So it’s finally happened

Passwords. Pah.

After running my blog on various virtual hosts and VPSs since 1998, my measures put into place to protect this site and the others on here were insufficient to protect against weak passwords.

Let’s just say that if you are a script kiddy and know all about press.php, tmpfiles.php and others, you have terrible operational security. There will be consequences. That is not a threat.

Published by vanderaj

Just another security geek

  1. If anything, I will add Google two factor authentication. I’ve already demoted the account that was broken into to a normal WP user and rotated all the passwords.

