hmmm… what?
Addendum before you read the incoherent ranting: My host rocks. They had a backup! In fact, they had four days worth, but all I needed was one and not only that but they restored it for me and everything is like new again. Wow, I feel so much better. My old host never would have done that. Westhost rocks!
First of all, one of my sites was apparently “hacked.” My host caught it and killed the process, whatever it was and changed some settings that… heck, I know not to have turned on so I dunno how it was on unless the “hacker” did that. Anyway, so I’m going through, changing passwords and removing unneeded things. ‘Cause, like, you know, all my sites are interconnected, right? And I go to get rid of three unneeded FTP accounts. Select. Select. Select. Delete. Yes, remove user’s home directories because, yah, like, those are just test FTP accounts for upgrades and stuff and… done.
Only. DUH, VAL.
Two of those accounts weren’t just tests and they deleted two websites. One was my candle site which I had a backup of so I uploaded that and everything seems to be ok. But another was a very large site with lots of images that runs on Joomla. I have a backup from August 5, only… for some reason it’s not complete. I don’t have ANYTHING from my images folder and some other sub-stuff that’s actually set up for other people. Granted, 80% of those people haven’t updated their sites since 2005 and I have the files but I can’t replace their documents and images if they’re not in my backup.
I want to die.
Well, maybe not. More accurately I just wanna give up forever and ever. Bah, what a mess this is going to be. I think I have some of the originals for the old site on the other computer and external hard drives, but nothing is going to be named or set up the same way, etc. And some of the newer stuff might be hiding in my email but since I lost some of that not long ago, too, who knows?
What doesn’t make sense though is that I am like, a harcore backuper. So why do I not have this one site in its complete form anywhere? It doesn’t even make any sense. I have two and three copies of everything else I’ve ever done or used… so why not this?
Ahhhhhhhhhhhhhhh…
I know, I know. Please ignore my incoherent ranting and return to your regularly scheduled day.

Amber
August 18th, 2008 at 4.50 pm
I’m glad your host got things fixed. That was really awesome of them!
Ajemi
August 21st, 2008 at 2.32 pm
When did you switch from Site5? I can’t wait to switch from them when my contract is up.
Vixx
August 23rd, 2008 at 1.26 pm ♥
Soooo relieved everything’s back to normal!
V xx
Val
August 23rd, 2008 at 9.11 pm
Actually, this post was from before things went really bad, lol. But I have been too tired/busy to make any updates :)
Owen
August 24th, 2008 at 8.51 am ♥
I get nervous about recommending hosts because when things like this happen inevitably you get some of the blame. But in this case I’ll just say, “See???” ;)
Val
August 24th, 2008 at 5.19 pm
Heh! Well I know that no one is going to recommend me someone who’s given them bad service and that all things can change given time, so I would never hold a recommendation gone bad against you. :)
But yeah, Westhost has been great with this hacking mess. What ended up happening after my initial post here was that it turned out that the hacker either got back in or had another backdoor and deleted everything as far as my files and some configuration stuff. Westhost then took my account offline to try and locate the exact problem and then I ended up talking to one of the guys directly on the phone. He’d asked if it was ok if he could call me. So he explained it a bit more and at that point, they were bringing things back up and they restored all my files and said that it was a waiting game, had to see if there was another back door. He’d personally been going through, like, every file, though, to make sure they were clean. The processes that were apparently running were coming from a CLEAN WordPress install that I’d done the day before in case that person’s account was not updated/was not clean. It was in the wp-includes folder and was named to appear that it was a WP file. The IP address trying to access that file was 64.229.176.4 which is curiously similar to one of the ones trying to DoS me last month which was 64.229.225.34 (the other trying to DoS was 219.129.239.147). I’ve contacted the abuse department at Bell Canada but have yet to receive even a canned response.
Which reminds me… it’s been so long since we talked about IP blocking that I guess I don’t remember a lot of how it’s done. I can do IP filtering by the server level (I guess, that’s how I thought they explained it to me) and they blocked both of those 64… IPs. But… if it’s a DSL user all they really have to do is turn off their modem for a bit and it will pick a new IP right? So how far should one block? 64.229.* ??
So, anyway, he said after restoring everything that it was pretty much a waiting game to see if they had another backdoor yet and that they were keeping close watch. That was mid-Thursday so, so far so good.