Recommended Posts

I have my own shared webhosting provided through UKHost4u... I host a wordpress blog on there. It keeps getting hacked. I've changed all passwords, etc. Wiped the space clean, reinstalled over 3 times now.

The recent reinstall was a few days ago. I slapped a theme on but haven't had chance to post yet.

And BAM it's got another damned JavaScript injection.

I hosted previously under another provider and no such issues.

I have spoken to the hosts, and they say that it's basically not their issue.

Can someone help, gimme an idea whats going on? I'm at my witts end over this...

www.brandbeast.co.uk

Link to comment
https://www.neowin.net/forum/topic/1112071-my-site-keeps-getting-hacked/
Share on other sites

Setup your domain to use cloudflare... it adds an extra layer of protection by blocking connections from know hackers, spammers, etc. It also provides a cache of your site when your actual host is down. Best of all it's free :)

Not saying it'll 100% solve your problems, but it can't hurt.

More info:

http://www.cloudflar...atures-security

Move to a host with support for mod_rewrite, it allows scripts to write files to those directories without them needing to be chmodded at 777 for full public access. Your host's security practises sound pretty poor

In fairness, I don't fully know what I'm doing, they seems to offer a lot of things, but they just aren't being particularly helpful :(

If they had mod_rewrite it would be set up server side in PHP, it doesn't need to be configured independently by each customer :) I admit Linux isn't my strength but a good admin would be able to harden a Linux server against such exploits.

Yea it's probably that. What OS are you using and what services do you have running (SSH, FTP, etc)?

If you are running Linux, set up a seperate partition for /var/www , and set it in /etc/fstab to mount read-only by default. When you need to add something, you run "mount -o remount,rw /var/www" to make it writable, and then "mount -o remount,ro /var/www/" when you are done.

That and there should be a guide on what folders should have what permissions set. You should take care to make sure those are set.

Ask your host to install ModSecurity and/or Suhosin. ModSecurity is a web application layer firewall and Suhosin protects from insecure codes used by inexperienced PHP developers.

Another thing your host should do is to run PHP in suPHP or FastCGI mode so the hackers can't make use of insecure file and folder permissions.

It seems like you have some vulnerable plugins/themes, so ask your host to do a maldet scan for your account, provide you with a list of infected files and then search the access logs to see who the hacker is and how he was able to inject the infected files. You should also see in the logs the script that was exploited to inject the malware and then you'll know which plugin or theme you should remove.

If your host can't help you with this, then it's about time that you search for a more experienced and secure provider, preferably a CloudFlare partner so you can use CloudFlare to add an extra layer of security and speed up your website. If you need a recommendation which would fulfill the stuff mentioned above, I'd be glad to help.

By chance, are you using a theme from a third party, or a paid one for free? Catch my drift?

If so, I guess they can be infected just like any other file that can be retrieved like that. If you are uploading the same theme each time and don't notice the problem until you upload it, then we probably have the answer. Just check the theme files out to see if they are infected. NOD32 gave me five separate warnings about your page. I'll have to check the logs to see what all it found.

ukhost4u doesn't exactly look like the best host 22 out of 79 ratings on the google review of the site are 3 stars or under. I'm also doubting some of the reviews since 20 of them are duplicates and all of them are 3 or 4 stars. There is only one four star rating with a name attached and only 15 of the 40 5 star ratings have names attached.

I'm with stablehost(they have servers in Germany). They aren't the biggest but they have good ticket support, good server stats and the best thing about them for me is they are really reliable. I've only had to contact support twice since 10th July 2011 the last one being in January. One was my fault with importing a SQL table that went into a loop and they helped fix that problem, the other was one of their servers hardware started to crap out causing the site to go slow, they moved me to a new server. Really good prices as well so their name fits the bill.

I'm really skeptical after being on hostgator, sharkspace, dreamhost and two other small hosting sites. The big ones have dumb staff and their servers get problems often, the small ones usually have support issues since they usually only have a couple of people running it in their past time so when things go wrong it might take a few hours to get a ticket response. Stablehost is in the middle taking the best from both.

Not sure how stablehost deal with hack attempts though, my site's have been hacked before but not on stablehost. Could be they have tough defenses or no one has aimed at me in the last year or so.

If you fancy them click here

If not my advice is don't go with the big giants or one man shows.

Um, while I value the time u spent...

It did not say you had a virus, it said it blocked a javascript injection. Why is it ok to blame the host and not my securing of my site?

Because nothing anyone says here is going to fix it. This is up to the site admins and not you.

Site admins? Have you followed the thread? It's MY site. Sure it's on their servers, they host it, but I uploaded Wordpress, set it up, installed the theme and didn't lock anything down beyond the standard install...

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If you look around on Amazon, some of these are available for $9
    • I’m still using an Xbox One S, so time for an upgrade to play this but as much as I hate Sony, I think I’ll get the ps5 pro
    • I bought this game. Played it for an hour, and then got a refund from Steam. Not a fun game at all.
    • Nothing Ear buds with active noise cancellation are at their lowest price ever with 51% off by Fiza Ali Amazon is currently offering the Nothing Ear wireless earbuds at their lowest price ever with 51% off limited prime deal. The earbuds feature an 11mm dynamic drivers with a ceramic diaphragm, and support high-resolution audio codecs including AAC, SBC, LDAC, and LHDC 5.0. They support active noise cancellation of up to 45dB across a frequency range of up to 5000Hz, and include a smart ANC algorithm, adaptive noise cancellation, and a transparency mode that allows surrounding sounds to be heard when needed. Connectivity is provided via Bluetooth 5.3, with support for multiple profiles including HFP, A2DP, AVRCP, and others. The earbuds also support dual connection, allowing them to be paired with two devices at the same time. Additional features include IP54 water and dust resistance for the earbuds and IP55 for the charging case, in-ear detection, pinch controls, low-latency mode, Google Fast Pair, Microsoft Swift Pair, and a three-microphone system per earbud for clearer voice calls. The Nothing X app, available on Android and iOS, provides access to custom EQ settings, bass enhancement, personal sound profiles, ear tip fit testing, firmware updates, customisable controls, dual-device management, and a find-my-earbuds feature. In terms of battery performance, each earbud has a 46mAh battery and the charging case has a 500mAh capacity. With active noise cancellation (ANC) turned off, the earbuds should offer up to 8.5 hours of playback on a single charge and up to 40.5 hours in total with the charging case. With ANC enabled, playback should last up to 5.2 hours on the earbuds and up to 24 hours with the case. For calls, talk time should reach up to 5 hours on the earbuds and 23 hours with the case when ANC is off, while ANC on should provide up to 4 hours on the earbuds and 18 hours with the case. Finally, fast charging should deliver up to 10 hours of playback from 10 minutes of charging when ANC is disabled. Nothing Ear Wireless Earbuds Bluetooth: $73.15 (Amazon US) - 51% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Microsoft officially launched its Copilot Cowork enterprise AI agent on June 16, 2026, switching to usage-based pricing on the same day it disclosed it is considering a Microsoft-hosted version of China's DeepSeek V4 as a lower-cost engine for the platform — a pairing that puts the company on a collision course with both its enterprise customers' security teams and a White House that has spent months trying to wall off Chinese AI from American infrastructure.................... https://www.techtimes.com/articles/318647/20260618/microsoft-eyes-deepseek-v4-copilot-cowork-what-azure-hosting-cannot-fix.htm  
  • Recent Achievements

    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      583
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      74
    4. 4
      Michael Scrip
      68
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!