Skip to content

Comment on One of my Drupal sites was hackedparent

Comments

That is assuming the cracker did not go further than the website's folder.

From my own experience, when one of my sites with username www-data was hacked (default apache installation), the client-side malware JS was injected into .htaccess file and added to ALL folders www-data had write access to.

What I am saying is, assume the worst, what other data could the cracked unix account do on the system.

Sorry, I should have clarified. A new VPS/image/machine. I would not simply create a "new site" on the box that got hacked as I too would assume evil is lurking outside of apache.

Douse it with gasoline and toast some marshmallows as I spin up a new instance imo :)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.