Hacked with drives now empty - Please help!


13 posts in this topic Last Reply

Recommended Posts

Hi All,

 

I need your help please. Sometime within the last few hours all of my drives are appearing as empty and the icon for my server is showing as 'HACKED'. Is anybody able to help me at all please?

 

Regards

Gary

Screenshot 2021-03-18 at 18.35.38.png

Link to post
3 minutes ago, GaryBellars said:

Hi SpuddyUK, not port forwarding anything to my knowledge. I believe my password was just the default one

I'm going to say you probably are forwarding http/https to the unraid host and that you didn't have a root password. I.E anyone on the internet could access your unraid box. 

Link to post

Did you put your server into your router's DMZ?

 

Does there happen to be any other diagnostics within /logs on the flash drive - relatively recent?  They might shed some light on what/why this happened.

 

As for recovery, your files are gone, but you might want to look into UFS Explorer (run on a Windows Box, to recover what you've lost), but it's probably pointless unless we can determine why this happened, otherwise it's just going to (probably) happen again.

 

Are you running a wordpress site or something via a container?

Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.