Summary: This evening around 21:31 GMT all websites on pemlinweb10 were defaced. In most cases additional files called index.htm, index.html and index.php were put into document roots for websites.
The action we've taken thus far:
1) disabled all the files
2) removed all the files (currently underway still) so that you can upload your site files if you have backups.
3) kicked off a bare metal restore of the servers file system to one of our dedicated restore servers.
4) found the entry point, hole and have plugged them.
What's left: The bare metal restore will take approx 9 hours to complete, it's currently one hour into this so it'll be finished by morning when our engineering shift starts at 8am. We will then begin a mass restore of sites from the restore. The latest backup for this server is started at 15:00 this evening and ended at 18:31 so the data should be quite recent. And infact since it was just index files it shouldn't take a lot of effort to restore them once the full restore has taken place.
Caveats: Anyone who uploads a new index files this evening should expect this to be overwritten from our restore tomorrow morning. If the restore fails for some reason we'll have to kick it off again. However we have other options available to us but a bare metal restore is typically the fastest method.
Update 08:31: The restore is still on going, the ETA is around 3h and 30 minutes which brings us upto midday or there abouts. We'll post further updates when we have the restore completed.
FYI we just rebooted the hardware node that pemlinweb10 resides on and it should be back in a few minutes.
Update 12:10: At the moment any file who's name starts with index is being restored to the state it was in at 15:00 yesterday. We don't have an ETA on how long this part will take, but it should hopefully be finished before lunch.
Update 16:30: The restore has taken longer than expected, mainly because we vastly under estimated just how many "index" files there are. For example, Joomla puts an index.html in every folder as a measure against directory listings. The vast majority of files are restored now, with only a few thousand left. The process should be finished within the next 15 mins.
The action we've taken thus far:
1) disabled all the files
2) removed all the files (currently underway still) so that you can upload your site files if you have backups.
3) kicked off a bare metal restore of the servers file system to one of our dedicated restore servers.
4) found the entry point, hole and have plugged them.
What's left: The bare metal restore will take approx 9 hours to complete, it's currently one hour into this so it'll be finished by morning when our engineering shift starts at 8am. We will then begin a mass restore of sites from the restore. The latest backup for this server is started at 15:00 this evening and ended at 18:31 so the data should be quite recent. And infact since it was just index files it shouldn't take a lot of effort to restore them once the full restore has taken place.
Caveats: Anyone who uploads a new index files this evening should expect this to be overwritten from our restore tomorrow morning. If the restore fails for some reason we'll have to kick it off again. However we have other options available to us but a bare metal restore is typically the fastest method.
Update 08:31: The restore is still on going, the ETA is around 3h and 30 minutes which brings us upto midday or there abouts. We'll post further updates when we have the restore completed.
FYI we just rebooted the hardware node that pemlinweb10 resides on and it should be back in a few minutes.
Update 12:10: At the moment any file who's name starts with index is being restored to the state it was in at 15:00 yesterday. We don't have an ETA on how long this part will take, but it should hopefully be finished before lunch.
Update 16:30: The restore has taken longer than expected, mainly because we vastly under estimated just how many "index" files there are. For example, Joomla puts an index.html in every folder as a measure against directory listings. The vast majority of files are restored now, with only a few thousand left. The process should be finished within the next 15 mins.