Knowledgebase

Database Was Modified by an Attacker Print

  • databasesphpmyadmin, databases, database, backup, restore, hacked, spam, ftp, password, woocommerce
  • 0

Recovering from a compromise affecting data.

WHAT IT LOOKS LIKE

Spam links injected into post content Administrator accounts you did not create Redirects configured in options Content altered or deleted Unfamiliar rows in configuration tables

FIRST ACTIONS

Open a ticket so we can check the account Take a copy of the current state before changing anything

Change every password: hosting, database, application administrators, FTP

FINDING WHAT CHANGED

Compare against a backup from before the compromise.

Check the users table for accounts you do not recognise.

Check the options table for altered site URLs and injected scripts.

Search post content for injected links.

CLEANING

Restoring a clean backup is the reliable route, provided the backup predates the infection.

Infections are frequently present for weeks. Check several restore points for the injected content to find one that is clean.

IF YOU HAVE NO CLEAN BACKUP

Remove the injected content specifically, which is laborious and workable.

THE CRITICAL STEP

Close the entry point. A cleaned database on a still-vulnerable site is reinfected within days.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot