The Haven - back up and running
Oct. 24th, 2010 04:54 pmMy lovely hosts, FutureQuest, have helped me to get rid of all the compromised files and they have blocked the IP that the hack originated in. They have been wonderful and incredibly fast to respond to everything, which is amazing on a Sunday afternoon.
I always write and update the site on my local hard drive, so I was able to restore everything to its pre-hacked state with no problems. It doesn't look like the hackers compromised the data in the reviews database, which is a relief!
That has been moved to a regular updating schedule, just in case.
The vulnerability was an old version of phyMyAdmin, which I have removed and I will be reviewing what I use in future to administer the databases. The hackers were able to use that to inject code in my index files and .htaccess files, which redirected everyone to a site that I assume then installed lots of nasties onto peoples' machines. If anyone visited The Haven between 20th October and 24th October, you should check your anti-virus and anti-spam things to make sure your machines were not attacked.
I apologise for this and I wish that I had detected the issues earlier. It is the first time the site has been hacked in the ten years that I have been running it, which I am trying to tell myself is a good running average although right now it doesn't feel like it.
Basic message: website restored and now protected better. Never believe it won't happen to you because it can.
I always write and update the site on my local hard drive, so I was able to restore everything to its pre-hacked state with no problems. It doesn't look like the hackers compromised the data in the reviews database, which is a relief!
That has been moved to a regular updating schedule, just in case.
The vulnerability was an old version of phyMyAdmin, which I have removed and I will be reviewing what I use in future to administer the databases. The hackers were able to use that to inject code in my index files and .htaccess files, which redirected everyone to a site that I assume then installed lots of nasties onto peoples' machines. If anyone visited The Haven between 20th October and 24th October, you should check your anti-virus and anti-spam things to make sure your machines were not attacked.
I apologise for this and I wish that I had detected the issues earlier. It is the first time the site has been hacked in the ten years that I have been running it, which I am trying to tell myself is a good running average although right now it doesn't feel like it.
Basic message: website restored and now protected better. Never believe it won't happen to you because it can.