Skip to main content

Cpanel Account Hacked, Or Just The Wp Sites?

Comments

2 comments

  • quizknows
    Generally with add-on domains, if one site gets hit they all get hit. At least it's only three. What you need to do with that stat time is consult the domain access logs; likely another hacked file is being used to change that one. Look for POST requests especially, or anything that matches the change time. Usually with stuff like this it's just the WP sites, but you can always change the cpanel password to help be sure, and review the cpanel access log if you can for any unauthorized IPs or file manager access. edit; also humor yourself and check the crontab or any .bash* files in the users home directory.
    0
  • cPanelMichael
    Hello :) You can find a similar thread at:
    -1

Please sign in to leave a comment.