4 ms·
I checked the zone-h database. http://www.zone-h.org/archive/notifier=T0xic http://www.zone-h.org/archive/notifier=T0xic It appears it's the usual mass deface
by saintfiends 15y ago
I checked the zone-h database.
http://www.zone-h.org/archive/notifier=T0xic http://www.zone-h.org/archive/notifier=T0xic
It appears it's the usual mass defacement, so they are probably exploiting a well-known vulnerability.
You are not the only one, I checked for other domains hosted with webfaction.com (Which seems to be a re-seller hosting service using linode, I could be wrong):
eyetraveldoc.com*
themediashow.net*
These were also defaced (these are using the same IP as yours), so there is a high chance that your hosting service is running a vulnerable kernel, service or the node you're on is. So notifying them and continuing from there would be a good start.
*They have been restored, but a mirror is on zone-h
- HNatWORK 15y agoThanks, I didn't know about this website. http://www.zone-h.org/archive/ip=174.121.79.144 http://www.zone-h.org/archive/ip=174.121.79.144 They have a list showing 26 hosts on that IP that were defaced. Randomly checked four of them (which are fixed now), all WordPress. But then #5 looked like a static HTML site (http://outrightoriginal.com/ http://outrightoriginal.com/), so I'm going to go with server compromise, not CMS compromise.
- codyguy 15y agoThanks for looking this up, I'll let the hosting provider know.