6

My Search Results were Hacked (How to Detect and Fix it)

 3 years ago
source link: https://www.chrisg.com/search-results-hacked/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
You are here: Home / News / My Search Results were Hacked (How to Detect and Fix it)

My Search Results were Hacked (How to Detect and Fix it)

posted on March 11, 2019

There is a new website hack going around (well, new to me). Here is how to tell if you are hacked, and what to do to fix it!

TL;DR

If you just want to get to the punchline, the TL;DR is the hack targets your robots.txt file. Make sure it is clean and the permissions are set correctly.

For a while, my Maker Hacks site was doing well referring new customers to my favourite laser engraver via my Glowforge review.

Then all of a sudden, they stopped coming in.

Now, obviously this is completely normal, so I didn’t think anything of it, until someone wanted the URL and out of laziness I did a google search rather than grab the link directly from my blog … and I saw this weird thing:

glowforge_review_-_Google_Search.png
That explains why my referrals dropped

Initially I blamed Cloudflare, or the SiteGround caching. I mean, the page itself was fine.

Fortunately my friend Hakan had seen this hack before.

To check your search results, go to Google and enter

    Site: http://your-site.com

Then see how your search results look.

Pasted_Image_3_11_19__12_20_PM.png
Ugh 🙁

In my robots.txt there was a line inserted that tells robots where to find an additional site map.

On my site they direct bots to check “/.well-known/acme-challenge/style/theme/upload/temp/temp/18.xml”

Deleting that entry, and setting the file to read only (chmod 444, or remove write access using FTP), seems to have cleared it up, as well as nuking the entire “/.well-known/” folder.

It gets worse

Unfortunately all the sites on my hosting account, including this one, were impacted, which makes me believe one of them (they are not all mine) had a dodgy plugin, theme or other vulnerability.

So I have asked that the other sites get their own host, and have signed up to Sucuri so they can keep an eye out rather than have to check all the time myself!

Filed Under: News


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK