
HAXX0RED
Adam Scheinberg, March 9, 2008 (17 years ago)
So, I updated sethadam1.com to "revision 9" on Friday, and when I went to show someone last night, imagine my surprise when I found the whole thing hosed. The site was missing entire chunks - random, non-sequential directories, missing entirely.
I'll spare you the details: I got hacked. Someone either brute forced their way into the admin site (which is now pretty locked down, until I figure this all out) or brute forced into SSH and uploaded several malicious PHP scripts. They are scary, I actually have them intact in a backup from a few days ago. How much has been revealed? My MySQL passwords? It's impossible to tell. Virtually everything will need scrubbing.
In the meantime, excuse any wonkiness until all is repaired. The good news is this finally forces me to finish work on the new administrative area I've been playing with.
I'll spare you the details: I got hacked. Someone either brute forced their way into the admin site (which is now pretty locked down, until I figure this all out) or brute forced into SSH and uploaded several malicious PHP scripts. They are scary, I actually have them intact in a backup from a few days ago. How much has been revealed? My MySQL passwords? It's impossible to tell. Virtually everything will need scrubbing.
In the meantime, excuse any wonkiness until all is repaired. The good news is this finally forces me to finish work on the new administrative area I've been playing with.
<br />
Seriously, running a machine that has been compromised is like getting in the driver's seat of your own car every day. The thief might drive you to the location you want, but it might also do other things ...