May 24, 2024

Lost Comments

Yesterday somebody defaced this site. This trashed the database that backs the site, so we had to restore it from a backup. Everything seems to be back to normal, except that any comments submitted after the backup (about two days ago) were lost. Sorry for the inconvenience.


    Comment Vandalism: Is this something that I should be concerned about for my site with WordPress 2.0.3? (Not that I have many comments to lose!) What was the bug and how can we guard against it?

  4. Comment spam would be nothing new. We get about 600 comment spams per day. Fortunately there are outstanding filtering tools.

  5. The working theory is that they exploited a bug in WordPress, and managed to run the WordPress script to reinitialize the blog. This wiped out the database that holds all of the blog content (including comments), replacing it with the nearly empty database that new WordPress blogs get. I had to restore the database from a backup, so about two days of content were lost.

  6. I didn’t catch that incident. Out of interest, did they spam the comments, or did they manage to hack the main content proper? And if so, can you comment whether they exploited a “bonafide” security loophole (e.g. open permissions), or did they “hack” their way in (exploiting technical faults in the comment processing scripts, or the webserver’s protocol handling)?

  7. Sorry to hear of the vandalism. I guess that’s probably why TTLB had your blog with the default Hello World, but over a hundred links to it.

