Question

Wordpress Sites Forwarding To Unknown Domain

Posted November 16, 2020 113 views
WordPressLEMPUbuntu 20.04

Hi DigitalOcean, I’m running Ubuntu 20.04 with a LEMP stack. There are two WordPress sites on this Droplet. I recently added the second, and wonder if somehow the WordPress site was compromised, because now both sites are unresponsive, when attempting to visit either site, they both forward to a crypto-based website (Virus?)

Can you help troubleshoot this issue?

Thanks,
W

edited by bobbyiliev

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

×
2 answers

Thanks, Bobby.

I solved the issue by:

1) Deleting all files inside /var/www/yourdomain.com where the infected files were placed
2) Uploading fresh versions of the files via sftp
3) Resetting passwords, including mysql database user password
4) Following your instructions above to create .htaccess files
5) And adding a reCaptcha in the login page

Hi there @willbeing,

Yes indeed, this sounds like the sites might have been compromised.

What I could suggest is running a scan for both websites, you could use a plugin like Wordfence to do so. Another option is to scan both sites with software like Maldet for example.

If you are unable to clear the malicious content, the safest bet would to restore a backup of your sites to a clean state. And then follow the steps from this answer here on how to secure your websites:

https://www.digitalocean.com/community/questions/how-to-secure-wordpress-without-a-security-plugin

Regards,
Bobby

Submit an Answer