Antichrist hacker targets WB


lausianne

I do have a backup module installed yes. Is that a problem?
(meanwhile upgraded to 2.8.1)

chio


lausianne

#1
Hi,

I'm surprised I haven't found anything about this on the forum yet.
This morning I found my own WB2.8 site hacked by some Antichrist guy. I did a quick Google search and found several other hacked sites, all WB.
"The Antichrist was here - 0KRam" is what the guy likes to put somewhere in front, preferably as an additional page before the home page. Adding some text, too.

All changes I found on my site were the added page, and all users had new passwords and email address. No obvious damage or malicious code. (I might have overlooked something.)
The hacks that I have seen before were quite a bit worse. Malicious code or site completely replaced by sth. ugly or both. Often it's the server, that's hacked, not the site directly.

Anyway, I'd like to know how he got in and how to avoid it in the future. Of course I changed all passwords and checked my access settings.
If anyone wants to analyse a hacked site, google one and ask the owner. I couldn't wait to clean mine, sorry.

I'm off reading the security stuff in this forum ...

Cheers,
Ralf.