A Modified .htaccess File and Hidden Redirects
What Is .htaccess and Why Do Hackers Modify It?
The .htaccess file is an Apache server configuration file that controls how the server handles HTTP requests for a given directory and its subdirectories. It allows, among other things, redirects, permission settings, access restrictions for files, and much more.
Hackers modify .htaccess because it is the fastest way to redirect traffic without interfering with PHP code or the database. A change to a few lines in this file can send all traffic from mobile devices or search engines to an advertising site.
Examples of Malicious Entries in .htaccess
Redirecting mobile users only:
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (android|iphone|ipad) [NC,OR]
RewriteRule .* https://zlosliwa-reklama.com/ [R=302,L]
Redirecting traffic from Google only (cloaking):
RewriteCond %{HTTP_REFERER} google. [NC,OR]
RewriteRule .* https://spam.example/ [R=302,L]
How to Check and Fix .htaccess
- Using FTP or File Manager, find all .htaccess files in the account — check
public_html and every subdirectory (there may be .htaccess files anywhere).
- Compare the contents with the default WordPress .htaccess file (available in the documentation).
- Remove all unknown RewriteRule and RewriteCond entries.
- If you are not sure what is original, delete the entire file and generate a new one in WordPress settings: Settings → Permalinks → Save.
Remember: .htaccess may also be saved under a hidden name, such as ..htaccess or .htaccess.bak — carefully check all files beginning with a dot.
If redirects return after you clean .htaccess, that is a sign the backdoor is deeper. Tell us what happened and we will find and remove the source of the problem, with a 30-day guarantee.