{"id":11998,"date":"2013-12-11T09:41:37","date_gmt":"2013-12-11T19:41:37","guid":{"rendered":"http:\/\/www.debito.org\/?p=11998"},"modified":"2013-12-11T09:41:37","modified_gmt":"2013-12-11T19:41:37","slug":"blog-biz-debito-org-hacked-down-for-nearly-two-weeks-now-back-up","status":"publish","type":"post","link":"https:\/\/www.debito.org\/?p=11998","title":{"rendered":"BLOG BIZ: Debito.org hacked, down for nearly two weeks, now back up"},"content":{"rendered":"<p>eBooks, Books, and more from ARUDOU Debito (click on icon):<br \/>\n<a href=\"https:\/\/www.debito.org\/handbook.html\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11452\" title=\"Guidebookcover.jpg\" alt=\"Guidebookcover.jpg\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2013\/05\/Guidebookcover.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/japaneseonly.html\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11335\" alt=\"japaneseonlyebookcovertext\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2013\/04\/japaneseonlyebookcovertext-150x150.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/handbook.html\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-1298\" title=\"Handbook2ndEdcover.jpg\" alt=\"Handbook for Newcomers, Migrants, and Immigrants to Japan\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2012\/12\/Handbook2ndEdcover.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/inappropriate.html\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8577\" title=\"inappropriatecoverthumb150x226\" alt=\"\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2011\/03\/inappropriatecoverthumb150x226.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/japaneseonly.html#japanese\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-1700\" title=\"jobookcover\" alt=\"\u300c\u30b8\u30e3\u30d1\u30cb\u30fc\u30ba\u30fb\u30aa\u30f3\u30ea\u30fc\u3000\u5c0f\u6a3d\u5165\u6d74\u62d2\u5426\u554f\u984c\u3068\u4eba\u7a2e\u5dee\u5225\u300d\uff08\u660e\u77f3\u66f8\u5e97\uff09\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2008\/05\/jobookcover-150x150.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"http:\/\/www.cinemabstruso.de\/strawberries\/main.html\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2735\" title=\"sourstrawberriesavatar\" alt=\"sourstrawberriesavatar\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2009\/03\/sourstrawberriesavatar.jpg\" width=\"75\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/?cat=32\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4921\" title=\"debitopodcastthumb\" alt=\"debitopodcastthumb\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2009\/11\/debitopodcastthumb.jpg\" width=\"100\" height=\"100\" \/><\/a><a href=\"https:\/\/www.debito.org\/?p=10137\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-10142\" title=\"Fodors\" alt=\"\" src=\"https:\/\/www.debito.org\/wp-content\/uploads\/2012\/04\/Fodors.jpg\" width=\"75\" height=\"100\" \/><\/a><br \/>\nUPDATES ON TWITTER: arudoudebito<br \/>\nDEBITO.ORG PODCASTS on iTunes, subscribe free<br \/>\n&#8220;LIKE&#8221; US on Facebook at <a href=\"http:\/\/www.facebook.com\/debitoorg\">http:\/\/www.facebook.com\/debitoorg<\/a><br \/>\n<a href=\"http:\/\/www.facebook.com\/handbookimmigrants\">http:\/\/www.facebook.com\/handbookimmigrants<\/a><br \/>\n<a href=\"https:\/\/www.facebook.com\/JapaneseOnlyTheBook\">https:\/\/www.facebook.com\/JapaneseOnlyTheBook<\/a><br \/>\n<a href=\"https:\/\/www.facebook.com\/BookInAppropriate\">https:\/\/www.facebook.com\/BookInAppropriate<\/a><\/p>\n<p>Hi