Knowledgebase

Checking Whether You Have Been Compromised Print

  • recoveringfromhack, recovering, hacked, cpanel, spam, domain, filemanager, security, malware, cron
  • 0

Verification.

WHAT TO CHECK

Your user list, for accounts you do not recognise Files modified recently that you did not change Your upload directory, for script files Your cron jobs Your site in search results

THE SEARCH CHECK

Search your domain name with unrelated terms: medication names, gambling terms, replica goods.

Injected spam pages frequently appear that way.

THE FILE DATE CHECK

Sort files by modification date in File Manager.

Anything changed recently that you did not touch deserves examination.

THE USER LIST CHECK

Attackers frequently create an administrator account.

Look for accounts you did not create.

RUN A SCAN

ImunifyAV in cPanel, or a security plugin.

CHECK FROM OUTSIDE

Load your site in a private window, on a phone, from a different network.

Some compromises show only to certain visitors.

THAT IS DELIBERATE

Redirects that exclude logged-in users, or that only affect search visitors.

WHAT TO DO IF YOU FIND SOMETHING

Follow the process in the next articles.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot