Securing a website

I guess the first thing is what is the underlying platform the website runs on? I've done a cleanup on a wordpress site that was hacked to use for pharmacy spam. It's quite the learning curve to get rid of the stuff, make sure you have a backup (even of the compromised site) before you do anything.

Tony.
 
Also once they have gained access, they will most likely have installed back doors, so even if you think you have secured the server you may not have. Below are screen shots of the backdoor I discovered on the site that I fixed up. It didn't even need a password to get into so anyone knowing what to look for could have taken advantage of it.

Tony.
 

Attachments

  • hack.PNG
    hack.PNG
    98.7 KB · Views: 88
  • hack2a.png
    hack2a.png
    58.3 KB · Views: 86