Ralle
Owner
- Joined
- Oct 6, 2004
- Messages
- 10,212
Hey guys,
Last night was tough. About an hour before I had planned to go to bed, Shar Dundred messaged me about the site returning a 404 File not Found when visiting it. I was shocked and checked it out myself. Yep, the site was gone. I logged onto the server and confirmed that the site was removed. Speechless I logged onto my home server and confirmed that I had a backup. It was only five hours old. But simply recovering the data would not protect us against what happened. It might as well happen again.
In the database I found plug-in which would give an attacker a backdoor. On disk I found a script that did the same. I removed these and started recovering from backup. I also found that multiple admin accounts had new passwords so those were reset. But I still hadn't found the security hole. Ash showed me a website where you can find exploits. We found one for an addon we use and how to protect against it. The company that develops this add-on is not in business any more but there were instructions on how to patch it.
I'm glad I set up backup on The new server, it's only a few days old. I have updated my backup script to back up files every four hours instead of every 24. We lost five hours worth of pastebin entries, resource images, custom avatars and custom profile pictures. This is almost nothing, whew. The rest of the site is stored in a different location and was not affected.
This is while also part of the reason why I want to move to XenForo. It is maintained and generally more secure than our current setup. I know there are still many things I need to change for it to be in all aspects as good or better than this.
The site was down for maybe 20 minutes but it took a few hours to get all the pastebin entries back.
I have written a script that monitors the the web server for code changes. If any file is changed, added or removed I will get an email immediately. This should help with monitoring if something happens.
Ralle
Last night was tough. About an hour before I had planned to go to bed, Shar Dundred messaged me about the site returning a 404 File not Found when visiting it. I was shocked and checked it out myself. Yep, the site was gone. I logged onto the server and confirmed that the site was removed. Speechless I logged onto my home server and confirmed that I had a backup. It was only five hours old. But simply recovering the data would not protect us against what happened. It might as well happen again.
In the database I found plug-in which would give an attacker a backdoor. On disk I found a script that did the same. I removed these and started recovering from backup. I also found that multiple admin accounts had new passwords so those were reset. But I still hadn't found the security hole. Ash showed me a website where you can find exploits. We found one for an addon we use and how to protect against it. The company that develops this add-on is not in business any more but there were instructions on how to patch it.
I'm glad I set up backup on The new server, it's only a few days old. I have updated my backup script to back up files every four hours instead of every 24. We lost five hours worth of pastebin entries, resource images, custom avatars and custom profile pictures. This is almost nothing, whew. The rest of the site is stored in a different location and was not affected.
This is while also part of the reason why I want to move to XenForo. It is maintained and generally more secure than our current setup. I know there are still many things I need to change for it to be in all aspects as good or better than this.
The site was down for maybe 20 minutes but it took a few hours to get all the pastebin entries back.
I have written a script that monitors the the web server for code changes. If any file is changed, added or removed I will get an email immediately. This should help with monitoring if something happens.
Ralle