please help

zakidouara

New member
Nov 14, 2019
7
1
3
please help
I downloaded from here Template or WordPress plugin, but someone logged into my control panel and removed my site's content?
When I delete WordPress and recreate my site, does the hacker delete it directly?

The picture shows you the topic
 

Attachments

  • 95514148_1316046295271450_4110589113101451264_n.png
    95514148_1316046295271450_4110589113101451264_n.png
    93.1 KB · Views: 42

ckeeper

Well-known member
Nov 8, 2019
623
376
63
Hi there,
First of all do not panic, make a backup of your existing website, I do not think your site is hacked because you have used a plugin or theme from Babiato. Can you login to the backend? We can not help you much without getting more detailed info from you. These indonesian hacker group are the ones that did it, https://www.facebook.com/sgbteam.hijr/ I think your site is still there, someone needs to clean out the hack.
 
M

mesum

Guest
what list ur plugin and ur theme?
Tips : try to scan all files your download from any website in Virustotal.com
 

Kanxa

Active member
Jan 14, 2019
134
24
28
please help
I downloaded from here Template or WordPress plugin, but someone logged into my control panel and removed my site's content?
When I delete WordPress and recreate my site, does the hacker delete it directly?

The picture shows you the topic
Hey, the Same Incident happened to me...My site also Removed From Control Panel. When I contact My Host they Said They do not Find any Error or Unusual activity...and I think that was due to my mistake or I didn't install any Files in a directory but I know that before the Site was removed I Sent an Email From My website to all Users...
 

tanierlyons

Well-known member
Staff member
Administrative
Moderator
May 24, 2018
75,209
111,760
120
please help
I downloaded from here Template or WordPress plugin, but someone logged into my control panel and removed my site's content?
When I delete WordPress and recreate my site, does the hacker delete it directly?

The picture shows you the topic
which hosting you are using ? check other domain on your hosting
 

cesar360

New member
Aug 25, 2018
28
14
3
São Paulo, Brazil
Defacing is a prank attack probally is not plugin related, this atack can happen when admin default username is not changed or via database attack.

Acess cpanel and check index.php and .htaccess (hidden file) i got some customers who downloaded nulled plugin from ebay with a php snippet code to redirect to this page.

Also check all your domains and do a FULL Backup restore (if possible) and I recomend later downlad a Malware Scanner plugin to try identify and remove any malicious JS. Wordfence is the best to me.
Here you can find more tips

Good Luck bro, defacing can be undone without data loss in most of cases
 
  • Like
Reactions: tanierlyons

Prabowo

Well-known member
Trusted Uploader
Mar 20, 2019
1,209
936
113
Jamban
www.non.e
Defacing is a prank attack probally is not plugin related, this atack can happen when admin default username is not changed or via database attack.

Acess cpanel and check index.php and .htaccess (hidden file) i got some customers who downloaded nulled plugin from ebay with a php snippet code to redirect to this page.

Also check all your domains and do a FULL Backup restore (if possible) and I recomend later downlad a Malware Scanner plugin to try identify and remove any malicious JS. Wordfence is the best to me.
Here you can find more tips

Good Luck bro, defacing can be undone without data loss in most of cases
This page? Did you mean Babiato, right?
 
Last edited:

MrSam_1

Well-known member
Administrative
Trusted Seller
Dec 1, 2018
24,090
27,353
120
please help
I downloaded from here Template or WordPress plugin, but someone logged into my control panel and removed my site's content?
When I delete WordPress and recreate my site, does the hacker delete it directly?

The picture shows you the topic
Hey, the Same Incident happened to me...My site also Removed From Control Panel. When I contact My Host they Said They do not Find any Error or Unusual activity...and I think that was due to my mistake or I didn't install any Files in a directory but I know that before the Site was removed I Sent an Email From My website to all Users...

Guys, "i downloaded from here template or wordpress plugin" is such a idiot thing to say. This board is full with templates and plugins. Be more specific:
I downloaded and used "this plugin" and "this theme" and ... whatever happened.

From what you said one can assume that you used hello theme and voicer plugin. Isn't that what you used?

You want help then ask for it in a proper way.

I've seen another member pretending that his site is virused because of a plugin he downloaded from babiato but in the end resulted that he used a version prior his joining to babiato.
 

cesar360

New member
Aug 25, 2018
28
14
3
São Paulo, Brazil
This page? Did you mean Babiato, right?
no, this black screen page signed by xbx39 the same OP has.
I dont think babiato uploads caused the issue, I have a lot of websites with wordpress plugins and themes since 2018 and never happened it.
 
Last edited:

MrSam_1

Well-known member
Administrative
Trusted Seller
Dec 1, 2018
24,090
27,353
120
Your websites are permanently scanned for vulnerabilities. And I mean permanently. Most active scan for wordpress is using xmlrpc to get your admin name and then bruteforce starts. And not even bruteforce, there are attacks that exploits certain vulnerabilities in not enough secured or improper coded plugins and themes that will reveal the password or give attacker a door to your website.

This happens on one of my websites and daily I have hundreds of attacks on all websites
2020-05-04 22_43_04-Web Application Firewall ‹— WordPress.png
2020-05-04 22_48_31-Web Application Firewall ‹ — WordPress.png
2020-05-04 22_48_10-Blocking ‹ Firewall ‹ WordPress.png

Edit: screenshots taken from wordfence (I also have a fail2ban installed on server for other applications)
 
  • Wow
Reactions: afroking and mesum

Forum statistics

Threads
69,481
Messages
909,912
Members
239,735
Latest member
jasonli

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu