Site hacked

Yep, my site was hacked. So was my other domain, sotsforum.net. That one is still in its hacked stage as of this writing. I have two service tickets outstanding with Dreamhost, but in the meantime, I found that I fortunately had a generic WordPress installation saved on my work computer, which is how I was able to get my blog back up.

Basically what happened was, someone accessed my FTP account illegally (I have since changed the password) and replaced my index.php files with pages full of ads. In the case of beingamberrhea.com, the site wouldn’t load and instead showed a MySQL error, but viewing the file on the server showed that it had indeed been modified at around 4:00 yesterday afternoon. The same thing happened in the wp-admin directory. I renamed both of the hacked files index_HACKED.php for Dreamhost’s reference, when/if they get to my support tickets (I’m guessing they’re swamped, ’cause this kind of thing happened to other accounts too) and uploaded the correct index.php files from the WordPress folder on my hard drive.

Meanwhile, amber.tangerinecs.com has its own problems; it was also hacked, but I had a full back-up of that as well, so I easily replaced index.php. However, I had inadvertently let the domain expire and had to renew it. :P It was registered w/ GoDaddy instead of Dreamhost, and I was not getting emails about registration. Hopefully all should be well, and Dreamhost still has my MySQL database with my 5 years worth of blog posts in it.

Side thought: I need to find a way to backup a site in its human-readable form, not just as a SQL dump!

Anyway. I don’t know when sotsforum.net will be back up, and I feel bad because I had been taking a pretty hands-off approach with that site lately anyway. But it seemed to be a self-sustaining community. Thank god for my WordPress stuff saved on this computer! I was feeling so weird and violated without my blog. I still feel weird and violated because of the hacking, but at least now my blog loads and I can tell y’all what’s up.

Add to that the fact that I woke up with a headache and stomach ache, and it just has not been a good day so far today!

As for my hosting situation after this… I’m not sure. I’ve been a Dreamhost customer for over 3 years and have been satisfied for the most part, and I know security breaches can happen to anyone despite the best laid plans, but still… I’m considering switching. On the other hand, I don’t know if I want to deal with the hassle of switching hosts. Will laziness win out? I do like Dreamhost’s web panel, and I remember back when I switched sotsforum.net from its previous home at HostReflex, what a pain in my ass that was.

Anyway… just wanted to let everyone know what’s up. Gotta work now. I wasn’t on the computer at all yesterday, so I’ll try to catch up w/ email and blog reading today as time permits (which it might not). On the bright side, Rusty and I had a great time with Figleaf yesterday. Photos from the Atlanta Botanical Garden will be posted tonight.

Update, 3:45 p.m. - Still no word from Dreamhost. It’s a good thing I had a WordPress backup! :P This means sotsforum.net is still a spam page, though. I’m sure Dreamhost is really freaking busy right about now, but damn, it’s been all day.

5 Responses to "Site hacked"

  1. Patrick Fitzgerald says:

    Usually after a screwup, these companies are a bit more vigilant (at least for a while) so I probably wouldn’t switch unless they make a habit of it.

  2. figleaf says:

    Yikes! For the record, back when I was doing my own hosting my site would get hacked semi-periodically. After months of tearing my hair out on layer after layer of security I finally figured out that I hadn’t excluded the flipping HTML “PUT” statement — the second oldest feature in the HTTP protocol after “GET!”

    Speaking of non-database backups, yet another reason I like MovableType is the default configuration is (still) all about static pages. That’s particularly nice for upgrades, site maintenance, backup, and hack recovery.

    I had a wonderful time with you and Rusty. You were perfect hosts, your friends were a blast, and Manuels (the “unofficial Georgia Democratic party headquarters”) was a riot.

    Good luck with your repairs,

    figleaf

  3. Veronica says:

    Oh, what a fucking pain in the ass. That sucks.

  4. Seth says:

    Sorry to hear about your troubles; thank goodness for that back-up.

  5. Mostly Muppet Dot Com says:

    Digital Bits…

    Just some bullets to keep you up-to-date, since I know you’re all on pins and needles.

    Thank god my Dreamhost-hosted blog didn’t get hosed
    Apologies to local bloggers Amber Rhea and Gregor Smith (who’s not really local anymore, being…

Leave a comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>