Skip to content

Cookie settings

Choose which kinds of cookies you allow. You can change your choice at any time via Cookie settings at the bottom of every page. Privacy statement

Necessary

Always on

Needed to log in, keep your cart and remember your choices. These are always on.

Which cookies?
  • weboke_sessie, weboke_klant, weboke_remember: your session and staying logged in
  • weboke_basket: your cart
  • wkBtwIncl: showing prices with or without VAT
  • wok_cookies: your cookie choice, 12 months

Measures which ad leads to a visit or order, so we do not pay for ads that do nothing.

Which cookies?
  • Google Ads via Google Tag Manager (_gcl_au, _gcl_aw), up to 90 days
  • OpenAI Ads, ads in ChatGPT
  • wok_aff: which partner referred you to us (affiliate programme), 60 days

4.6

Help! My site has been hacked. How can I fix or prevent this?

It is very frustrating when your account has been hacked. We do everything we can to make things as difficult as possible for hackers, but unfortunately a hacker may still gain access to your site. It is then important to try to find out how the hacker gained access to your system.

This can be a difficult and time-consuming job, but finding the cause/source is important to prevent it in the future. Simply deleting everything and restoring a backup is not the solution.

Make sure you do not put the infected website back online unless you are 100% sure the problem has been solved and it is safe.

You can temporarily suspend your domain yourself via the control panel under domain settings (or via the websites option with Windows hosting), so that the hacked site cannot cause any further damage to third parties. If needed, you can restore an old backup via Installatron (Linux hosting) or use our backup module. Make sure you first delete all folders and files and only then restore a backup, otherwise newly added and hacked files would remain in place.

You can also choose to have our experts fix the hack. Because this is a time-consuming job, this service is unfortunately not free of charge.
Click here for more information.

Investigating possible causes:

  • The most common cause: you use a script or plugin that has not been updated to the latest version, is not secure or contains bugs. This can also be a module in, for example, WordPress or Joomla.
  • You offer an upload option to your visitors, and one of them has uploaded a PHP program and run it.
  • You use predictable, overly simple passwords, or passwords that can be found via, for example, haveibeenpwned.com.
  • Your computer is infected with a virus or worm/keylogger, which captures usernames and passwords, for example those of your FTP account.
  • You have created a form into which, for example, SQL or PHP code can be entered, or a form without a Captcha, so that spam can be sent.
  • Search your website's log files (in DirectAdmin in the statistics / logs menu) for anything suspicious. Also search the Litespeed/Apache Usage Log and Backed up Apache logs. Look for IP addresses from foreign countries, and in particular for POST requests combined with an IP address from a foreign country. You will often find something there. You can use a site like www.whatsmyip.org to find out which country an IP address is from.

How to prevent a hack:

  • The most important: make sure all your scripts such as WordPress/Joomla are always up to date with the latest updates. This certainly also applies to plugins and templates. Updates can usually be installed easily via Installatron or via the script itself.
  • Use FTPS instead of plain FTP
  • NEVER use YOUR username and password in scripts. If you must, create a separate user for it via the control panel.
  • Only use well-known, reputable scripts and keep them up to date.
  • NEVER offer upload options. Extremely dangerous.

WordPress, Joomla and other scripts: make sure the latest version is installed!
It is important to keep WordPress/Joomla and other scripts up to date. This generally prevents hacks. Via Installatron (Linux hosting) updates can be installed very easily. If you did not install WordPress/Joomla or another script via Installatron, you can easily import it into Installatron afterwards and then update your script.

Securing folders such as administrator in Joomla
It is important to give folders such as /administrator extra protection. This article explains how.

Iframe hack:

If you are the victim of the iframe hack, the cause is often a Trojan virus on your PC that grants itself access to your FTP accounts

  • Check whether your website has indeed been hacked. You can do this, for example, via the UnmaskParasites website.
  • Use FTPS to log in instead of FTP. FTP sends all data as readable text, whereas FTPS encrypts the data sent, making it harder for hackers to obtain this sensitive data.
  • Now change all your FTP passwords.
  • Change all folders (Linux) via the control panel/file manager or via FTP to chmod 755 and all files to chmod 644.

HTACCESS hack / htaccess has been modified:

In the example below, a hacker has modified your .htaccess. As a result, Google and Yahoo will still index your site as normal, but all other visitors will be redirected to the hacker's site.

RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC,OR]
RewriteRule .* http://hacker.xx/in.html?= [R,L]

 

Google sees your site as an attack site (Reported attack site!):

You can request information via the links below (enter your own domain name):

http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&hl=nl&site=http://www.uwdomein.xx/

Via this link you can get information, among other things, and also submit a request to no longer have your domain name/site treated as an attack site. Make sure it really has been cleaned up completely!

http://www.google.com/support/webmasters/bin/answer.py?hl=nl&answer=45432

  1. Select the site you want in the Webmaster Tools dashboard.
  2. In the message 'Parts of this site may be distributing malicious software', click 'More information'.
  3. Click 'Request a review'.
Was this article helpful?

← Back to General hosting

One moment…

Set up your domains

For each domain, arrange the nameservers, the link to your hosting and who becomes the owner.

Loading your domains…