Part 3 — I Needed Remote MySQL Access, So I Made It Too Easy

Part 3 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com There was another problem waiting for me after the filesystem investigation. MySQL. And this one was partly my own fault. I had a legitimate reason for allowing remote MySQL connections. Some of my applications live on temporary cloud VPS instances. I create a VPS when I need…

Read More »

Part 2 — The Files Were Pretending to Be WordPress

Part 2 of a real-world WordPress VPS compromise investigation By SepedaTua — CrushEdge.com In Part 1, I stopped the server and started looking at the filesystem instead of immediately trying to get the websites back online. The first confirmed webshell was bf6f03.php. Then I found something more interesting. The attacker had apparently decided that naming a file shell.php was too…

Read More »
Fixing Common LEMP + WordPress Issues on Ubuntu 20.04

Fixing Common LEMP + WordPress Issues on Ubuntu 20.04

You set up a LEMP stack on Ubuntu 20.04, followed the tutorial, and now things are… not quite right. PHP doesn’t seem to work properly. Or WordPress installs fine, but you can’t upload files larger than 2MB. And every guide you find suggests editing some random php.ini or .htaccess and ends up breaking things. Let’s clean this up step by…

Read More »