Blog. It&#8217;s good to be back after nearly two weeks of being down after being hacked. Just a brief paragraph recap of what happened for those who are interested:<\/p>\n<p>On November 29, I tried to log in but found that my password wouldn&#8217;t work. I got in touch with my provider but they were slow in answering, and after being bounced between a couple of helpful and unhelpful techies, I got signed up for a cleaning-out service. This took some time, as Debito.org after nearly two decades of service has accumulated around 16 GBs of data. But once that was cleaned out, I still had trouble logging in. So I had to manually update themes and change passwords here and there, only to find out that the only password that would now work to avail me of this dashboard was the old one (I&#8217;ve now gotten in and changed it officially via the blog dashboard). So here we are, back, as of this morning, ready to resume discussion.<\/p>\n<p>Meanwhile, the question remains, <strong>who hacked Debito.org and why?<\/strong> Several techies wrote to me saying that WordPress is particularly vulnerable to hacks and spiders that implant viruses with delayed infection times. I don&#8217;t doubt that, but hours after Debito.org was taken offline, I got this weird message:<\/p>\n<p>======================<br \/>\n<strong><em>Begin forwarded message:<\/em><\/strong><\/p>\n<p><em>From: &lt;dvib7om+7tzkj4@guerrillamail.com&gt;<\/em><br \/>\n<em> Subject: All your base are belong to us<\/em><br \/>\n<em> Date: December 1, 2013 at 7:57:47 PM HST<\/em><br \/>\n<em> To: &#8220;debito@debito.org&#8221; &lt;debito@debito.org&gt;<\/em><br \/>\n<em> Return-Path: &lt;dvib7om+7tzkj4@guerrillamail.com&gt;<\/em><br \/>\n<em> X-Original-To: debito@debito.org<\/em><br \/>\n<em> Delivered-To: x9560096@homiemail-mx2.g.dreamhost.com<\/em><br \/>\n<em> Received: from alc-junkmail-backend3.dreamhost.com (caiajhbdcaib.dreamhost.com [208.97.132.81]) by homiemail-mx2.g.dreamhost.com (Postfix) with ESMTP id 43058448606 for &lt;debito@debito.org&gt;; Sun, 1 Dec 2013 21:58:58 -0800 (PST)<\/em><br \/>\n<em> Received: from localhost (localhost [127.0.0.1]) by alc-junkmail-backend3.dreamhost.com (Postfix) with ESMTP id 3F4171616045 for &lt;debito@debito.org&gt;; Sun, 1 Dec 2013 21:58:58 -0800 (PST)<\/em><br \/>\n<em> Received: from connor.dreamhost.com ([208.97.132.205]) by localhost (alc-junkmail-backend3.dreamhost.com [208.97.132.104]) (amavisd-new, port 10024) with ESMTP id Nbkua-ThjKXQ for &lt;debito@debito.org&gt;; Sun, 1 Dec 2013 21:58:58 -0800 (PST)<\/em><br \/>\n<em> Received: from guerrillamail.com (mail.guerrillamail.com [198.143.169.10]) by connor.dreamhost.com (Postfix) with ESMTP id AB6042CA800C for &lt;debito@debito.org&gt;; Sun, 1 Dec 2013 21:58:57 -0800 (PST)<\/em><br \/>\n<em> Received: by 198.143.169.10 with HTTP; Mon, 02 Dec 2013 05:57:47 +0000<\/em><br \/>\n<em> X-Dh-Virus-Scanned: Debian amavisd-new at alc-junkmail-backend3.dreamhost.com<\/em><br \/>\n<em> X-Spam-Flag: NO<\/em><br \/>\n<em> X-Spam-Score: -1.039<\/em><br \/>\n<em> X-Spam-Status: No, score=-1.039 tagged_above=-999 required=999 tests=[RP_MATCHES_RCVD=-1.049, T_DKIM_INVALID=0.01]<\/em><br \/>\n<em> Mime-Version: 1.0<\/em><br \/>\n<em> Message-Id: &lt;159d7d8b8dd29e053ac7484078bb82ca2248@guerrillamail.com&gt;<\/em><br \/>\n<em> X-Originating-Ip: [185.2.28.159]<\/em><br \/>\n<em> Content-Type: text\/plain; charset=&#8221;utf-8&#8243;<\/em><br \/>\n<em> Content-Transfer-Encoding: quoted-printable<\/em><br \/>\n<em> X-Domain-Signer: