Has My Site Been Hacked?

Website URL

https://www.grousemusic.com/

Error Message

None

Other Information

Hello,

Everyday, I click on my website from a bookmark and it looks ok.
Today, however, I visited from a link on an external page and I’m seeing a website in Turkish (I think), possibly a betting site.
Anyway, I don’t recognise it at all.
My website is still there with all its pages, it’s just the landing site, with no extension, that’s the problem.
So https://grousemusic.com/Home.html is my site and all the links at the top are working fine but it you go to grousemusic.com that’s where the problem is.
How could it just be that page that’s the problem?
What should I do to get rid of that?
Thank you.

Welcome to the InfinityFree community forum! Good to have you here.

  • Most people answering here are volunteers. They’re often the fastest source of help. Admin (the only staff member) checks in about once a day for issues on our end.
  • Volunteers can’t see your account or website. Share what you actually see, like error messages and what happens when you try something. That’s more useful than your theory of what’s wrong.
  • AI tools often get InfinityFree wrong. If a volunteer’s advice differs from what an AI told you, please try the volunteer’s suggestion first.
  • Solving an issue is a joint effort. Try the suggestions you get and report back what happened.

Beep boop, I’m a bot! I dug through the forum to get you started. I sometimes get things wrong though, so do with this what you will until a human has a look.

Your account was suspended for abuse on 2 October and reactivated on 3 October. Did you know about that? It matters here, because a site showing content you didn’t put there sounds like it could be connected.

I can’t tell from here whether your site has been hacked. Here’s why only the bare address could be affected. grousemusic.com and grousemusic.com/Home.html are different files. If someone added or replaced the default index file in your site’s root folder, only the bare address would show their page. Home.html and its links would keep working normally. Some of these pages also only show to visitors who arrive from another site, such as a search result or a link. That would explain why your bookmark looks fine.

This article says InfinityFree automatically scans sites for harmful content, and that malicious code often arrives hidden inside free themes and plugins:

Two questions would help narrow it down:

  1. When you open your root folder (usually htdocs) in the file manager or FTP, is there an index.html or index.php there that you didn’t create? If so, what’s its modified date?
  2. Is the site plain HTML files you wrote, or does it run WordPress or another CMS with themes and plugins?

I had a brief look at your account and the files on it and I also suspect that your account has been hacked somehow.

Your website has an index.php file that was added on the 1st of October, along with a number of other files added to your website, and some files appear to have been modified too (notably the .htaccess file).

Like the bot said, it would be good to know how your website was built. I mostly see plain HTML files. Does the website contain any PHP code, or is it actually just a static site? Not having any PHP code rules out a lot of possible reasons how an attacker could have gotten access.

Besides that, to eliminate this issue, you should do the following:

  • If you have a backup of your site, now is the time to use it. Delete all the files from your website, and restore it from a clean backup from before your website was hacked.
  • If you don’t have a backup, then go through all the files and folders of your account and look for any that were modified recently. Remove any files or content you don’t recognize.
  • Update the password of your hosting account.
  • Check the login history in the members area for any logins you don’t recognize. If you see any, then reset your members area password as well, and consider enabling two-factor authentication if you haven’t already.

Thank you for your help with this. I do have a backup. I will follow everything you suggest.

Looking at the Login History, it doesn’t look particularly suspicious. I don’t remember every date I logged in but the IP address is the same for every log-in. I was aware of the account suspension and I think I logged in when I received the emails regarding this, so the dates don’t really help there.

As far as PHP, I don’t know. It’s a very basic website, probably static as you say.

It was built a long time ago in iWeb and edited over the years via HTML editing.

The hacking seems odd, in that it left my site almost intact and didn’t change any passwords.

Looking again, the files were edited on October 1st and there is no log-in on that date so it looks like the site must have been accessed by some other means?

Thanks again.

PHP code runs on the server, and a vulnerability in the PHP code of a website could enable an attacker to gain access to your website and install malware into it. And the most certain way to make sure that there is no vulnerable PHP code on your account is to not have any PHP code at all. But of course, many websites need PHP code to work, so foregoing PHP entirely is often not an option.

If your website really didn’t have PHP code and they didn’t go through the members area, then they must have been able to access your hosting account directly. If they were able to obtain your hosting account password, they could have accessed the hosting control panel or the FTP server for your account, and added code that way.

Unfortunately, I don’t have access to any logging to verify that.

Based on what you say, I’m guessing it was through some PHP code.

I’ve removed all recently altered files and changed my password and all looks back to normal now so I’ll see how things go from now on.

Can I clarify one thing you said? Is there a distinction between the ‘members area’ and hosting account password? I only have one password to access everything on Infinity.

Your members area password is the one you use to log in.
Within your members are, you can have up to 3 hosting accounts. each of which has their own credentials. you’ll only ever likely use these for things like database access and FTP access. But they are also used on the back end for things like the script installer (which uses FTP) and the control pannel. If someone got hold of these credentials it wouldn’t appear in your login history, but they would be able to make any changes they wanted to your site.

If you want to properly secure your website, you should really try and get some definitive answers on this. Guessing it was PHP and then not doing anything is the worst possible outcome.

If there is PHP code in your website, and it was used to hack your website, then simply removing the malware doesn’t address the vulnerability the attackers used to gain access to your site. Then the code must be checked for potential security issues which must be solved before you can consider yourself safe again.

If your website doesn’t use PHP, then that’s not an issue. But then you should absolutely make sure that no PHP code exists on your account to completely close that vulnerability.

Yes, there is! And if you think there is only one, you may have updated the wrong one, because there should be a check from reusing the same password.

Logging on to the members area at dash.infinityfree.com can be done with a password. However, every hosting account also has its own password, which is used to login to the hosting control panel of that account, and connect to FTP or the database.

Seeing how your members area login history didn’t show anything unusual but your account still got compromised, updating the hosting account password is the critical step to take. There is no harm in updating the members area password too, but there is probably little benefit to it too.

If there is PHP code in your website, and it was used to hack your website, then simply removing the malware doesn’t address the vulnerability the attackers used to gain access to your site. Then the code must be checked for potential security issues which must be solved before you can consider yourself safe again.

Absolutely, I will endeavour to find out.

As far as the password, I’ve now updated the Hosting Site one too. I’ve never had to use that before as the dash.Infinity password seems to grant access to the Control Panel, File Manager etc.

Thanks again.