Restoring hacked wordpress site | Wordpress Support | Forum Archive

The free forums are no longer in use. It remains available as read-only archive.

Avatar
Lost password?
Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
The forums are currently locked and only available for read only access
sp_Feed Topic RSSsp_TopicIcon
Restoring hacked wordpress site
March 31, 2011
9:50 pm
Avatar
Colin G.
New Member
Members
Forum Posts: 2
Member Since:
March 31, 2011
sp_UserOfflineSmall Offline

Hello, I am new to xCloner, and would like to try a restore.  I recently had a bunch of my WP sites hacked, disabling my admin area access.  

If this happens, and I have my cron backups done to Amazon s3, would I remove the hacked WP install via Fantastico, and do a fresh install in the same directory name ?  Then install the xCloner plug in and restore from an amazon backup ?  

I assume since all the paths reference the subdirectory where uploads live, I would have to do it this way (into a dir named the same as where the original install was).  The only issue is that it then would be restoring xCloner over itself, when it writes the plugins directory - not sure the best way to do this - would I need to do a separate WP install for the xCloner which is run to live, and just create an empty directory named the same as the directory the WP site was in, and point the install there ?

Basically, I want to do a runthrough on a throwaway site to make sure I know how to do a restore should I get hacked again.  

Anyone with experience restoring a hacked WP site (especially from an Amazon backup) out there ? Your guidance would be most appreciated.

 

Thanks,

Colin Goldberg

http://www.colingoldberg.com

April 1, 2011
6:23 am
Avatar
Ovidiu Liuta
Admin
Forum Posts: 2484
Member Since:
September 26, 2010
sp_UserOfflineSmall Offline

HI Colin, usually, in such situations, it's best to restore the backup in a clean folder, so my suggestion is that you move the hacked website files to another directory, and then restore the backup you have in it, this should restore your site to the original backup state without issues.

 

The reason i am sugestion this is, if in case the hackers planted some additional files in your site, restoring the backup won't help much if you don't remove all the code they added.

 

Hope it helps! Ovidiu

April 1, 2011
1:00 pm
Avatar
Colin G.
New Member
Members
Forum Posts: 2
Member Since:
March 31, 2011
sp_UserOfflineSmall Offline

Hi Ovidiu,

 

I think I understand - so if my WP install was in /blog , I would move the hacked files to /blog2 and then restore into /blog ?  Could I do a fresh installation of WP in a new directory altogether, and run the restore from there into /blog if my admin area of the original site was compromised and I couldn't access the xCloner plug-in at all ?  This was the case the last time I was hacked.

I would think I would have to restore into the same directory as the original site, as any paths to images on my wordpress pages and posts would be absolute, and contain /blog/wp-content/uploads, etc in the URL, correct ?

 

Also, would I have to drop the original database using phpMyAdmin before doing a restore, or will the restore process replace the old (existing database) - (for example, blog_wrdp) with the backed up one ?

Thanks so much for your help, I plan on joining for premium support.  Also, I saw there is a way to do multisite management with a premium subscription, but could not find a description of this - is there a URL on this site describing how this works, or in the manual somewhere ?

 

Thanks so much,

Colin

April 1, 2011
2:08 pm
Avatar
Ovidiu Liuta
Admin
Forum Posts: 2484
Member Since:
September 26, 2010
sp_UserOfflineSmall Offline

XCloner does not require wordpress to be installed prior to restore, please check the Restore wiki, it should help. XCloner provides an independent restore script which can be used to start the restore process with only the backup archive, no other directories need to be created.

 

Regarding the database restore, it would be best to create a new empty database and import the new site data there. Regarding the multisite support, that doesn't refer to the Wordpress MU, it works with that by default, it's an internal project we hope to release at some point in the future!

 

Regards, Ovidiu

Forum Timezone: America/Chicago
Most Users Ever Online: 867
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
mlguru: 30
Django29: 29
D: 21
Andy: 21
Marcus: 20
Jamie F: 19
Member Stats:
Guest Posters: 738
Members: 10048
Moderators: 2
Admins: 3
Forum Stats:
Groups: 3
Forums: 7
Topics: 2397
Posts: 8236
Newest Members:
Gayira Duncan
Moderators: TriP: 0, Steve Burge: 0
Administrators: Ovidiu Liuta: 2484, Victor Drover: 1, Valentin Barbu: 0