Dev-Picayune

picayune: of little value or importance

Sites Hijacked

Thanks to a ‘Security Breach’ at DreamHost, my 2+ sites were hijacked. Obviously have things running again, but this issue points out several things. FTP is not very secure (as if we didn’t know that). Running PHP, while convenient because everyone runs it, is also a dangerous because the bad guys just wrote a script that edited any ‘index.php’ files out there on the accounts they managed to breach. If I’d been running some funky cool django stuff, there’d have been no index.php to hijack.

No comments

No comments yet. Be the first.

Leave a reply