Ok from the start;
We had our site reported as down by a customer. When I checked the site, all that was there was CentOS welcome page. I assumed that there had been a major technical issue with out Webhost. I asked them to look into it and they said they were working on it now and to check again in 10 minutes.
The website was restored, but products that were listed as sold had become available again and we were missing categories in the menu and products which we had just put on were no longer showing. It was like they had restored back to DB backup that was 1 Year old.
So I asked them to double check and make sure they had the correct backup, they said they only keep 10 days anyway so it can't be that old.
I've just been able to log into PHPmyAdmin for the first time and I can see that the categorises do appear in the tables and the products are also in the products table.
After days of back and forth the webhost finally said that they though our site had been subject to the injection, here is what they said: " further to my review it would appear that the initial issue was actually a site injection i.e someone externally took advantage of the sites code which caused the first issue, once we have ensured the site is working I will then review the updates around the site to ensure its patched."
So the question still remains what the hell could have caused this strange issue?
I'm currently downloading the site to perform a Winmerge against a fresh copy of ZC, see if that throws anything up.
ZC site version: 1.3.9h (I realise this is an old version, but I'm currently working on a 1.5 upgrade with template change and was waiting until that was finished before doing anything).
Any advice / help welcome.
Many thanks in advance
Logicalstep


Reply With Quote

