Malicious attack? What happened?

[ad_1]

Hey everyone,

I am in the process to figure out what exactly happened and I am at a loss. I self-host my own WordPress website. I set up everything in February, but had no time to further write on it in the past month. Took a look at it today and for some reason the login didn’t work. Took a look at the page to see that it reverted back to the sample page after the initial install. The `wp_users` table contains only an admin user (which doesn’t fit the admin name I used) with an unknown gmail address.

On the technical part, both worpress and the database run as Docker container. The database creates a mount-bind into `/var/lib/postgresql/data` and wordpress into `/var/www/html` to persist all data.

I am really at a loss at what happened. I don’t really care about the my changes. I write backups, hopefully they go far enough back in time. But that doesn’t matter as long as I can’t figure out the source of the changes.

If anyone has an idea how I can look further into it, I appreciate any help. Thank you!

[ad_2]
3 Comments
  1. Did you have any security plugin installed? what are the file permissions on the wordpress install and what ports are open on your servers?

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer