How do you know a site is hacked?
Hacked means someone broke in without your permission. Common signs are:
- Your pages show strange content or ads.
- Visitors are sent to other websites.
- Search results show odd titles for your site.
- A browser warns visitors that your site is unsafe.
- There are files or users you did not create.
- Your site sends spam email.
Steps to clean it
- Stay calm and act fast. The longer a hack stays, the more damage it does.
- Change your passwords. Do this for your hosting account, FTP, database, email and your website admin. Use long passwords nobody can guess. Use a different one for each. Change them from a clean computer.
- Scan your computer. Run an antivirus scan. A virus on your PC may have leaked your passwords.
- Back up the hacked site. Save a copy for checking later. Do not mix it with an older, clean backup.
- Look for a clean backup. If you have one from before the hack, restoring it is often the fastest fix. Ask Hostvento support whether backups are available on your plan.
- Remove bad files. Open File Manager and check for files you do not know. Sort by date modified to spot recent ones. Look in the upload folders for files ending in
.php, which should not be there. - Replace core files. Download a fresh copy of your CMS (the software that runs your site, like WordPress or Joomla). Upload it over the old core files. Keep your own content and settings file.
- Check admin users. Delete any admin you did not create.
- Check the database. Hackers sometimes add spam links to posts. Search for odd text.
- Check
.htaccess. Look for redirect lines you did not add. - Update everything. Update your CMS, themes and plugins. Delete ones you do not use.
- Ask for help. Open a support ticket and say your site is hacked. A malware scan tool can also find hidden code.
Tip: Never delete files in a hurry without a backup. Some are real files your site needs.
Stop it from happening again
- Use strong, unique passwords and change them often.
- Keep all software updated.
- Use only themes and plugins from trusted sources.
- Take regular backups and store a copy off the server.
- Limit who has admin access.
- Use an SSL certificate so your site runs over HTTPS.
Quick recap
- Change all passwords first.
- Back up, then clean or restore.
- Remove unknown files and users.
- Update software and ask support if you are stuck.