Part 6 — What I Changed After the Restore

The final practical part of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com The restore was the easy part. The harder question was: How do I make sure I don’t have the same problem again next week? I could restore the websites from a known-good backup, start Apache and MariaDB, and call it a day. That would be…

Read More »

How to Delete Thousands of .TXT Files from Google Drive

If you run automated backups, sync log files, or work with data export scripts, Google Drive can quickly turn into a dumping ground. Last week, while cleaning up some folder structures, I found thousands of stray .txt files scattered across subfolders. Clicking them one by one in the web browser was out of the question—unless I wanted my weekend stolen…

Read More »

Part 4 — The Log Lines That Weren’t There

Part 4 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com By this point I had enough evidence to say: The server had been compromised. I had malicious PHP. I had disguised image files. I had a PHP-based file manager. I had an encoded payload. I had a native executable associated with cryptomining. I had suspicious database activity….

Read More »

Part 3 — I Needed Remote MySQL Access, So I Made It Too Easy

Part 3 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com There was another problem waiting for me after the filesystem investigation. MySQL. And this one was partly my own fault. I had a legitimate reason for allowing remote MySQL connections. Some of my applications live on temporary cloud VPS instances. I create a VPS when I need…

Read More »