FTP TUTORIALS & GUIDES

Manual Website Recovery Using FTP After a Crash or Hack

Learn how to manually recover a website using FTP by restoring backup files, replacing damaged content, checking permissions and safely returning your site to working order after errors, failed updates, malware or data loss.

Updated: June 20, 2026
By: RSH Web Editorial Staff

Hosting from $2.99/mo
  See Plans    Contact Us

Menu

Manual Website Recovery Using FTP After a Crash or Hack

Learn how to recover a site with FTP or SFTP: restore clean files, replace damaged content, fix permissions, and bring the site back after a failed update, malware, or data loss.

Manual website recovery using FTP after a crash or hack

Recovery

When the public site is broken, FTP or SFTP still reaches the files. Use a known-good backup first. Prefer SFTP so the restore session is encrypted. Automated backups

Step 1: Connect

  1. Use FileZilla, WinSCP, or another client. Choose a client
  2. Host, complete username, password or SSH key, port 21 (FTP/FTPS) or 22 (SFTP).
  3. Open the document root, usually public_html.

Step 2: See what broke

Missing core files (index, wp-config, .htaccess)
New or unexpected scripts in writable folders
Wrong permissions (directories not 755, files not 644)
Database errors (FTP cannot fix the database; restore a SQL dump in cPanel)

Step 3: Restore clean files

  1. Work from a backup you trust, not from files already on the live server if they may be compromised.
  2. Upload the archive or copy files into public_html.
  3. Overwrite damaged files. Do not extract a zip into a random extra folder and leave two copies of the site.
  4. If the backup includes a database dump, import it in phpMyAdmin or the host restore tool.

Step 4: Clean and lock down

  • Remove unknown files that appeared after the incident.
  • Reset FTP, cPanel, CMS admin, and database passwords.
  • Update the CMS, themes, and plugins after the site loads again.
  • Change leftover FTP accounts you no longer need. FTP user accounts

Use SFTP or FTPS for the restore. Plain FTP can expose the same passwords you just reset. Using SFTP with cPanel

Step 5: Test

Home page, login, forms, and a few inner URLs
HTTPS and the admin dashboard
Error logs if a page still fails

Frequently Asked Questions

Can I recover a site with FTP if the homepage is down?

Yes, if FTP or SFTP still accepts the login. The website and the file service are separate. Connect with FileZilla or WinSCP, open public_html, and replace damaged files from a clean backup. If you cannot log in at all, reset the password in cPanel or ask the host. Client setup is in choosing an FTP client.

What if I do not have my own backup?

Ask the host for the latest account backup before you overwrite anything. Download a copy of the current files first so you can compare them. Without a backup you can only remove obvious junk files and restore what the host still has. Start automated copies after the site is stable. Backup jobs are covered in automating website backups with FTP.

Does restoring files also restore the database?

No. FTP restores themes, plugins, uploads, and config files. Posts, users, and store orders live in MySQL. Import a matching database dump in cPanel after the files are in place. A files-only restore can leave the site half-working. WordPress-specific file steps are in managing WordPress with FTP.

Should I use SFTP for recovery?

Yes when SSH is enabled. Recovery often includes passwords and configuration files, so encrypted SFTP or FTPS is safer than plain FTP. Extra FTP accounts still use FTPS unless they are SSH-enabled. See FTP vs SFTP vs FTPS and using SFTP with cPanel.

What should I do before I upload the backup?

Download the current public_html folder, note unexpected files, and check permissions. Then upload the clean backup into the same document root. After a compromise, change FTP, cPanel, database, and admin passwords. Do not log in from a computer you do not trust. Upload paths are in uploading files with FTP.

Which permissions should restored files use?

Use 644 for most files and 755 for directories unless the application documents something else. Wrong chmod can cause a blank page or an upload error after an otherwise good restore. Set ownership and permissions in the FTP client or cPanel File Manager. Account limits are explained in FTP user accounts.

How often should I back up so recovery is possible?

Weekly is a baseline for a quiet site. Daily is better when content or products change often. Also copy the site before updates. Keep dated copies off the same server. Test that an archive actually opens before you need it. Scheduling ideas are in automating file transfers.

How do I reduce the chance of another outage?

Keep CMS core, themes, and plugins updated, use unique passwords, and turn off unused FTP users. Enable HTTPS and keep an offsite backup. After a hack, look for leftover unknown files before you reopen the site. More reading is on the blog index and in protecting devices from malware.

Tweet  Share  Pin  Email

Add Comment

* Required information
Drag & drop images (max 3)

Comments

No comments yet. Be the first!

Composed by our masterful copywriters

RSH Web Services offers different cPanel hosting packages which are tailored to your needs. From personal, professional to business websites. We have a package that will fit your budget and needs, our reliable hosting services will work for you