Hacked. A Short Story
kukuruku.co
kukuruku.co
Finally, if you're really paranoid, you also have to flash the bios in the machine too as there are rootkits that can potentially survive formatting...
If you think it might be compromised, if you have reason to believe that perhaps something bad happened, you probably should re-image it. There may be smoke without a fire, but it's not worth the risk, is it?
Systems like docker, LXC, and virtuozzo are where you run into the issue you describe.
It's rare that attackers tamper with data, usually they just leak it. Source code may be targeted though.
buffer overflows in non-executable files means it's easy for someone who wants to, to recompromise a machine: pdf, gif, jpg, whatever.
By that, I mean you need to consider any IPMI processor compromised as well, since these can be attacked (or their secrets stolen). Basically rebuild the machine from as low a level as you can. Depending on the brand of server hardware, you may need physical access.
I'm also starting to think that the move from Linux being a sysadmin-only OS to being something that can casually be spun up by even the most jr of developers, means we're having a Microsoft circa 1997 moment where security needs to be commoditized. I wonder if any of the few commercial AV's for Linux are updated frequently enough to catch hacks like these.
These are frequently set up on a single server, containing code, database, and any file storage necessary. They're frequently written by cloning and modifying a framework, making reinstalling from a known good copy difficult to impossible. They often have no version control and are frequently configured to allow the webserver to modify code, so there is rarely a known good copy of the site code. In short, what's running on the compromised server is often the only usable iteration of the site's code available.
I hope nobody on HN would willingly set up a site like this, but the fact remains that they exist and need to be maintained. Attempting to clean a system in place is nowhere near 100% effective, but it's much more effective than doing nothing, which is exactly what will happen if you try to tell a client that they have to be offline for days, lose several months of data, and pay someone to rewrite half their site from scratch because you want to format their server and attempt to rebuild it.
I refuse to work on projects that cannot be installed from scratch in a local VM.
The moment he discovered an attacker he should have been on the phone with the client explaining the situation and asking how to proceed. If the client wanted him to shut down and clean up the hack, he should be charging for that. If not, he should have done nothing.
Transparency resolves most problems.
What he could have done on the other hand is: inform the client of the attack and propose him to get rid of it for a certain fee...
Not a good general/continuing policy, but maybe worth doing the first time, if you're interested.
Basically, you destroy a VM and spin up a new one with one of your images, it will then use chef or salt to pull in its config.
SSH isn't needed then.
There are plenty of tutorials, but it is boring to follow them manually, especially if you need to make a couple of tweaks to ISO or update it.
So I put together a couple of scripts to automate the process:
[1] http://www.cosmonautdreams.com/html/blog/websites/readabilit...
Your source's UX qualifications also seem a bit... dubious.
Just a developer and sys admin, my qualifications come purely from usage. I only noticed the trend of web development going back to what it was in the early 2000's where landing pages & splash screens were all the rage. I hate reading any blog on medium or that follows this format to me it detracts from the content and is visually irritating.