Forum Moderators: Robert Charlton & goodroi

Message Too Old, No Replies

site hacked and 10k urls injected.What to do?

         

Arturo99

8:42 am on Feb 16, 2023 (gmt 0)

5+ Year Member Top Contributors Of The Month



My site was hacked and 10k urls were injected, in a foreign language.
A site command shows them as does search console.
I tightened up security but what to do with those 10k.
Will they drop off naturally any time soon?
Are bulk removal tools recommended?
thanks
Arturo

not2easy

12:10 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Google put out a video with instructions to help you deal with a hacked site: [web.dev...]

Note - if you can see them, Google can too and may start warning visitors in their listings, to keep people from clicking. Your situation may or may or may not be harmful to others, it is best to use the tools they offer to identify and repair a problem.

Arturo99

1:36 pm on Feb 16, 2023 (gmt 0)

5+ Year Member Top Contributors Of The Month



thanks for the video but no mention of any tools.
Basically just and find a pro.
Do you know of any tool to remove the 10k urls?
thanks, art

not2easy

1:45 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



No, sorry. Google used to have a set of tools to help find and repair such problems. When I looked up my link to those tools - [support.google.com...] it is redirected to a newer page full of answers and "How-to" information.

That may or may not give you what you need, but I can't get a link to the newer content because it all has the hashtag # element that breaks links here. That old link will take you to their new page full of answers, but that's the only way to get there from here.

tangor

5:47 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Something like this happened to me about 3 years back, though the site itself was not hacked---whole bunch of bogus links ...

Made sure the site was clean, then looked for, and found, regex masks to deny in .htaccess JUST TO MAKE SURE these were NOT attributed to example.com and inside of three weeks these things FINALLY disappeared.

Not sure this is the same thing... but might take a look and see what your logs say.

Arturo99

6:28 pm on Feb 16, 2023 (gmt 0)

5+ Year Member Top Contributors Of The Month



Tangort, can i have an example of a REGEX mask so i can check my htacces?

not2easy

6:35 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I would suggest that if there is no warning in Google's SERPs where your site is listed than it is more likely to be as tangor suggests. I thought that the 10K links part was a known fact. Often the appearance of unusual links in GSC are NOT on your site, but appear to be to your pages from a bogus site. Yes, those disappear in a short time and have no effect.

tangor

6:37 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Something as simple as

SetEnvIfNoCase Request_URI "wp-" ban

NOTE: that is example only. I don't use word press and reject ALL things word press!

Wilburforce

9:33 pm on Feb 16, 2023 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I don't use word press and reject ALL things word press!


Amen to that!

Arturo99

8:34 am on Feb 17, 2023 (gmt 0)

5+ Year Member Top Contributors Of The Month



not2easy
10k links show up on a site: example.com search
They are still there. 10k japanese or chinese urls
However all of them link only to a 404 message.

Search console, pages shows them as well showing as crawled, not indexed.
Do you recommend using a bulk removal tool
One at a time manual removal takes far too much time.

tangor

10:52 am on Feb 17, 2023 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



The 404 will eventually make them disappear. My solution to send 403 merely makes it happen a bit faster. If the links/urls are invalid, they serve no purpose as far as the search engines are concerned and will be EVENTUALLY deprecated. Again, I suggest looking at your system logs to verify the 404 failures.

Also remember, those links you see are not the kind of things USERS are looking for in the first place! Since they are DOA (dead on arrival) they won't really hurt you, just look ugly in the logs.

nickZ

8:36 pm on Feb 21, 2023 (gmt 0)



@Arturo
You should play back a back up or change to some other Server as lang as you cannot rule out any involvement.

tangor

6:03 am on Feb 22, 2023 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



A bit of caution here ... unless you KNOW your site was hacked and you found EVIDENCE of malicious code instead of merely being TARGETED by a bunch of script kiddies banging domains with hacking ATTEMPTS, hold off on making major changes to the site.

Resolve the issue of being HACKED first. As for the other, all of us face that every few months, and the IPS never remain the same.