Rescuing a Severely Hacked Website: A Case Study by CMS Live

Rescuing severely hacked websites

Summary

At CMS Live, we recently helped a business recover from a severe website hack caused by a vulnerability in their hosting provider’s caching system. The attack resulted in malicious redirects, unauthorised admin accounts, and thousands of daily malicious requests. Despite the previous hosting provider’s failed attempts to fix the issue, we stepped in to fully clean and restore the site. Our process included a complete security audit, manual file and database cleanup, blocking malicious traffic, and implementing ongoing monitoring. This case highlights the importance of choosing a secure, well-managed hosting provider. If your website has been hacked, CMS Live can help rescue and protect it from future attacks.

You will learn

At CMS Live, we specialise in providing premium web hosting services with a personal touch. Recently, we had the opportunity to assist a business owner whose website had been severely hacked due to outdated software, insecure hosting platform and insufficient management from the old hosting provider.

This blog post will walk you through the issue, the rescue operation, and the extensive steps we took to restore and secure the site.

The Initial Situation

A reputable web designer, who typically uses our white label web hosting services, built a website for a client. However, the client decided to host their site with another provider solely because they used green energy on their hosting platform. While this is an admirable choice, it is crucial that the hosting provider also delivers reliable service, support, and security.

Unfortunately, the client’s website was not fully managed or even maintained, leading to outdated software and a severe hack across the website files, database, and hosting platform. Over 30 PHP files were infected with malicious code, and more than five full admin accounts were created on the fly. The old support team tried deleting the admin accounts, but they kept reappearing after a few days, and they had no idea why.

For over two weeks, the old hosting support team tried to fix the problem of the site redirecting users to inappropriate websites and virus warning security popups. This severely damaged the client’s professional image and reputation. The web designer and the client reached out to their hosting provider with constant support tickets for nearly two weeks. Eventually, they were told the provider couldn’t help and suggested finding a security consultant to clean up the mess.

At this point, the client realised they were on their own with no help from anyone. They required the services of a true managed hosting specialist and security expert. The client turned to us based on their web designer’s recommendation. This is where Martin Starkie from CMS Live stepped in to take control of the situation.

The Technical Challenge

The website was compromised due to a vulnerability in a caching system installed by the hosting provider, specifically a Cross-Site Scripting (XSS) vulnerability identified as CVE-2023-40000. This vulnerability allowed attackers to inject malicious scripts into the website, leading to unauthorized redirects, unauthenticated full admin users, and potential data breaches.

Understanding the Vulnerability

The XSS vulnerability in the caching system allowed attackers to exploit the website by injecting malicious JavaScript code into web pages viewed by users. The injected script could then perform actions on behalf of the user without their knowledge or consent, such as redirecting them to harmful websites. The severity of this attack was rated extremely high at 8.2, making it a high-severity vulnerability.

For more technical details on the vulnerability, you can refer to this source: Qualys ThreatProtect

This vulnerability would affect approximately 4 million websites globally between Oct 23 – Jul 24.

Our Approach to the Rescue

When we were brought in, we requested full access to logs and error logs from the current host to understand the extent of the issue, but they could not provide them. Despite this setback, we quickly got to work. Here’s how we tackled the problem:

  1. Assess the damage on the old hosting platform.
    We could see that over 30 files across the website installation had been compromised with malicious code and 5 unauthenticated admin accounts which kept re-appearing after deletion. It was obvious that systems had been compromised higher upstream and using simple tools and simple thinking wouldn’t cut it.
  2. Initial Assessment and Backup
    We began by taking a complete backup of the compromised website. This step is crucial to ensure we have a recoverable copy before making any changes. This also allowed us to post mortem the issue at a later date to really dig into the code and the compromised files to truly understand the hack.
  3. Isolating the Issue
    We identified the outdated caching system as the primary vulnerability, although secondary issues were identified.
  4. Thorough Cleanup
    The website was so badly infected, we eventually opted for a clean install which would guarantee a solid and clean base to build on. Using a combination of automated tools and manual inspection, we meticulously scanned the website for injected malicious scripts and worked through every line in the database. The hack had compromised nearly every file, necessitating a comprehensive cleanup.
  5. Manual Database and File Cleanup
    We manually cleaned all the website files and database entries to ensure every trace of the hack was removed. This was a painstaking process but essential to fully restore the site.
  6. Monitoring
    During the cleanup process we started to monitor all external requests to the website to really understand what was going on and who was behind this. There were 2 IP addresses initially – one in South Africa and one in Netherlands sending POST data to this URL – update_cdn_status – Each IP sends around 2500 malicious requests every 24 hours and we are seeing just in excess of 5000 requests in total which are still trying to compromise and access the website to this day. We quickly found and isolated the malicious traffic hitting the website and blocked it from even hitting the web server. We observed that the bad actors then increased their efforts by sending more malicious traffic when they realised their access was blocked. They even set up an external monitoring service to check if the website was still online, which we also blocked.
  7. Monitoring and Testing
    After the cleanup and updates, we closely monitor the website logs for any unusual activity and take any necessary action to build and maintain WAF and firewall rules.

The Outcome

Thanks to Martin’s swift and comprehensive response, the client’s website was fully restored and secured within a short period. The site no longer redirected users to malicious pages, and the client could once again operate their business smoothly.

However, because the site had been compromised once, it is now on hackers’ lists of vulnerable websites. Despite our extensive efforts to secure the site, the update_cdn_status requests are still being sent to the website from external sources at a rate in excess of 5,000 per 24 hours, and these cannot be completely stopped as their origins are unknown.

Discover our expertise in website hosting

CMS Live believe in going the extra mile for our clients. This incident underscores the importance of choosing a reliable hosting provider who not only supports green initiatives by using a Carbon Neutral Data Centre but also delivers on security and service. We are proud to have helped this business owner regain control of their website and continue to offer premium website hosting solutions.

If you’re looking for a hosting provider that combines excellent service, personal customer care, and technical expertise, look no further than CMS Live. We’re here to ensure your online presence is safe, secure, and always up to date. One of the services we offer is the recovery of hacked websites, ensuring they are cleaned and fortified against future attacks.

CMS Live: Your Trusted Partner in Web Hosting 

We’re always here to help!

On this page

Hosting Knowledge

Security Headers for Website Hosting

How Security Headers Strengthen Your Website Hosting – A+ Protection by CMS Live Hosting

Website security is more than just having an SSL certificate—it requires robust security measures like security headers to protect against cyber threats. In this blog post, we explain what security headers are, why they matter, and how they safeguard websites from attacks such as XSS, clickjacking, and data injection. CMS Live has achieved A+ security ratings for its hosting services, proving our commitment to website security. We offer fully managed hosting with built-in security measures, ensuring businesses stay protected. If security matters to you, CMS Live is the right hosting partner.

Read More
Secure Website Hosting for Business Owners | CMS Live

Secure Website Hosting for Business Owners: Why It Matters

In today’s digital world, website security is more important than ever for business owners. This blog post highlights the importance of secure website hosting for business owners and explains how a security-first approach can protect websites from cyber threats. It covers essential security measures, including real-time threat monitoring, DDoS attack mitigation, web application firewalls, and SSL encryption. Business owners will also learn what to look for in a hosting provider, ensuring their website stays protected against evolving threats. With fully managed security, CMS Live ensures businesses can focus on growth without worrying about cyber risks.

Read More
Past Updates