“The Internet is the first thing that humanity has built that humanity doesn’t understand, the largest experiment in anarchy that we have ever had.” – Eric Schmidt
Most of you know by now that my website was hacked last week. You probably saw big warning screens like the one above when you tried to visit my site. And most of you have been asking what happened. So… Here’s the story: I’m traveling like crazy this month, so I had to cram most of this months blogging work into one week and a half long period in between a conference in Texas, and my trip to the Nike Young Athletes Innovation Summit in a couple of days. I was pretty stressed at how much work I had to do, but ready for the challenge.
Then – I got hacked.
I mean, majorly hacked. I had been working on a sponsored posts for Clever Girls, and took a break for lunch. When I came back to my desk, my dashboard had been replaced by a huge malware warning screen. I freaked out a bit. I’m NOT tech savvy, and am not good at troubleshooting when things go wrong. So my first step was to check in to my Facebook groups to ask for help. None of the simple solutions worked. Ugh. What to do?
“There are three kinds of death in this world. There’s heart death, there’s brain death, and there’s being off the network.” – Guy Almes
I was already starting to get messages – emails, tweets, fb comments – asking what was going on. My next step was to call my hosting company for advice. Long story short – After 2 days of waiting, being assured that the scanning service I had purchased would find the problem, and the GoDaddy security team would help me fix it once found – I was informed that all 5 people I had spoken with had given me the wrong info. While the scanning system would assist me in finding the issue, there was no one at GoDaddy who would be helping me to fix it. Oh. My. Heck. 2 1/2 days of waiting to find out that I was still at square one?? I kind of lost my cool for awhile. Luckily for me, the uh-MAY-zing Beck Ryan from Stone Alley 4 WP came to my rescue!! {Connect with her on Facebook too – she is awesome.} Everyone has told me how super smart she is at fixing just about any WP problem imaginable – so I was so relieved to have her helping me out! She was able to login to my account, find the malware, and clean it up right away. But…. It kept coming back. Again, and again. Since Becky is pretty much a genius with this stuff, she was incredibly frustrated by this – and said she’d never seen anything quite like it. Finally, I felt bad for taking up so much of her time, and decided to look for some additional outside help.
“A blogger is constantly looking over his shoulder, for fear that he is not being followed.” – Robert Brault
At this point my Adsense account had been suspended, I had caused problems for a ton of other bloggers who were linked to me, Google had me blacklisted – and I’d missed an incredible amount of deadlines. And – I’d been online night and day, trying everything I could to get things fixed. Every time we thought things were clean, and starting to clear up – another attack would hit and knock me back down again!! But, finally, we figured out what we THINK was the trigger to it all –
The problem: ADV Plugin Scam for WP – Malware and More!
I’m always super careful about adding plugins. But, this was back at the holidays, the company had looked reputable, and I was so over-worked that I fell for this and didn’t do my research. It was supposed to be for adding ads to my site – but then I didn’t realize in the craziness of the holiday season, but I never heard from this company again, and just kind of forgot about that plugin. It was most likely the door that let the hackers into my site. From what GoDaddy told me, this malware originated in Russia – it caused my site to FILL with porn pop-up ads, and added malicious code that would attack the visitors computer. Since this was such a devastating ordeal, I have named it the Russian Porn Pop-Up Attack of 2012, to try and give it a bit of humorous side. You know, so I don’t cry when I think about it :)
The Silver Lining in the Malware Cloud
Does it seem crazy to say that while this was the MOST stressful thing that has ever happened since I’ve started this site, it also had some positives to it? Well, it did, and I want to share some lessons learned:
- I now know SO incredibly much more about the inner workings of my site than I did before. I know what FTP is, where to login to it, and how to change my password. I know how to look at the coding in my site, and some red flags to watch for. And I know everything in my Webmaster Tools dashboard like the back of my hand!
- I finally added some extra services to help me run my site. Things have gotten too big for me to handle it all on my own. And, since I rely on only this income to support me and my little girl – I cannot afford another crisis like this! I now have a great security company doing daily scans of my site, monitoring it for problems – as well as basic maintenance package to stay on top of updates.
- I learned that I have an incredible group of friends and fans online! I cannot even tell you how helpful all of the tips and information you all sent me. The words of encouragement were so needed and appreciated. And to all of the other bloggers who offered assistance – You all rock. I had no idea how truly amazing the people I’ve met online really were until this crisis hit!
So – Thank you SO much to everyone for sending me the kind words, the offers of assistance, and great tips to try. Luckily, everything is FINALLY fixed, and determined by Google to be totally clean and safe again. Whew – What a week it’s been!
What to do if your site has been hacked:
Most cases of malware are pretty simple to clean up – might be a bad link in a spam comment, or an ad or button in your sidebar causing problems. But if you think you’ve been hacked, here are a few tools and resources to check out:
- Check out your sites health in the free security scan on Sucuri.com – it’ll let you know what types of problems your facing.
- If your WordPress site was hacked, this article will give you some tips on what to look for – if you’ve got some decent tech skills, you might be able to fix it up yourself.
- Need more help? Then check out the great services offered at Stone Alley 4 WP – she is totally affordable, and super amazing!
- Want to protect yourself from problems in the future? Check out this article on How to Protect Your Website from Hacker Attacks. Great tips that can help you avoid a huge catastrophe like I just went through.
Make sure to always keep your site updated with the latest versions of WordPress and each of your plugins. Be sure to use secure passwords. Be cautious in how many plugins you use, since they do add a bit of risk to your site. And if your site is more than a hobby, I recommend adding a maintenance package and security services to your site too, to make sure you have access to quick assistance if you need it.
Share your story
Have you ever had your site hacked? Any tips to share – what to avoid, how to fix it, services that rocked? Share your story in the comments – maybe it can help someone else avoid a mess too!
Thank you so much for your patience & support – I’m glad to be back!!
























