12/08/2008

407 (mainly dutch) websites hacked and all backups are gone

This is the list 

This is the most destructive hack seen in the last couple of years and it poses some problems for professional hosters and website owners. You should have an offline backup of your website, Or one that is made online by another server without having entry rights (logins). if the backup server would have login rights, that server could have been emptied also, as was done with the regular backup. 

The biggest problem with this hack is how to protect your backup because if you enter as owner of the site or server than you shouldn't have under any circumstances have access to the logs or the backup. But the logs and backup will need some login to be sure that they are backing up all the files and not only the visible files. 

Have to break my head on this, except if any one has a solution in mind ? You have to remember that the hacker here has access to the site, the database, the server, the works,.... and still you will need to do a backup without giving the hacker-admin any rights on the backup server or giving him the possibility to see or decrypt the logins.

there are about 20 .be sites between them 

09:52 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment