• I have a client’s site that I’m trying to fix that has been hacked. I’ve isolated the issue to be within wordpress, but can’t pinpoint what is causing the redirect. Weirdest part is that I can still access the dashboard and if I activate or deactivate a plugin, the site goes back to running like normal, then 10-15 minutes later, will start to redirect again. It is redirecting to revtroyperry.org. Couldn’t find any info on an exploit specifically redirecting to this site, but maybe someone might know if there is a specific hack that is known to do this. With the way everything is acting, I’m quite sure there is a script somewhere that runs every so often to reinject this exploit.

    List of things I’ve done-
    Checked domain forwarding on the host. Nothing abnormal here.
    Reinstall wordpress (site works again, then 10-15min later reverts to redirecting hack like explained above)
    Deactivated and deleted ALL plugins.
    Deleted all php files not being used in latest wordpress installation.
    Checked uploads and themes. Nothing strange here.
    I’ve also replaced the index.php file with code that doesn’t route through the wordpress process (just displayed text). When I had this file active, it never reverted to redirecting, which made me believe the problem is isolated to within the wordpress structure somewhere.

    Also, this is not specific to google or facebook type links to the site. The redirect happens even when directly typing in the site url.

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Site hacked and redirecting’ is closed to new replies.