3 ms·
You should consider what information was available on that server. Did the code contain any passwords for other systems (such as an internal DB, or another prod
by Practicality 10y ago
You should consider what information was available on that server. Did the code contain any passwords for other systems (such as an internal DB, or another production machine?). If so, those systems should be considered compromised now too.
On the other hand, if you are just getting started it may be that production doesn't have much on it yet, and you can just nuke the thing and start over.
I understand recommending security experts is easier, so that if you're wrong, you can just blame the expert, but you may be able to make the decision yourself if you are aware of everything that is on that machine.