PHP mailDomainSigner 0.2-20110415 &lt;http:\/\/code.google.com\/p\/php-mail-domain-signer\/&gt;<\/em><br \/>\n<em> Dkim-Signature: v=1; a=rsa-sha1; s=better; d=guerrillamail.com; l=255; t=1385963871; c=relaxed\/relaxed; h=to:from:subject; bh=ouvuUWJpwETjUDkcfcPvQDw0gQM=; b=EjFrOzxmAT\/eOU2HuLhFdm1C3vIFrookRLn+491+dkq3Y4K6XnkVbqScxTuQsQoM<\/em><\/p>\n<p><strong>you were taken down and you will be taken down again until you learn how not to be a hypocrite<\/strong><\/p>\n<p>&#8212;-<br \/>\n<em>Sent using GuerrillMail.com<\/em><br \/>\n<em> Block or report abuse: https:\/\/www.guerrillamail.com\/abuse\/?a=RUR2DBkPY7AQigeg%2FzAQYBM%3D<\/em><br \/>\n======================<\/p>\n<p>In response, we&#8217;ve signed up for a program offering constant security scans and cleaning, and although that increases maintenance costs, we&#8217;ve gotten donations (and lots of free advice, thanks for both!) from very kind people out there. Much obliged!<\/p>\n<p>If you like what you see and want to keep Debito.org up and hack-free, please consider contributing a little something by Paypal:<\/p>\n<form action=\"https:\/\/www.paypal.com\/cgi-bin\/webscr\" method=\"post\" target=\"_top\"><input type=\"hidden\" name=\"cmd\" value=\"_s-xclick\" \/><br \/>\n<input type=\"hidden\" name=\"encrypted\" value=\"-----BEGIN PKCS7-----MIIHPwYJKoZIhvcNAQcEoIIHMDCCBywCAQExggEwMIIBLAIBADCBlDCBjjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRYwFAYDVQQHEw1Nb3VudGFpbiBWaWV3MRQwEgYDVQQKEwtQYXlQYWwgSW5jLjETMBEGA1UECxQKbGl2ZV9jZXJ0czERMA8GA1UEAxQIbGl2ZV9hcGkxHDAaBgkqhkiG9w0BCQEWDXJlQHBheXBhbC5jb20CAQAwDQYJKoZIhvcNAQEBBQAEgYAr7Zk5vFp7g6UHpsixKSnyf73HK+9zloN8cs5W0XycEq0lO5p9x\/TECgT\/I63zzoZA7VV4Z6TB7ICSt0hs2LcNIlbE4ZEtVKjD99SttNAqvBPGA25DFvVp0sK362I6v5EOPo2xGnJXdMUjHRyyyLhimMUzN6rH3fMfWWet6TX9iDELMAkGBSsOAwIaBQAwgbwGCSqGSIb3DQEHATAUBggqhkiG9w0DBwQIOnizK9+VHKGAgZicL731lHZ04+WHV\/yyWJrs3CXmC1FYLMH\/pDSyxU0sQiusO\/Abr8jFWHATKNg8jGJjqK9\/u7S4XmOVHWnktDWPW05PoHor31clzvG2gBMfggAaiJf3Q4axotKaGBmCrhNnMT8GVwmQ6uLavkHv+iTUD\/c\/lIp\/s+3wOvb14qFc4w0fSBAFUkctsqgUBdwdfJONN7uexw03i6CCA4cwggODMIIC7KADAgECAgEAMA0GCSqGSIb3DQEBBQUAMIGOMQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExFjAUBgNVBAcTDU1vdW50YWluIFZpZXcxFDASBgNVBAoTC1BheVBhbCBJbmMuMRMwEQYDVQQLFApsaXZlX2NlcnRzMREwDwYDVQQDFAhsaXZlX2FwaTEcMBoGCSqGSIb3DQEJARYNcmVAcGF5cGFsLmNvbTAeFw0wNDAyMTMxMDEzMTVaFw0zNTAyMTMxMDEzMTVaMIGOMQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExFjAUBgNVBAcTDU1vdW50YWluIFZpZXcxFDASBgNVBAoTC1BheVBhbCBJbmMuMRMwEQYDVQQLFApsaXZlX2NlcnRzMREwDwYDVQQDFAhsaXZlX2FwaTEcMBoGCSqGSIb3DQEJARYNcmVAcGF5cGFsLmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAwUdO3fxEzEtcnI7ZKZL412XvZPugoni7i7D7prCe0AtaHTc97CYgm7NsAtJyxNLixmhLV8pyIEaiHXWAh8fPKW+R017+EmXrr9EaquPmsVvTywAAE1PMNOKqo2kl4Gxiz9zZqIajOm1fZGWcGS0f5JQ2kBqNbvbg2\/Za+GJ\/qwUCAwEAAaOB7jCB6zAdBgNVHQ4EFgQUlp98u8ZvF71ZP1LXChvsENZklGswgbsGA1UdIwSBszCBsIAUlp98u8ZvF71ZP1LXChvsENZklGuhgZSkgZEwgY4xCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzEUMBIGA1UEChMLUGF5UGFsIEluYy4xEzARBgNVBAsUCmxpdmVfY2VydHMxETAPBgNVBAMUCGxpdmVfYXBpMRwwGgYJKoZIhvcNAQkBFg1yZUBwYXlwYWwuY29tggEAMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADgYEAgV86VpqAWuXvX6Oro4qJ1tYVIT5DgWpE692Ag422H7yRIr\/9j\/iKG4Thia\/Oflx4TdL+IFJBAyPK9v6zZNZtBgPBynXb048hsP16l2vi0k5Q2JKiPDsEfBhGI+HnxLXEaUWAcVfCsQFvd2A1sxRr67ip5y2wwBelUecP3AjJ+YcxggGaMIIBlgIBATCBlDCBjjELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRYwFAYDVQQHEw1Nb3VudGFpbiBWaWV3MRQwEgYDVQQKEwtQYXlQYWwgSW5jLjETMBEGA1UECxQKbGl2ZV9jZXJ0czERMA8GA1UEAxQIbGl2ZV9hcGkxHDAaBgkqhkiG9w0BCQEWDXJlQHBheXBhbC5jb20CAQAwCQYFKw4DAhoFAKBdMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTEzMTIxMTIwMTEzN1owIwYJKoZIhvcNAQkEMRYEFDzj8aM+DX\/gnWZshm9ZhJkaVpsKMA0GCSqGSIb3DQEBAQUABIGANuxzET4H9X8SN97cDjB2MUj5+1dNvd2KYNXzzY2wZEPeDt0mh8xMA2Mz7urBvJUhtw6chObHLn7HRZda8lvmK9\/suSp4d+a7o7LDwvazlVuwR9e2dbhqEHz5PNwQZ8VVAARx3urnOGPzDYAYry+QZ8WzZBZ3h2jPASv\/tLfI\/u0=-----END PKCS7----- \" \/><br \/>\n<input type=\"image\" alt=\"PayPal - The safer, easier way to pay online!