Bristol perspective: most "breaches" I investigate are drunk admins or cat on keyboard. Not kidding about the cat. Had a client with a shell open and a feline incident that ran sudo something. Check your logs but also check your sobriety and your pets.
Accidentally rm -rf'd a client's entire WordPress
olespete said:
A shell at 3am with a convenient rm -rf is not always user error
works on my bench ¯\_(ツ)_/¯
Following. Want to see how this ends.
Fail2ban is clean. No weird SSH times. Bash history is just me being stupid, no mystery there. I was deploying a theme update at 2am, got the paths wrong, recursive delete on the wrong parent. The "someone made me do it" theory is flattering to my ego but no. Just tired and dumb.
Database rebuild starts tomorrow. Client is bringing product photos on a USB stick. We go again.
42U and still growing
marcus_qc said:
Fail2ban is clean. No weird SSH times.
Fine. You are boring and I am relieved. Lock down your deploy scripts. Use a staging directory. Sleep during hours humans sleep.
airgapped, encrypted, faraday'd, still worried
Same here on the wp-content heart stop. Mine was a trailing slash in an rsync command. Recovered from a DigitalOcean snapshot I forgot I had. The relief was physical. Get your snapshots automated marcus_qc.