Jump to content

Did my server get hacked or my Website?

I run a Web Server behind an untangle firewall running Ubuntu 16. I also use Cloudflare to hide my IP on my website. I looked today and Cloudflare noticed phishing pages on my website. I looked and they were fake Bank of America pages in my WordPress installation! It was an example.com/wordpress path so I think they just hacked into my blank WordPress install. I have removed it all. Is my server ok?

Specs:

 Gaming PC: i5 3570, 16GB 1600MHz, GTX 780 3GB, Transcend 128GB, WD 500GB, Seagate 500GB, Thermaltake 600W Smart, S340 w/ RGB, Windows 10 Pro

 Server: Xeon E5 2650, 12GB 1600MHz ECC, 8400GS, WD 2TB + 1TB + 1TB, EVGA 500B 500W, Windows 10 Pro

 Laptop: Macbook Pro Retina 2013, i7 4558U, 8GB 1600MHz, Intel Iris Pro 1.5GB, Apple 256GB NVME, Mojave

 

 Internet: $70/month For 500/100, Actually get 525/102

Link to comment
Share on other sites

Link to post
Share on other sites

You should probably wipe the server for good measusre, you don't know what else was put on there.

 

Or just delete the vm, thats why vms are great.

Link to comment
Share on other sites

Link to post
Share on other sites

You could start by checking your access logs, but you're probably best off just wiping everything

75% of what I say is sarcastic

 

So is the rest probably

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, Electronics Wizardy said:

You should probably wipe the server for good measusre, you don't know what else was put on there.

 

Or just delete the vm, thats why vms are great.

Yeah, its on a VM. Ill check the logs.

Specs:

 Gaming PC: i5 3570, 16GB 1600MHz, GTX 780 3GB, Transcend 128GB, WD 500GB, Seagate 500GB, Thermaltake 600W Smart, S340 w/ RGB, Windows 10 Pro

 Server: Xeon E5 2650, 12GB 1600MHz ECC, 8400GS, WD 2TB + 1TB + 1TB, EVGA 500B 500W, Windows 10 Pro

 Laptop: Macbook Pro Retina 2013, i7 4558U, 8GB 1600MHz, Intel Iris Pro 1.5GB, Apple 256GB NVME, Mojave

 

 Internet: $70/month For 500/100, Actually get 525/102

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, newcbomb said:

Yeah, its on a VM. Ill check the logs.

If its on a vm, just nuke it. 

 

Might want to keep the image to investagate later, but I wouldn't connect it to the network.

Link to comment
Share on other sites

Link to post
Share on other sites

@myselfolli @Electronics Wizardy I also just realized that  I don't even have SSH open on my firewall so i can only access it from the local network and WordPress was really the only point of entry. Should I be ok? 

Specs:

 Gaming PC: i5 3570, 16GB 1600MHz, GTX 780 3GB, Transcend 128GB, WD 500GB, Seagate 500GB, Thermaltake 600W Smart, S340 w/ RGB, Windows 10 Pro

 Server: Xeon E5 2650, 12GB 1600MHz ECC, 8400GS, WD 2TB + 1TB + 1TB, EVGA 500B 500W, Windows 10 Pro

 Laptop: Macbook Pro Retina 2013, i7 4558U, 8GB 1600MHz, Intel Iris Pro 1.5GB, Apple 256GB NVME, Mojave

 

 Internet: $70/month For 500/100, Actually get 525/102

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, newcbomb said:

@myselfolli @Electronics Wizardy I also just realized that  I don't even have SSH open on my firewall so i can only access it from the local network and WordPress was really the only point of entry. Should I be ok? 

Well since somebody gained access to your machine - in one way or another - no, you're not okay

75% of what I say is sarcastic

 

So is the rest probably

Link to comment
Share on other sites

Link to post
Share on other sites

Pretty sure this is a WordPress issue, if the server got accessed then surely they would've done something else than to simply add fake Wordpress entries

🙂

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×