Yesterday there was a post about the main giderosmobile.com page redirecting to a porn site on which
@atillim stated that somebody had changed a htaccess file but was not sure why. I notice this thread appears to have been removed today without any follow up. If somebody has managed to get access to alter a htaccess file then I think Gideros need to follow this up to explain what happened and what measures have been taken to stop it happening again in the future.
I'm a little concerned that the thread appears to have been removed as that could be understood as hiding what happened. Are everybody's passwords safe, has any other information on the server been compromised?
Comments
Updating the .htaccess might be a quick fix but not a solution.
I would also like to know if this is investigated, what happened, how far it went and what has been done to prevent it to happen anymore.
Also what, in the worst case, can happen? Passwords are stolen and the pair username/password is tested on thousands of websites right?
Are any other sensitive informations stored in the database?
Also, do you know exactly how this was achieved? Have you checked that no backdoor has been uploaded to allow further access without going through the original route? Have you changed your server passwords and all other passwords to access parts of your system. Are you absolutely certain that access is now restricted?
This is all pretty basic stuff.
@all if you feel about your user info/SHA1 hash is not safe, please change your password.
1. After our investigation, we understand that only .htaccess file is changed.
2. We've already updated and cleaned up the system and changed all the server passwords.
3. Wordpress uses "salted" SHA1 hashes therefore the decryption facilities you've mentioned doesn't work on them (except bruteforce).
4. If you feel about your user info/salted SHA1 hash is not safe, please change your password.
Anyway, thank you for your update. Why did you delete the original thread?
Likes: phongtt
Likes: phongtt, talis
Likes: talis
Likes: talis