A warning to secure your clients' Wordpress sites
Even though I had made an effort to keep wordpress updated on all the sites, I was using the same FTP and wordpress password on all sites. Fatal mistake number one.
I woke yesterday to find a welcome message from the hackers, and Indonesian music playing on one of my sites. I was able to restore a backup, thankfully, and thought I was over the worst.
But no such luck. One by one, my other sites started going down like dominoes. Five in the first day.
Then this morning I found another 9 affected. I have a Virtual Private Server, so had to roll back the entire VPS to last Friday, to be sure of getting rid of everything. This meant some of my clients lost updates they had made in the last few days.
So, a lesson to be learned. Always have different passwords on every site, and different passwords for the FTP and wordpress admin. And above all, always make sure your sites are backed up in such a way that they can be quickly restored.
You might think "it will never happen to me." That's what I thought. It's a sickening feeling when it happens.
Makes you wonder what goes on in the minds of the low-lifes who do this kind of hacking.
SCHEMA.ORG + GEOTAGGING + KML + PUBLISHERSHIP + so much more...
>> Agency founders: Regain control when overwhelmed
|~| VeeroTech Hosting - sales @ veerotech.net
|~| High Performance CloudLinux & LiteSpeed Powered Web Hosting
|~| cPanel & WHM - Softaculous - Website Builder - R1Soft - SpamExperts
|~| Visit us @veerotech Facebook - Twitter - LinkedIn
>> Agency founders: Regain control when overwhelmed
We help businesses manage cyber risk and compliance requirements.
|~| VeeroTech Hosting - sales @ veerotech.net
|~| High Performance CloudLinux & LiteSpeed Powered Web Hosting
|~| cPanel & WHM - Softaculous - Website Builder - R1Soft - SpamExperts
|~| Visit us @veerotech Facebook - Twitter - LinkedIn
We help businesses manage cyber risk and compliance requirements.
We help businesses manage cyber risk and compliance requirements.