September 25, 2020

Lost Comments

Yesterday somebody defaced this site. This trashed the database that backs the site, so we had to restore it from a backup. Everything seems to be back to normal, except that any comments submitted after the backup (about two days ago) were lost. Sorry for the inconvenience.


  5. I didn’t catch that incident. Out of interest, did they spam the comments, or did they manage to hack the main content proper? And if so, can you comment whether they exploited a “bonafide” security loophole (e.g. open permissions), or did they “hack” their way in (exploiting technical faults in the comment processing scripts, or the webserver’s protocol handling)?

  6. The working theory is that they exploited a bug in WordPress, and managed to run the WordPress script to reinitialize the blog. This wiped out the database that holds all of the blog content (including comments), replacing it with the nearly empty database that new WordPress blogs get. I had to restore the database from a backup, so about two days of content were lost.

