rez.nuxx.net hull breech
Well, I’m pretty certain I know how the attack was done.
It appears to have been a phpBB exploit targeted at crisishour.com launched from 213.219.122.11.
Within the course of ~30 minutes that IP hit every single vhost I’ve got, and on crisishour.com it actively went and ‘did things’ in phpBB. Looks like via whatever hole in phpBB it deleted the contents of every vhost it could find and tossed an index.html or index.php in the root, as appropriate. I believe it also may have parsed the config files for Apache, because it seems like a pretty intelligent script. It also deleted all files and directories that www:www had access to in those subdirectories.
Fortunately things in the database and Gallery data directory are intact. I just need to move all of that over to Dreamhost one site at a time. This will take a while.
For what it’s worth, that IP is zone-h.org, which appears to be a shady ‘security’ site and the IP is owned by people in Estonia.
So, lessons learned?
1) Separate privileges based on site.
2) Don’t host domains for people who won’t keep their shit reasonably up to date and won’t stay in touch with me.
3) Don’t run phpBB until it’s been secure for a while.



