<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacked</title>
	<atom:link href="http://www.terragalleria.com/blog/2012/04/12/hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.terragalleria.com/blog/2012/04/12/hacked/</link>
	<description>QT Luong&#039;s updates and thoughts on photography, travel and nature</description>
	<lastBuildDate>Wed, 22 May 2013 16:43:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=281</generator>
	<item>
		<title>By: Jonathan</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-175829</link>
		<dc:creator>Jonathan</dc:creator>
		<pubDate>Wed, 18 Apr 2012 15:25:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-175829</guid>
		<description><![CDATA[Thanks for sharing. Couple of comments:

1) &quot;High-resolution digital files are valuable, by only if you can license them, a task which is nowadays quite difficult even for legitimate image creators.&quot;

Much of the value of your site lies in the network of incoming links, distributed across the Internet, that you have built up over many years. The good news is that this incoming link network is essentially unhackable. The bad news is that incoming links have value only if your site is up and running.


2) &quot;However, the hosting company set up the drives as an LVM (Logical Volume Manager) volume group, which defeated the purpose. They recommended that I reload the OS and restart from scratch, although there exists a risky procedure to remove a drive from the LVM. As it had taken me more than a day to get to that point, I wasn&#039;t too keen on doing it over again, so I asked my system administrator to try the procedure. Sure enough, it failed, leaving the server in a state where it wouldn&#039;t even boot.&quot;

In a situation of the type, where the help-desk&#039;s advice is to reload the OS or perform some other complex task where you are risking hours or days of your time if all doesn&#039;t go as planned, why not put your current HDDs aside and start from scratch on a new HDD? Then if everything goes well you can wipe your old HDDs, use one of them and keep the other in reserve, and if everything doesn&#039;t go well you can at least use your server until you decide what to do next.]]></description>
		<content:encoded><![CDATA[<p>Thanks for sharing. Couple of comments:</p>
<p>1) &#8220;High-resolution digital files are valuable, by only if you can license them, a task which is nowadays quite difficult even for legitimate image creators.&#8221;</p>
<p>Much of the value of your site lies in the network of incoming links, distributed across the Internet, that you have built up over many years. The good news is that this incoming link network is essentially unhackable. The bad news is that incoming links have value only if your site is up and running.</p>
<p>2) &#8220;However, the hosting company set up the drives as an LVM (Logical Volume Manager) volume group, which defeated the purpose. They recommended that I reload the OS and restart from scratch, although there exists a risky procedure to remove a drive from the LVM. As it had taken me more than a day to get to that point, I wasn&#8217;t too keen on doing it over again, so I asked my system administrator to try the procedure. Sure enough, it failed, leaving the server in a state where it wouldn&#8217;t even boot.&#8221;</p>
<p>In a situation of the type, where the help-desk&#8217;s advice is to reload the OS or perform some other complex task where you are risking hours or days of your time if all doesn&#8217;t go as planned, why not put your current HDDs aside and start from scratch on a new HDD? Then if everything goes well you can wipe your old HDDs, use one of them and keep the other in reserve, and if everything doesn&#8217;t go well you can at least use your server until you decide what to do next.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: QT Luong</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-175313</link>
		<dc:creator>QT Luong</dc:creator>
		<pubDate>Mon, 16 Apr 2012 06:36:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-175313</guid>
		<description><![CDATA[Michael, yes, I&#039;ve spent quite a bit of time securing the server. This includes: change of all passwords (now using complicated long ones that are a pain to type) deployement of a reverse proxy, software updates (ex: PHP), paying attention to PHP notices (for instance going to PHP 5.3, I replaced hundreds of instances of mysql_db_query() since it is deprecated...), review of scripts to make them injection-proof, hiring a sysadmin for security audit, and installing a bunch of security programs and monitors.]]></description>
		<content:encoded><![CDATA[<p>Michael, yes, I&#8217;ve spent quite a bit of time securing the server. This includes: change of all passwords (now using complicated long ones that are a pain to type) deployement of a reverse proxy, software updates (ex: PHP), paying attention to PHP notices (for instance going to PHP 5.3, I replaced hundreds of instances of mysql_db_query() since it is deprecated&#8230;), review of scripts to make them injection-proof, hiring a sysadmin for security audit, and installing a bunch of security programs and monitors.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Russell</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-174911</link>
		<dc:creator>Michael Russell</dc:creator>
		<pubDate>Sat, 14 Apr 2012 20:53:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-174911</guid>
		<description><![CDATA[Glad you have everything back up and running though the road to completing that was not easy.  Have you taken any new precautions with the new server so this sort of thing is less likely to occur again?]]></description>
		<content:encoded><![CDATA[<p>Glad you have everything back up and running though the road to completing that was not easy.  Have you taken any new precautions with the new server so this sort of thing is less likely to occur again?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: QT Luong</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-174194</link>
		<dc:creator>QT Luong</dc:creator>
		<pubDate>Fri, 13 Apr 2012 02:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-174194</guid>
		<description><![CDATA[Richard, I don&#039;t think that the case. At the time of the first intrusion, I was not traveling, and therefore did not use public wifi. Also, I am wondering how those tools would work. I&#039;d imagine they&#039;d try to catch passwords, but for logging into the server I use only protocols such as ssh and scp which are highly encrypted (unlike, let say ftp). ]]></description>
		<content:encoded><![CDATA[<p>Richard, I don&#8217;t think that the case. At the time of the first intrusion, I was not traveling, and therefore did not use public wifi. Also, I am wondering how those tools would work. I&#8217;d imagine they&#8217;d try to catch passwords, but for logging into the server I use only protocols such as ssh and scp which are highly encrypted (unlike, let say ftp). </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rolf Hicker</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-174134</link>
		<dc:creator>Rolf Hicker</dc:creator>
		<pubDate>Thu, 12 Apr 2012 23:05:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-174134</guid>
		<description><![CDATA[I&#039;m very sorry to hear your trouble with the servers. I had to spent a fair amount of time into software development and server trouble too - not fun being a photographer. Glad you got it going again.

Hope you had a great time up North.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m very sorry to hear your trouble with the servers. I had to spent a fair amount of time into software development and server trouble too &#8211; not fun being a photographer. Glad you got it going again.</p>
<p>Hope you had a great time up North.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Wong</title>
		<link>http://www.terragalleria.com/blog/2012/04/12/hacked/#comment-174075</link>
		<dc:creator>Richard Wong</dc:creator>
		<pubDate>Thu, 12 Apr 2012 19:53:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.terragalleria.com/blog/?p=4432#comment-174075</guid>
		<description><![CDATA[Sounds like a complicated process, QT. I&#039;m not sure how often you use public internet wifi, but do you think your security was compromised by using public wifi? I went to an SEO conference in November and one of the speakers was demonstrating all these illegal tools to hack people&#039;s computer from public wifi networks. Which ironically was probably the reason why my site was hacked during that conference...]]></description>
		<content:encoded><![CDATA[<p>Sounds like a complicated process, QT. I&#8217;m not sure how often you use public internet wifi, but do you think your security was compromised by using public wifi? I went to an SEO conference in November and one of the speakers was demonstrating all these illegal tools to hack people&#8217;s computer from public wifi networks. Which ironically was probably the reason why my site was hacked during that conference&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
