Jump to content
Forum²

Recommended Posts

  • Forum² Admin
Posted

On man! Bad memories. I got an email from a co-admin about the site be hacked. One thing an admin never wants to hear. I went to the site and was greeted with a page that said I should pay 500 bitcoin to get the site back. I was in panic mode. WTF am going to to do. I hadn't even logged in to the server yet.

 

I fire up RDP and log in to the server. Loaded right up. Now I'm thinking "wait a minute if my files are all encrypted why can I get into the server". I think maybe it's only the webroot. I open up webroot and can clearly see and access all the files. At that point I knew it was a scam. I still had to find out why they were able to replace the index.

 

Upon investigating I found I had left a test site on an old vulnerable version of Wordpress public accessible. I removed it and replaced the site index. Did a security audit and all was clean.

 

Lesson learned. Of you have old installs of anything make sure you don't leave them online.

  • 3 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...