Apr. 16th, 2011

octothorpe: (Default)
It seems one of my websites was hacked — ages ago. They were able to get in via an old Movable Type install. Through it, they were able to modify the HTACCESS file, and create a bunch of files (although it seems they couldn't modify existing ones). the HTACCESS file was gigantic — full of ModRewite rules (redirecting requests to different URLs). It seems I was a zombie host to all sorts of strange files… not just star porn, but famous quotes from Donald Rumsfeld.

I've stopped it by removing the hacked file, and removing all scripts, but *my* pages still exist (I removed some suspicious directories), so the operate normally. (MT was never truly dynamic… if you changed something, you rebuilt the entire website if that change appeared on every page)

So how did I find out? Well, my new Wordpress install required me to create a bunch of 301 Redirects (so my old content will be found at a new URL, and Google et al will automatically change their search results to match) and it seems those conflicted with the parent (corrupt) htaccess file, causing BOTH domains to become totally dead through an Error 500 (internal server error).



Crazy.
octothorpe: (Default)
All too strange:

These are the file requests that are now 404ing (as the redirect isn't there anymore)

monitors-jacques-cousteau-thesis-statement
speculators-julia-louis-dreyfus-montgomery-doughnuts
doesn-famous-quotes-donald-rumsfeld
shaven-bonnie-wright-fake
church-ryan-sheckler-skateboards
dreads-online-radio-theriver-amy-grant
her-anthony-hopkins-morgan-freeman
lowering-jacqueline-obradors-sex-video
immune-michelle-monaghan-thong

Profile

octothorpe: (Default)
octothorpe

Expand Cut Tags

No cut tags