My website has been hacked by a porn site

  • Unknown's avatar

    Help!!
    My website has been hacked by a porn site. It is very graphic and I am a teacher. Not good!
    Roberta

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar

    I just reset my password on WordPress.com to see if that would help. It hasn’t.

  • Unknown's avatar

    Hello there,
    re: hacked accounts and blogs

    If anyone is posting anything to your blog or removing anything from it, or changing anything in it, or if your blog has been deleted and you did not delete it, then it’s most likely that you have provided them with the ability to do so, either deliberately by adding them as official users, or by allowing them access to your login information, or by posting content that makes it easy for them to guess what your log-in information is.

    For you, the question that needs to be answered is: Who, aside from me, has access to my login information?

    Go to your email program immediately and change the password to a very difficult one because that’s how many hackers gain access to blogs.

    Read > http://en.support.wordpress.com/security/

    Change your blog password to a very difficult one > http://en.support.wordpress.com/passwords/#change-your-password
    You can also reset your password via your Settings tab on the WordPress.com home page:
    http://wordpress.com/#!/settings/

    Disable post by email https://en.support.wordpress.com/settings/email-post-changes/

    Use a secure, encrypted connection to connect to your Dashboard. Under Users → Personal Settings, check the box that says “Always use HTTPS when visiting administration pages, and click Save Changes.

    Use two step authentication http://en.support.wordpress.com/security/two-step-authentication/

    Run a security scan on your computer. See here to run a security scan http://geekflare.com/online-scan-website-security-vulnerabilities/

    Never leave your computer logged into your blog and walk away from it. Always log out properly.

    Also, be aware that Staff have records of who did what under which username and login information and when they did it. I flagged this thread with modlook for a Staff follow-up. Please subscribe to it so you are notified when they respond. To subscribe look in the sidebar of this thread, find the subscribe to topics link and click it. Note that there is a backlog and be patient while waiting.

  • Unknown's avatar

    I note that this site https://robertamcnaughton.wordpress.com/ is an old empty one. We cannot help anyone who does not provide the relevant URL for the site they are referring to so do that now please.

    What is the exact URL starting with http:// of the wordpress.COM hosted site you refer to please?

    And, exactly which wordpress.COM username account registered that site?

    This is wordpress.COM support. I’m asking because we cannot accurately answer questions posted here until we have confirmed the URL referred to and verified the hosting.
    We provide support only for wordpress.COM hosted sites. Our support docs do not apply to
    (1) local installs of wordpress.ORG software on your own server or
    (2) wordpress.ORG software installs on paid hosting, and we do not provide support for them at wordpress.COM. That support is found at http://wordpress.ORG/support/
    Also, note that we do not provide Jetpack support https://jetpack.me/support/ for sites linked to wordpress.COM accounts with the Jetpack plugin so they display on the My Sites wordpress.com account page.

  • Hi @robertalmcnaughton, we don’t see any sites like that on our servers. Just two older accounts.

    To be clear, WordPress.com is a service. WordPress.org is free software that you can install and maintain on your own. It sounds like you have your own copy, and it was not well maintained :(

    If you’d like to consider moving your site here (where we maintain the software for you) we can help you point the domain to our servers and what not. Let us know if you want to go that route.

    You may need some help from your host or a contractor to get rid of the current hack first though. You can also get help from the WordPress.org community here:
    https://wordpress.org/support

    I hope you can fix that quickly!

  • @robertalmcnaughton if possible, have your host restore the site to its pre-hacked state first.

    Then you can update the software / hire a contractor if needed. You could also export the site and move it here so we’ll cover security for you.

  • Unknown's avatar

    Oy, I didn’t set it up in the first place. It was rerouted in such a way that I could have my name as the url without wordpress in the url and so I am the manager but I don’t know how it has been routed. web.com is my server for robertamcnaughton.com. I’ll call them again and see if they can help get rid of the hack.

    After that I will look to wordpress.org and then if it isn’t solved I’ll contact wordpress.com and set up my site there.

    Thank you so much! I’ll be in touch today no doubt.

    Roberta

  • Unknown's avatar

    I would love to expedite this process and gain control of the site again by exporting it to you, but I don’t even see it here for exporting?

    How much does WordPress.com cost per month to host a site and do I keep the robertamcnaughton.com url?

  • Unknown's avatar

    I just exported robertamcnaughtonwordpress.com and there is no content/ no files.

    my website url was robertamcnaughton.com. Not sure where that is anymore. I haven’t been keeping it up for a number of years. It is in need of a redesign for sure, but I would like to get the content to rebuild with.

  • Unknown's avatar

    My site robertamcnaughton.com has been reverted back to it’s original content from 6 months ago so the pornography hack is now gone.

    I would like to now redesign the site and get a better handle on it so that this doesn’t happen again from my neglect of the site.

    The problem is – I am on wordpress.com and in “my sites” and I don’t see any content to redesign. the message displayed is – “Not Found
    Apologies, but no results were found for the requested archive. Perhaps searching will help find a related post.”

    Is it lost? Am I looking in the wrong place?

  • Unknown's avatar

    To be clear: you wrote – @robertalmcnaughton if possible, have your host restore the site to its pre-hacked state first.
    Then you can update the software / hire a contractor if needed. You could also export the site and move it here so we’ll cover security for you.

    I would like to do this. I have finished the first part of your advice.

  • Hi @robertalmcnaughton, if you’d like to move the site here, use this process:
    https://en.support.wordpress.com/moving-from-self-hosted-wordpress-to-wordpress-com/

    This won’t copy over your theme, but it will get your content here where it’s safe from being hacked.

    If you need help, let us know which step you’re on and what is happening.

  • The topic ‘My website has been hacked by a porn site’ is closed to new replies.