Quick help: I’ve been hacked

Virus on a WordPress site via password reset email

We know that on January 10, 2024 there was a serious security breach in the “Post SMTP” plugin. This breach would allow an attacker to gain full access to the website by being able to change the password of a website administrator.

Since users with administrator permissions can perform high-level tasks, such as installing new plugins, they use this to install a plugin specially prepared by them that actually contains all the malware they want to introduce into the website, and from that moment they have already “infected” the website.

If you have the “Post SMTP” plugin, you have not updated it recently, and you have received password recovery emails and password change emails that you did not generate, your site may be infected.

How did we learn about this vulnerability?

At GIGA4, as providers of maintenance for WordPress sites, we learned about this breach from the very beginning and have secured the sites we maintain so that they have not been affected.

In addition, as WordPress site security specialists, we have already cleaned sites that have been affected by this security breach.

If your site has been affected, you can contact us and we will provide more details and a quote to recover, secure, and maintain your website.

The Internet is an environment that requires high levels of security.

Imagine a wireless garage door opener, traditionally they have been hacked in a very simple way, just by having the right device and listening to the radio frequency signals emitted by one of the remotes, someone specialized could replicate that signal and open the doors.

The security of these garages is not based on the security provided by the remote control; the remote control is only a small barrier that adds to the need to be physically in the garage and not to carry out activities that attract the attention of the neighbors.

But imagine that with the procedure you already know you can hack all the garages in the same neighborhood at the same time and gain access without anyone noticing. This is how intrusions are carried out on the Internet. Internet security has to be ruthless, the barriers must be complete, no loose ends can be left untied.

Good understanding of viruses and intrusions

They usually gain access by exploiting a known security vulnerability, constantly searching for increasingly elaborate methods to gain access to the web or server.

The second most common case is because, through some method, they have managed to discover the password.

These are usually not targeted attacks, but rather automated attacks launched on any website that comes their way. Web sites receive attack attempts of all kinds constantly, at least hundreds per hour.

Prevention is necessary to prevent unauthorized access.

When the virus enters the website the first thing it usually does is: hide to make detection difficult, replicate to ensure its survival and open “back doors” to allow easy access to its owner.

Once it has spread, only a thorough review can ensure its elimination.

The goal is to take advantage of your server or website resources: Using it to send spam benefiting from your reputation, as a phishing site to perform scams, doing SEO to affect a third party, displaying advertising, mining cryptocurrencies, stealing data and/or using it to perform other attacks.

Cleaning and prevention

At GIGA4 we know the preventive techniques to secure a website. As well as the procedure to be followed in the event of a security breach of any kind.

We have experience solving this type of problems in very different web sites and with peculiar casuistics.

Our protocol includes reviewing the site files both manually and using heuristics and checksum verification, reviewing the database, bringing the site up to date to address known security holes, changing the salts and all passwords, as well as various prevention techniques.

Screenshot of the tesla.php virus, cleaned by Francisco in February 2023.

We eliminate viruses

We look for them where they are, anticipate what they are doing and eliminate them. We do this in a cloned environment to prevent their spread as we make them disappear.

Web security

By updating the site, we close known security holes. In addition, we introduce preventive measures that block the most common operations that lead to an intrusion. Finally, we offer you our maintenance service.

Priority solution

We know that a virus is a major problem that affects the operation of the website and needs to be fixed as soon as possible. We give priority to the solution of this type of problems.

We are real and human

We collaborate with the WordPress project through the “Five for the future” program. Francisco is part of the plugin review team, proactively collaborating with the security of the WordPress ecosystem. Roberto is part of the community team, organizing and participating in non-profit events to raise awareness of the tool, provide training and create professional connections.

We are a registered entity in the catalog of cybersecurity companies and solutions of INCIBE, the national cybersecurity institute in Spain. This registration proves that we are a registered entity in Spain, we provide security solutions, our site complies with the legislation and is secure.

Do you think we can help you?

If you have had a problem related to a virus or an intrusion in a WordPress site, contact us, we will tell you the first steps to follow and we will review your case to give you an effective long-term solution.

Talk to us

Briefly tell us what you need: what is happening, what type of project it is and, if possible, its scope. The more context you provide, the better we can advise you.

    Phone
    L-J 11-17h
    • Granada
    • Valladolid
    • Berlin