Urgent Please Read!
Posted: Tue Mar 23, 2004 8:17 pm
Hey everyone,
Sunday afternoon the server was attacked. After a security investigation they have confirmed that this was a professional attack directed at this server with a purpose.
Once I was made aware of the breach I put into play our security plan for a hack attempt. Because of protocol the server was offline for 6 hours so the data center could clear the server and install a new hard drive.
Yesterday, as we were transferring files form the old Hard drive to the new one we detected viruses on all files, on all sites, on this server. NOT TO WORRY IT CANNOT BE TRANSFERRED OUTSIDE THE SERVER! This then lead to the higher level investigation, that found 2 hidden directories that contained programs that has caused this server to be compromised.
The data center has a built in protocol that calls for the server to be pulled offline until the investigation is finished. So they have given us time to finish the investigation and reformat our security system on this server. This will require the server to be on and off line frequently over the next few days.
Because the hacker(s) used a brute force program they have all the passwords on the server including every member of storm2k.With that said it is going to a huge task to change all password and it would make no sense to do it before the server is clear ands secured. You will be receiving an email with instructions on how to proceed in this matter.
Again I want to apologize for this problem. We have been doing private business for 4+ years and have never been hacked. That is 300+ servers with a perfect record. Now on a server that only serves non-profit community based website is the target, it just does not make sense. Only someone with a grudge would do this. We will find out who has done this. The FBI has the case and they will pursue charges.
Steve O.
Sunday afternoon the server was attacked. After a security investigation they have confirmed that this was a professional attack directed at this server with a purpose.
Once I was made aware of the breach I put into play our security plan for a hack attempt. Because of protocol the server was offline for 6 hours so the data center could clear the server and install a new hard drive.
Yesterday, as we were transferring files form the old Hard drive to the new one we detected viruses on all files, on all sites, on this server. NOT TO WORRY IT CANNOT BE TRANSFERRED OUTSIDE THE SERVER! This then lead to the higher level investigation, that found 2 hidden directories that contained programs that has caused this server to be compromised.
The data center has a built in protocol that calls for the server to be pulled offline until the investigation is finished. So they have given us time to finish the investigation and reformat our security system on this server. This will require the server to be on and off line frequently over the next few days.
Because the hacker(s) used a brute force program they have all the passwords on the server including every member of storm2k.With that said it is going to a huge task to change all password and it would make no sense to do it before the server is clear ands secured. You will be receiving an email with instructions on how to proceed in this matter.
Again I want to apologize for this problem. We have been doing private business for 4+ years and have never been hacked. That is 300+ servers with a perfect record. Now on a server that only serves non-profit community based website is the target, it just does not make sense. Only someone with a grudge would do this. We will find out who has done this. The FBI has the case and they will pursue charges.
Steve O.