Jump to content

wolstech

Chief Risk Officer
  • Posts

    19183
  • Joined

  • Last visited

  • Days Won

    759

wolstech last won the day on June 9

wolstech had the most liked content!

About wolstech

  • Birthday May 17

Contact Methods

  • Website URL
    https://www.raxsoft.com

Profile Information

  • Gender
    Male
  • Location
    Pennsylvania

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

wolstech's Achievements

Grand Master

Grand Master (14/14)

  • Well Followed Rare
  • Reacting Well Rare
  • Conversation Starter Rare
  • Dedicated Rare
  • Very Popular Rare

Recent Badges

1.6k

Reputation

  1. In regards to your original request, you must send your support request from the email address on the account in order for it to be reset. Providing the email address in the body of the email is not sufficient, the email must actually be sent from that mailbox to prove that you control the associated email address.
  2. non-WordPress domain on this account) That's why I missed it...that domain has node instead. When I went through the domains, I saw that one had node enabled and just skipped over it, as I was focused on the WP stuff. Good news is that those files, while definitely malicious, likely would not have been able to run anyway since you had Node enabled (passenger redirects everything to node when enabled on a domain, so Apache never gets to run the PHP files). The interesting part is that the index.php is clearly meant for a nonexistent WP on that domain, and the mac.php looks like it may be the same or a very similar file to a file called bless24.php that was on the compromised lda.ng domain (I recognize this string from the top: xtamdxsirm from the other day).
  3. Updated and unsuspended. Your account may take up to 2 hours to function.
  4. The files from your old account can be downloaded from https://heliohost.org/backup/
  5. What is your username?
  6. The contents of the domain lda.ng have been discarded, the associated WP database developer1_lda has been dropped, and you've been unsuspended. Your account may take up to 2 hours to function fully. The attack came in through Wordpress itself, which is usually either a result of plugins with vulnerabilities, or failure to install updates. A backup from February actually does exist for your account at https://heliohost.org/backup/ if you need anything from that timeframe. You can make backups using the backup tool in Plesk. Note that if you use this, it is advised that you configure remote storage, as the backups it creates count towards your disk space quota and can quickly cause you to run out of space.
  7. Krydos can install this for you.
  8. Our policy is typically to require the entire account be reset without a backup to destroy the contents before you can recover a hacked account (in case phishing or similar was set up and stolen information is present), though after looking through your account I don't see anything suspicious outside of the one domain that was compromised (lda.ng). Are you OK with deleting the contents of the domain lda.ng and the associated WP database to be unsuspended?
  9. Your friend can do that themselves by logging into the account, selecting delete account, and then on the following screen, clicking the option to archive account instead of deleting it. If they do this, they'll also be able to restore the account themselves later without losing any data.
  10. Wiki got attacked by bots. The forum and wiki live on the same server, so the wiki being hit causes the forum to slow down. We are working to mitigate the bot attack against the wiki.
  11. The file hk_hlm_founds.txt on your account is in a folder called pass_lists, which we took to mean it's "found" (stolen) passwords. Can you explain what this file is for? Can you show how you obtained the contents of this file? Note that if we agree to unsuspend you, we are likely going to require a full reset without a backup as well. Also escalating as I'm curious about Krydos's input on this...
  12. That account is permanently banned because it was used to store what appears to be stolen personal information.
  13. The IP you're posting from is not blocked. What IP are you having issues with?
  14. I've gone ahead and created this under your other account. Please check your PMs for information regarding your Lily account.
  15. That domain is working for me and the SSL certificate is installed now. A test email also delivered successfully from my end. You probably didn't wait long enough for DNS to propagate or something. Can you give it another try?
×
×
  • Create New...