on her site. When she filed another<br \/>\n  reconsideration request, she got a response from Google notifying her that her site no longer had<br \/>\n  hacked content!\n<\/p>\n<p>\n  Even though Sam had cleaned up the hacked content on her site, she knew that she would need to<br \/>\n  continue to<br \/>\n  <a href=\"https:\/\/codex.wordpress.org\/Hardening_WordPress\" class=\"external-link\">secure her site<\/a><br \/>\n  against future attacks. She followed the steps below to keep her site safe in the future:\n<\/p>\n<ul>\n<li>\n    Keep the CMS (content management system like WordPress, Joomla, Drupal, etc) up to date with the<br \/>\n    most current version. Make sure plugins are up to date as well.\n  <\/li>\n<li>\n    Make sure the account used to access the administrative features of the CMS uses a difficult and<br \/>\n    unique password.\n  <\/li>\n<li>\n    If the CMS supports it, enable<br \/>\n    <a href=\"https:\/\/en.support.wordpress.com\/security\/two-step-authentication\/\" class=\"external-link\">2-step verification<\/a><br \/>\n    for login. (This might also be called two factor authentication or two step authentication.)<br \/>\n    This is recommended for the account being used for password recovery as well. Most email<br \/>\n    providers, like<br \/>\n    <a href=\"https:\/\/www.google.com\/landing\/2step\/\" class=\"external-link\">Google<\/a>,<br \/>\n    <a href=\"https:\/\/windows.microsoft.com\/en-us\/windows\/two-step-verification-faq\" class=\"external-link\">Microsoft<\/a>,<br \/>\n    <a href=\"https:\/\/help.yahoo.com\/kb\/activate-sign-in-verification-sln5013\" class=\"external-link\">Yahoo!<\/a><br \/>\n    all support this!\n  <\/li>\n<li>\n    Make sure the plugins and themes installed are from a reputable source&mdash;pirated plugins or<br \/>\n    themes can often contain code that makes it even easier for hackers to get in!\n  <\/li>\n<\/ul>\n<h2 id=\"case-study-2:-professional-website-with-lots-of-hard-to-find-hacked-pages\" tabindex=\"-1\">Case Study #2: Professional website with lots of hard to find hacked pages<\/h2>\n<p>\n  A small business owner named Maria who also manages her own website received a message in her<br \/>\n  Webmaster Tools that her site was hacked. The message provided an example of a page added by<br \/>\n  hackers: <code>https:\/\/example.com\/where-to-buy-cialis-over-the-counter\/<\/code>. She talked to her<br \/>\n  hosting provider who looked at the source code on the home page but could not find any<br \/>\n  pharmaceutical keywords. When the hosting provider visited<br \/>\n  <code>https:\/\/example.com\/where-to-buy-cialis-over-the-counter\/<\/code>, it returned an error page.<br \/>\n  Maria also bought a malware scanning service but the service was not able to find any malicious<br \/>\n  content on her site.\n<\/p>\n<p>\n  Maria then went to Webmaster Tools and used the Fetch as Google tool on the example URL Google had<br \/>\n  provided (<code>https:\/\/example.com\/where-to-buy-cialis-over-the-counter\/<\/code>) which returned<br \/>\n  no content. Confused, she filed a reconsideration request and received a rejection message which<br \/>\n  advised her to do two things:\n<\/p>\n<ol>\n<li>\n<p>\n      Verify the non-www version of her site as hackers often try to hide content in folders that<br \/>\n      may be overlooked by the webmaster.\n    <\/p>\n<p>\n      While it may seem like <code>https:\/\/example.com<\/code> and <code>https:\/\/www.example.com<\/code><br \/>\n      are the same site, Google actually treats these as different sites.<br \/>\n      <code>https:\/\/example.com<\/code> is referred to as the &#8220;root domain&#8221; while<br \/>\n      <code>https:\/\/www.example.com<\/code> is called the subdomain. Maria had<br \/>\n      <code>https:\/\/www.example.com<\/code> verified but not <code>https:\/\/example.com<\/code> verified<br \/>\n      which is important because the pages added by hackers were non-www pages like<br \/>\n      <code>https:\/\/example.com\/where-to-buy-cialis-over-the-counter\/<\/code>. Once she verified<br \/>\n      <code>https:\/\/example.com<\/code> she was able to successfully see the hacked content on the<br \/>\n      provided URL with the Fetch as Google tool in Webmaster Tools.