I need some help trying to figure out what kind of attack is happening with my host. I have a single ubuntu server with some wordpress apps, bookstack, roundcube, and tautulli. I've noticed recently that a bunch of "index.php" files have been added to sites in "upload" folders, and that what appears to be system files for the web apps being modified.

(more detail in comments)

#wordpress #selfhosted #linux

Follow

@ryan are the services you run packaged in sandstorm.io ? You could run Sandstorm and get better isolation at least.

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.