Monday, September 04, 2006

hacked!

A few days after the last photo I put up, I logged on to my photoblog to post another. What do I find? My website's been hacked sometime in between.

Luckily only the index page was replaced, so I was able to reupload a backup copy I had on my computer. If anything else had been tampered with, I'd have probably had to build the photoblog over again. People are such idiots. What satisfaction do they get out of hacking someone's photoblog? There's no money to be stolen, no secret information to attain. I haven't made any political statements on that site, or said anything of an offensive nature. Just some punk kid in Saudi Arabia with a bit too much time on his hands.

I emailed the hosting company.

Hi,
I've been hosting with you for a few months now, and have had no bad experiences in the past.
This morning, when accessing my website, I was surprised and upset to see that my website had been hacked.
Fortunately, only the index page had been changed, so I was able to reupload a backup copy I had.
However, this security issue is quite serious as I'm sure you understand, and it may have me second-guessing my decision to host with you. I switched over after hosting with another company for many years.

I'm attaching a screenshot of what was left on my website. Please let me know the possible reasons that this could have happened and what steps both of us can take to prevent this from occurring in the future.

Looking forward to hearing from you soon,
Umar Shahzad


I got a reply back fairly quickly,
Hello,

There was a security vulnerability released earlier this week and we were in the process of updating all servers. However, in this process one of our servers was exploited. We have patched the vulnerability on all servers and this is impossible for this to happen again. This secuity issue is definitely quite serious, but it certainly could have been worse given that only an index file was deleted. Sorry for the inconvenience and thank you for your cooperation.

Thanks,

George Virdi
Sr. Systems Engineer


...So it was a problem on the server end, not on mine. Hopefully I don't experience something like this again. (I've noticed several blogger blogs I used to frequently read have also been hacked and completely deleted)

Oh, and even though it wasn't the issue, I've reset the passwords on all my accounts.. and I'd advise you guys to do the same every so often.

1 comment:

Pink said...

lol... that's quite funny actually... not for the victims tho obviously. saudi kids always have too much time on their hands.

anyway, am checking up all the blogs ive missed out on for like the past 2 months, congratualtions (sort of) on passing ur yr, inshaAllah hope all goes well.

also, i need ur expertise (yes, i am trying to flatter u) - have been looking up different types of design software available, i came across inkspace & gimp - just wondering what they're used for & how user-friendly they are for the beginner?

ws