Knowledgebase

How to Clean a Compromised Site Print

  • recoveringfromhack, recovering, hacked, database, cron, plugins, themes, uploads
  • 0

The proper process.

THE PRINCIPLE

Remove the compromise and close the entry point.

Doing only the first means it returns.

THE PROCESS

  1. Back up the compromised state
  2. Identify the entry point
  3. Change every credential
  4. Remove or replace compromised files
  5. Check the database
  6. Remove unauthorised accounts and cron jobs
  7. Update everything
  8. Verify it is clean
  9. Monitor

THE ORDER MATTERS

Cleaning before changing credentials means the attacker can return during cleanup.

THE MOST RELIABLE METHOD

Replace rather than clean.

Fresh core files, fresh plugins and themes from legitimate sources, keeping only your own content and configuration.

WHY REPLACE

You cannot be certain you found everything.

WHAT TO KEEP

Your uploads, after checking them Your database, after checking it Your configuration, after checking it

WHAT TO DISCARD

Everything else, replaced with clean copies.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot