|
Written by Roberto Montagna
|
|
Saturday, 26 December 2009 14:45 |
|
In the evening of the 23rd December I noticed something wrong with my website: the homepage was simply a white page with a search field in the middle. It took me a while, but I finally realised that it had been defaced. In other words, somebody hacked into my website and changed some contents. I don't know exactly when that happened, but I can restrict the time frame to some time between the afternoon of the 22nd December and the evening of the 23rd, while I didn't check the internet. I don't know the details of how the attack was carried out. According to what the support of my hosting service said, it seems that I didn't upgrade the CMS I'm using. I don't think somebody actively tried to attack my website: rather, I believe that this was some kind of automated attack based on some known vulnerability of the CMS. As for the motivations, from a quick analysis of the scripts left on the server by the defacer, it seems to me that their purpose was to collect email addresses stored in the database (but there was only my address) and to attack the hosting server. Now I finally restored all the contents. From now on I'll keep an eye on the security warnings about Joomla, more for the time it took me to restore the whole thing than for the damage done, which was after all limited.
|
|
Last Updated on Saturday, 26 December 2009 15:05 |