{"id":498,"date":"2018-10-04T21:05:30","date_gmt":"2018-10-04T21:05:30","guid":{"rendered":"https:\/\/www.rochen.com\/docs\/?post_type=ht_kb&#038;p=498"},"modified":"2021-04-28T20:49:14","modified_gmt":"2021-04-28T20:49:14","slug":"dealing-with-compromised-websites","status":"publish","type":"ht_kb","link":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/","title":{"rendered":"Dealing with Compromised Websites"},"content":{"rendered":"<p>In the event your website is compromised, we have some suggestions to help you restore as well as secure your site. Please take careful note of the following:<\/p>\n<blockquote><p>99% of site compromises are a result of insecure scripts and\/or insecurely stored passwords.<\/p><\/blockquote>\n<p>99% of site compromises are a result of insecure scripts and\/or insecurely stored passwords. To avoid this situation always use secure passwords and store them securely (i.e. not in your Browsers or FTP Clients), and keeping all scripts on your account up-to-date with published security patches as required by our\u00a0<a href=\"https:\/\/www.rochen.com\/legal\/aup\/\" target=\"_blank\" rel=\"noopener\">Acceptable Use Policy (AUP)<\/a>.<\/p>\n<p>It&#8217;s imperative that once you have access to your site you\u00a0change\u00a0all\u00a0of your passwords (cPanel\/FTP, email, db-users, secondary FTP accounts, and passwords used in your scripts such as user\/backend passwords) and\u00a0perform a security audit on all scripts\/content under your account.<\/p>\n<h3>So, what can you do in this unlikely event?<\/h3>\n<ul>\n<li>Take a backup of your site (backup your files via FTP and your database(s) via phpMyAdmin).<\/li>\n<li>Change\u00a0all\u00a0of your passwords (cPanel, mail accounts, database users, FTP subaccounts, and Webdisk subaccounts).<\/li>\n<li>Make sure the attacker has not created any malicious Cron Jobs in your account.<\/li>\n<li>Remove any malicious content from your account by either\u00a0restoring\u00a0from a known-clean backup if you can determine when the compromise occured or manually\u00a0auditing\u00a0all content under your account and removing anything malicious.<\/li>\n<\/ul>\n<h4>If restoring<\/h4>\n<p>a) Remove all of your own files\/directories (do\u00a0not\u00a0remove any system files or directories though) and b)\u00a0restore your site to an earlier time using the Rochen Vault via these steps.<\/p>\n<h4>If auditing<\/h4>\n<p>Either audit all content under your account locally, or download it and audit it on your own computer to locate and remove all malicious content.<\/p>\n<p>Secure your scripts and\/or local computers to ensure this doesn&#8217;t happen again. Update all scripts, and keep them updated within 72 hours of security patches being released. Make sure you are subscribed to update notification mailing lists or RSS feeds for those scripts.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert    \"   >\r\n    \t\t\t    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tOn all of our shared servers we run suPHP, so *never* set file permissions above 644 and folders above 755. You can\u00a0reset your permissions via these steps.<br \/>\nConfiguration files (such as Joomla&#8217;s configuration.php) should have file permissions set to 640.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n","protected":false},"excerpt":{"rendered":"<p>In the event your website is compromised, we have some suggestions to help you restore as well as secure your site. Please take careful note of the following: 99% of site compromises are a result of insecure scripts and\/or insecurely stored passwords. 99% of site compromises are a result of&#8230;<\/p>\n","protected":false},"author":2,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[230],"ht-kb-tag":[313,314,312,311],"class_list":["post-498","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-general-use-and-troubleshooting","ht_kb_tag-audit","ht_kb_tag-clean-up","ht_kb_tag-compromised-site","ht_kb_tag-hacked"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Dealing with Compromised Websites - Rochen Documentation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Dealing with Compromised Websites - Rochen Documentation\" \/>\n<meta property=\"og:description\" content=\"In the event your website is compromised, we have some suggestions to help you restore as well as secure your site. Please take careful note of the following: 99% of site compromises are a result of insecure scripts and\/or insecurely stored passwords. 99% of site compromises are a result of...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/\" \/>\n<meta property=\"og:site_name\" content=\"Rochen Documentation\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-28T20:49:14+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/documentation\\\/dealing-with-compromised-websites\\\/\",\"url\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/documentation\\\/dealing-with-compromised-websites\\\/\",\"name\":\"Dealing with Compromised Websites - Rochen Documentation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/#website\"},\"datePublished\":\"2018-10-04T21:05:30+00:00\",\"dateModified\":\"2021-04-28T20:49:14+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/documentation\\\/dealing-with-compromised-websites\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.rochen.com\\\/docs\\\/documentation\\\/dealing-with-compromised-websites\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/documentation\\\/dealing-with-compromised-websites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Dealing with Compromised Websites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/#website\",\"url\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/\",\"name\":\"Rochen Documentation\",\"description\":\"Official documentation for Rochen&#039;s web hosting services as well as helpful articles for CMS like WordPress, Joomla and Drupal.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.rochen.com\\\/docs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Dealing with Compromised Websites - Rochen Documentation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/","og_locale":"en_US","og_type":"article","og_title":"Dealing with Compromised Websites - Rochen Documentation","og_description":"In the event your website is compromised, we have some suggestions to help you restore as well as secure your site. Please take careful note of the following: 99% of site compromises are a result of insecure scripts and\/or insecurely stored passwords. 99% of site compromises are a result of...","og_url":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/","og_site_name":"Rochen Documentation","article_modified_time":"2021-04-28T20:49:14+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/","url":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/","name":"Dealing with Compromised Websites - Rochen Documentation","isPartOf":{"@id":"https:\/\/www.rochen.com\/docs\/#website"},"datePublished":"2018-10-04T21:05:30+00:00","dateModified":"2021-04-28T20:49:14+00:00","breadcrumb":{"@id":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.rochen.com\/docs\/documentation\/dealing-with-compromised-websites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.rochen.com\/docs\/"},{"@type":"ListItem","position":2,"name":"Dealing with Compromised Websites"}]},{"@type":"WebSite","@id":"https:\/\/www.rochen.com\/docs\/#website","url":"https:\/\/www.rochen.com\/docs\/","name":"Rochen Documentation","description":"Official documentation for Rochen&#039;s web hosting services as well as helpful articles for CMS like WordPress, Joomla and Drupal.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.rochen.com\/docs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb\/498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/comments?post=498"}],"version-history":[{"count":1,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb\/498\/revisions"}],"predecessor-version":[{"id":1668,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb\/498\/revisions\/1668"}],"wp:attachment":[{"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/media?parent=498"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb-category?post=498"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.rochen.com\/docs\/wp-json\/wp\/v2\/ht-kb-tag?post=498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}