\" name=\"submit\" src=\"https:\/\/www.paypalobjects.com\/en_US\/i\/btn\/btn_donateCC_LG.gif\" \/><br \/>\n<img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/www.paypalobjects.com\/en_US\/i\/scr\/pixel.gif\" width=\"1\" height=\"1\" border=\"0\" \/><\/form>\n<p>Anyway, we&#8217;re back. Let the discussion resume! Thanks for reading and contributing! Arudou Debito<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s good to be back after nearly two weeks of being down after being hacked. Just a brief paragraph recap of what happened for those who are interested:<\/p>\n<p>On November 29, I tried to log in but found that my password wouldn&#8217;t work. I got in touch with my provider but they were slow in answering, and after being bounced between a couple of helpful and unhelpful techies, I got signed up for a cleaning-out service. This took some time, as Debito.org after nearly two decades of service has accumulated around 16 GBs of data. But once that was cleaned out, I still had trouble logging in. So I had to manually update themes and change passwords here and there, only to find out that the only password that would now work to avail me of this dashboard was the old one (I&#8217;ve now gotten in and changed it officially via the blog dashboard). So here we are, back, as of this morning, ready to resume discussion.<\/p>\n<p>Meanwhile, the question remains, who hacked Debito.org and why? Several techies wrote to me saying that Wordpress is particularly vulnerable to hacks and spiders that implant viruses with delayed infection times. I don&#8217;t doubt that, but hours after Debito.org was taken offline, I got this weird message (see full blog post):<\/p>\n<p>In response, we&#8217;ve signed up for a program offering constant security scans and cleaning, and although that increases maintenance costs, we&#8217;ve gotten donations (and lots of free advice, thanks for both!) from very kind people out there. Much obliged.<\/p>\n<p>If you like what you see and want to keep Debito.org up and hack-free, please consider contributing a little something by Paypal (click here).<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[],"class_list":["post-11998","post","type-post","status-publish","format-standard","hentry","category-debitoorg-website-updates"],"_links":{"self":[{"href":"https:\/\/www.debito.org\/index.php?rest_route=\/wp\/v2\/posts\/11998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.debito.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.debito.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.debito.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.debito.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11998"}],"version-history":[{"count":0,"href":"https:\/\/www.debito.org\/index.php?rest_route=\/wp\/v2\/posts\/11998\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.debito.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.debito.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.debito.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}