The board is really slow tonight.
Mal ,'Shindig'
Buffistas Building a Better Board ++
Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.
My home network is bogged down with a lot of large file copies, so I can't tell--are other people experiencing slowness? Hands?
It's seemed a little slow all day to me.
I'm feeling like the internet in general is slow, so yeah, also here.
The site is slow because we have been hacked.
I logged in and found the following script running: /var/www/vhosts/buffistas.org/cgi-bin/footgear.pl. Modification time of Feb 24.
The script is some kind of DDOS program. I think we have been using a shit-ton of bandwidth the past week or so.
I killed any footgear.pl processes that were running, moved the script out of the way, and made the cgi-bin directory unwritable. It will take me a while to go through the logs to see if I can figure out how they got in.
Yikes!
Good god, Tom. Thanks for catching that.
I am curious about how they got in, too. Our admin password is decently strong--do you think it should be changed?
A cursory google doesn't show me any scriptkiddy sites with that application name or anything, but I don't know all the l33t places to go.
eta: and do you think it's something we should report to iStrata in case that's how they got in, or other customers are compromised?
Wow! Thanks for catching that, Tom.
Looks like they got in through plesk.
Is there a security loophole or exploit that they used? Is our password compromised? Was it our plesk install, or one at a higher level (like iStrata admin, or something?)