Recovering from a hackWritten by Brad Markle
Recovering from a Hack can be overwhelming. Not only do you have to deal with restoring your site to a good working state, you also need to take steps to help prevent a repeated attack on your site. The following is a series of steps are recommend for recovering from a hack (regardless of the nature of the hack). While this may seem overwhelming, this is an exhaustive list. You will want to try and close any open doors the hacker might have used (or may have left behind) to compromise your site.
The first step you want to take is to make sure you change all passwords associated with your account. The following is a list of different passwords you will want to update.
- cPanel Password
- Email Passwords
- FTP passwords
- Passwords for any Content Management Systems (CMS) such as WordPress, Joomla or Drupal
Note! You can get more information about your website hack by reviewing Google's Safe Browsing Diagnostic Page.
Check your local computer
Hacks can come to our servers through your local computer. When a computer is compromised by a virus, hack code can be uploaded to your site through FTP programs and HTML editors. The following explains the steps to take to prevent hacks from your local computer.
- Update any anti virus programs you have on your local computer and run a full scan of local machine. If you do not have anti virus on your local computer, it is highly recommended that you install an anti virus program, keep it up to date, and run regular scans (yes this includes Mac and Linux users as well). Both AVG and Avast offer free anti virus programs from Windows, Linux and Mac users.
- If you use a wireless router to connect to the Internet, make sure it is a secured connection. If you are not sure how to secure your wireless router, consult your router's documentation or do a search online for your router model and how to secure it. Your router manufacturer may also be able to assist you further.
- If you use any local web design/development software (e.g. Dreamweaver, iWeb, Microsoft Expression Web, etc.) make sure your software is up to date.
- Make sure that all Adobe products (including Adobe Acrobat and Adobe Acrobat Reader) are updated.
- Check your browser version and update as needed. If you have more than one browser installed on your computer, check all browsers installed.
Securing your site through cPanel
The cpanel is your hosting account control panel. It is recommended to secure your server through your cPanel. Below are steps to do this.
- Change your cPanel password.
- Make sure all of the FTP accounts listed are in use. If they are not, remove them. Make sure passwords for all FTP accounts have been changed.
- Check that all email accounts listed are in use. If there are any listed that are not in use, delete the accounts. Change your email account passwords.
- In the Email Forwarders area of cPanel, make sure any forwarders listed are ones that you created and are still forwarding from and to the correct email addresses.
- Review the Cron Jobs area of cPanel and make sure any cron jobs listed are legitimate and still contain the correct commands.
- Check the Simple DNS Zone Editor in cPanel. Under "User-Defined Records", check for any records pointing site away that shouldn't be there. Of course, if you use a third party for email or other services (like Google Apps for instance) you will expect to see records for those things. Just make sure that any DNS records listed are correct.
- In Redirects, review any redirects listed. If there are any redirects you did not create, remove them. If you have redirects you have created, make sure the redirections is still set up properly.
Other security issues to check
After you verify that your server and your computer is secure, you will want to secure other areas of your server like your CMS software and maintaining a backup. The following are other security issues you can check.
- If you are using a CMS (e.g. WordPress, Joomla, Drupal, etc.) to create your site, make sure you are running the latest version. Update if necessary.
- Change any administrative passwords for any CMS (e.g. WordPress, Joomla, Drupal, etc.) you use, even if it is a custom built CMS.
- When accessing the Internet, make sure the network you are on is secure. If it isn't, or you aren't sure if it is, do not connect to your cPanel/server (this includes using an FTP program, publishing from design software, logging into email, or logging into a CMS admin area)
- Create and download regular backups of your account. We cannot stress how important this is. Downloading your backups is essential. In the event something goes wrong, having the backup stored separately from your account is vital.
We are here 24/7 to help you with your server If you are hacked and need assistance, you can contact tech support to see if we can help. Even though coding support is beyond our support, we are always happy to see what we can do to help you get your site working.