\n    <\/p>\n<\/li>\n<li>\n<p>Check her <code>.htaccess<\/code> file for new rules.<\/p>\n<p>\n      Maria talked to her hosting provider who showed her how to access her <code>.htaccess<\/code><br \/>\n      file. She noticed right away that her <code>.htaccess<\/code> file had some strange content<br \/>\n      that she had not added:\n    <\/p>\n<div><\/div>\n<p>\n      The<br \/>\n      <a href=\"https:\/\/httpd.apache.org\/docs\/2.0\/misc\/rewriteguide\" class=\"external-link\"><code>mod_rewrite<\/code><\/a><br \/>\n      rule you see above was inserted by the hacker and redirects anyone coming from certain search<br \/>\n      engines, as well as search engine crawlers, to main.php, which generates all of the hacked<br \/>\n      content. It&#8217;s also possible that these rules can redirect users accessing the site on a mobile<br \/>\n      device. On the same day, she also saw that a recent malware scan found suspicious content on<br \/>\n      the <code>main.php<\/code> file. One top of that, she also noticed an unknown user in the FTP<br \/>\n      users area of her website development software.\n    <\/p>\n<\/li>\n<\/ol>\n<p>\n  She removed the <code>main.php<\/code> file, the <code>.htaccess<\/code> file, and removed the<br \/>\n  unknown user from her FTP users area and her site was no longer hacked!\n<\/p>\n<h2 id=\"steps-to-prevent-getting-hacked-in-the-future\" tabindex=\"-1\">Steps to prevent getting hacked in the future<\/h2>\n<ul>\n<li>\n    Avoid using FTP when transferring files to your servers. FTP does not encrypt any traffic,<br \/>\n    including passwords. Instead, use SFTP, which will encrypt everything, including your password,<br \/>\n    as a protection against eavesdroppers examining network traffic.\n  <\/li>\n<li>\n    Check the permissions on sensitive files like <code>.htaccess<\/code>. Your hosting provider may<br \/>\n    be able to assist you if you need help. The <code>.htaccess<\/code> file can be used to improve<br \/>\n    and protect your site, but it can also be used for malicious hacks if they are able to gain<br \/>\n    access to it.\n  <\/li>\n<li>\n    Be vigilant and look for new and unfamiliar users in your administrative panel and any other<br \/>\n    place where there may be users that can modify your site.\n  <\/li>\n<\/ul>\n<p>\n  We hope your site never gets hacked, but if it does, we have many resources for hacked webmasters<br \/>\n  on our<br \/>\n  <a href=\"https:\/\/developers.google.com\/web\/fundamentals\/security\/hacked\" class=\"external-link\">Help for Hacked Sites page<\/a>. If<br \/>\n  you need more help or would like to share your own tips, you can post in our<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/threads?hl=en&#038;thread_filter=(category:security_malware_hacked)\" class=\"external-link\">Webmaster Help Forum<\/a>.<br \/>\n  If you do post to the forum or submit a reconsideration request for your site, please include<br \/>\n  <code>#NoHacked<\/code>.\n<\/p>\n<p class=\"byline-author\">Posted by Julian Prentice and Yuan Niu, Search Quality Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wednesday, February 18, 2015 Every day, thousands of websites get hacked. Hacked sites can harm users by serving malicious software, collecting personal information, or redirecting them to sites they didn&#8217;t intend to visit. Webmasters want to fix hacked sites quickly, but unfortunately recovering from a hack can be a complicated process. We&#8217;re trying to make [&hellip;]<\/p>\n","protected":false},"menu_order":83516,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[665],"ar_kb_etiket":[],"class_list":["post-24866","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-blog"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24866","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/24866\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27052"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=24866"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=24866"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=24866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}