Wow, that's a scary one, because even changing the passwords may be closing the barn door after the horse, with the potential for backdoor access.
Buffistas Building a Better Board ++
Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.
board slow for anyone else? normally, i'd chalk it up to our crappy internet here at work, but with the recent hack i thought i'd mention it.
Have you heard back from iStrata?
Not a word. I'll ping them again.
iStrata says we need to upgrade our Plesk.
By implication, we're on our own for that one.
Yech. So they're not taking any responsibility? Because it won't be just upgrading Plesk, right, it'll also mean tracking down any backdoors?
That's what we get with our own server. Control has its downsides.
Trufax.
I'm fairly certain they didn't leave any back doors behind. It just looked like a drive-by script kiddie attack. They just dropped off their payload and left. They made no attempt to cover their tracks by erasing log messages, or changing file modification times. And the files I found on the system correspond exactly to what I saw in the log files. There was nothing else. And the script they did leave was nothing special.
Okay, good.