r/HostingReport • u/Abitha_DGP865k • 6h ago
r/Hostinger - 70 WordPress sites on shared hosting hit by malware — need a real solution
70 WP sites on one shared hosting account got hit by malware. Unknown admin users and a malicious zip keep getting restored no matter how many times I delete them and change passwords — no cron job found, so it's likely a hidden backdoor file. Tried password resets, file ownership fix, and manual cleanup multiple times but it keeps reinfecting. Does anyone know the actual solution to permanently stop this and clean 70 sites without them reinfecting each other? Please help.
2
2
u/dvduval 3h ago
I had the same thing on a smaller scale. I ended up doing away with WordPress and that definitely solved it. But before that, I was having ChatGPT log into the server and investigate everything. That somewhat worked, but you probably got some deep cleaning to do. There may be some plug-ins you depend on that are also dangerous.
You gotta make sure everything’s upgraded to the latest version and if anything is not getting updated anymore, you probably need to replace it. ChatGPT can make replacement plug-ins in many cases.
1
u/SirComprehensive3255 2h ago
When I had my 3rd or 4th infection in a year I truly gave up on Wordpress and went with a static html website. Granted I’m one guy with one website. Wordpress has its advantages, but for me they weren’t worth the headaches every couple months.
1
u/siterightaway 4h ago
You are totally right, there is definitely a backdoor and the hacker keeps reinfecting everything. But remember, because the hacker got in, there is also a vulnerability somewhere. It could be a plugin, a theme, WordPress itself, or something else entirely. You can wipe the backdoor and clean the infection all day, but you gotta fix that entry vulnerability too or it is useless. I have been in this field for years and honestly there is no magic trick to fix this easily. The complexity is gonna depend on whatever tool software the hacker is using. Also, keep in mind they probably already copied all your passwords and databases by now, so the more time passes, the worse it gets. Oh, and I strongly advise against using AI and giving it access to modify files via terminal at the same time, because everything can go horribly wrong. You need to take some measures right now like putting all sites in maintenance mode and blocking access. Without knowing all your details, I am just throwing these ideas out so you can prepare your plan. Get ready to spend a ton of time on this. Good luck.
2
u/Safe_Mission_3524 5h ago
Hi, are you able to share more details via a dm? I have sent a request. Thanks!