{"id":23,"date":"2007-08-14T02:28:51","date_gmt":"2007-08-14T01:28:51","guid":{"rendered":"http:\/\/tmachine1.dh.bytemark.co.uk\/blog\/index.php\/2007\/08\/14\/re-install-complete-blog-should-be-ok\/"},"modified":"2007-09-10T05:01:46","modified_gmt":"2007-09-10T04:01:46","slug":"re-install-complete-blog-should-be-ok","status":"publish","type":"post","link":"http:\/\/new.t-machine.org\/index.php\/2007\/08\/14\/re-install-complete-blog-should-be-ok\/","title":{"rendered":"Re-install complete; blog should be OK"},"content":{"rendered":"<p>Someone brute-forced their way into the server last week, my fault for not disabling all logins to the server.<\/p>\n<p>Normally, this isn&#8217;t a problem, as the default firewall setup I always use prevents any remote logins except from known-good hosts. However, this server was accidentally provided with partially missing firewall code by the hosting company, and so I couldn&#8217;t run my firewall without first upgrading the kernel. And I&#8217;d been &#8220;too busy to get around to&#8221; doing that&#8230;<br \/>\n<!--more--><br \/>\nOh well. Fortunately, I had a very recent backup of the blog, and I&#8217;ve now discovered a couple of major flaws in WordPress&#8217;s backup system (note: it doesn&#8217;t bother even trying to backup your uploads, embedded images, etc) that I can now change my backup procedure to accomodate.<\/p>\n<p>Apologies to anyone trying to follow the links in the last 6 hours. You were probably locked-out &#8211; I firewalled off the whole machine for a few hours to investigate how they got in and what they did once they were in. You still have to wipe all harddisks and re-install, of course, but you need first to find out how they did it, or you have no way of making sure they don&#8217;t get in again.<\/p>\n<p>Oh, and I kept enough incriminating evidence to give to the police \/ FBI if the hosting providers manage to track down the perpetrators. One of them left his IP address in, but I&#8217;m pretty sure that was just another compromised host (have informed the large, famous, north-american telco it came from. Probably one of their naive users with a compromised windows 2k\/xp box).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Someone brute-forced their way into the server last week, my fault for not disabling all logins to the server. Normally, this isn&#8217;t a problem, as the default firewall setup I always use prevents any remote logins except from known-good hosts. However, this server was accidentally provided with partially missing firewall code by the hosting company, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/23"}],"collection":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/comments?post=23"}],"version-history":[{"count":0,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/23\/revisions"}],"wp:attachment":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/media?parent=23"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/categories?post=23"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/tags?post=23"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}