Skip to content

Accidentally rm -rf'd a client's entire WordPress

General Discussion by marcus_qc 24 replies 3.5K views
9 #1

Hey folks gonna keep this short because im shaking right now 3am client call just happened rm -rf on their entire wordpress directory no backups my fault entirely no excuses theyre a bakery site been up five years super stoked to ruin someones livelihood tonight gonna start scraping wayback and praying someone has a stale copy if youve got a miracle im listening

42U and still growing
#2

Best practices for disaster recovery:

  • Automated daily backups to offsite storage
  • Immutable snapshot policies
  • Pre-incident runbooks
  • Post-incident review within 24 hours

This situation is preventable. I recommend immediate implementation of a 3-2-1 backup strategy.

I host with Hetzner and learned this the hard way.

#3

Check cloudflare cache now

#4
marcus_qc said:
Rm -rf on their entire wordpress directory no backups my fault entirely

WAIT. Before you touch anything audit your bash history for what ELSE got deleted. This could be a breach vector. What if someone got shell first and MADE you run that command. I need you to check fail2ban logs NOW and verify your firewall rules before you do ANY recovery! 👀

airgapped, encrypted, faraday'd, still worried
#5

Oh man this takes me back to 2019 when I was working this shared host and a client ran rm -rf from their wordpress admin somehow dont ask me how and it took out seventeen sites because the permissions were all wrong and the backups were on the same array and the array was raid zero because someone thought speed mattered more than survival and I spent three days pulling files from google cache and archive.org and begging the client to check their email attachments for images and it was a wedding photographer so the emotional stakes were through the roof and we got maybe sixty percent back and they still sued and I learned that day that backups are not a suggestion they are the only thing between you and absolute professional annihilation and you never ever trust a single point of failure and you test your restores monthly and you keep offsite copies and you document everything and you nev

#6

This one landed: "customer deleted own site, demands we recover from backup, admits they cancelled backup service six months ago to save four dollars monthly." We found a stale Cloudflare cache with 80 percent of assets. The bakery sent us cookies. The ticket said "cookies stale, just like our cache." We ate them anyway.

reported. resolved. repeat.
#7

Ja the Cloudflare cache is your Friend in Despair nein do not rely upon it ja I have seen this before with the WordPress content management system ja the stale Cache is a BackupOfLastResort nein it is not a Backup strategy ja you got lucky this Time nein you will not get lucky again ja implement the Automated backup system immediately nein do not sleep until this is done

#8

What hosting stack? Need to know what's recoverable.

No logs, no proof. I have logs.
#9

I did this once, wp-content gone, heart stopped

#10

Wayback for a bakery, damn

8-char NTLM found in 4min 32sec

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft