visitor stats

Hongkiat.com defaced and hacked

defaced

Cely woke me from my dream telling me hongkiat.com was hacked and defaced. I totally did not see this coming, but it is entirely my fault that I did not upgrade to Wordpress 2.2.1 as soon as possible.

The Damages

The defaced messages sounds quite personal, it seems like the hacker has been following my entries. Besides defacement, the database was gone too but I managed to recover from a backup copy. Entries for the pass 2-3 days were gone.

I thank those who took the initiatives to inform me through e-mails, IMs, and text messages. It should be fine now. It hurts but lesson learned.

Posted by hongkiat in Blogosphere, at 06.26.07

Related Contents

Sponsors

Comments

  1. HongKiat.com defaced | The Danesh Project

    June 26th, 2007 at 5:24 pm

    [...] HongKiat.com was defaced yesterday. He lost his database and 2-3 days of posts. [...]

    comment

  2. Ahmad Uzair

    June 26th, 2007 at 5:37 pm

    What a pity.Thank God you had a backup.After been hacked by Jamaycka, now I frequently make a backup.

    comment

  3. earl-ku

    June 26th, 2007 at 6:00 pm

    macibai … never mentioned me for giving u a call at 4am? kaninia …

    comment

  4. melvin,foong

    June 26th, 2007 at 6:01 pm

    If you want a copy of ur past 2 day’s archives, let me know. Cheers.

    And next time, don’t message me with “Don’t tell me it is not you” I rather you message me with Hello, or Hi, or morning =)

    comment

  5. Nicholas

    June 26th, 2007 at 6:27 pm

    Oh, this site is back online.

    comment

  6. Kimkins

    June 26th, 2007 at 6:39 pm

    Yeah I saw that yesterday as I was telling one of my friend about your post regarding 400 Malaysian blogs were hacked.

    And when I came here…OMG you became one of the victim.

    But anyway good to see you back! You will be able to recover your previous posts (if you want) using google cache. Just search for the post titles and if they were indexed by google, it will appear and just click on Cached and get the cached version. Then later you can repost them in your wp.

    wish you all the best

    comment

  7. CincauHangus

    June 26th, 2007 at 7:02 pm

    i tot u were doin another april fool joke. :P

    anywayyy.. who ask u not to upgradeee… :P

    come go out have a beer. i know u sad..

    comment

  8. David

    June 26th, 2007 at 8:04 pm

    I’m signed up for your rss feeds and i’ll click the link from time to time, very informative stuff you have here. I was quite upset when i saw that your site was defaced.

    I”ve had similar experiences. A hacker once took down my design portfolio and disrupted my business. I havent been able to get back on track fully since.

    I’ve been doing alot of reading from your site and it does help alot. Keep up the good work.

    comment

  9. kucau

    June 26th, 2007 at 8:30 pm

    i dont think the defacer is kinda leet. they are actually a bunch of script kiddies whos use ready made script. they are the real noob

    comment

  10. hongkiat

    June 26th, 2007 at 8:51 pm

    Ahmad: I’m glad my host did backups regulary :-)

    Earl: I din not realized your call 4.00 in the morning. Phone batt run dry this morning, but thank you la, especially your post on that. You sound happy thou.

    Melvin: Knowing what you are capable of, you’ll probably think the same. At least I did not jump on conclusion. ;p

    Nicholas, Kimkins: Previous 2 post were fine; I have backups at home.

    Cincau: April Fool over la, I wont do such thing especially when it potentially hurts my online revenue. Siao! I’ll still take your killkenny.

    David: I learned the important of constant backup now, haha.

    Kucau: The defacer definitely thinks it’s cool. Btw, I’ve got the SQL injection exploits, hate to believe such things are so easy available online.

    comment

  11. earl-ku

    June 26th, 2007 at 9:01 pm

    wahahahahahahah i am i am i am … told u i hate tech blogger rite … wahahahha

    but hey like what lilian said, been there, so i know how frustrating is it … haha

    Cincau, eh got killkenny for me or not? mahai …

    comment

  12. Zaizen

    June 26th, 2007 at 9:06 pm

    I realized your blog has been hacked today 8 am morning..i try to chat wif u via gmail but no have answer..now..looks hongkiat.com lback to normal..you’re so fast man solve this problem..

    comment

  13. hongkiat

    June 26th, 2007 at 9:29 pm

    belle: you’re next! Hahah.

    earl: A moment there I was panicked too when I realized DB was gone, there goes half year of blogging. been there, learned and learned well. :-) Backup DB and you sleep soundly.

    Zaizen: Sorry buddy, wasnt able to respond to you as I was buzy ’saving’ the blog from the disaster. My site monitor report says its been down since 4.00am yesterday.

    comment

  14. Wing Loon

    June 26th, 2007 at 10:12 pm

    Damn…hackers are fast if you really don’t get your wordpress up2date, :(

    comment

  15. Michael

    June 27th, 2007 at 1:14 am

    alamak.. another case here ar? .. eh.. melvin fong? are you the melvin i know ar?.. @@?

    hmm.. the hacker sound malaysian la @@

    comment

  16. Adam

    June 27th, 2007 at 5:38 am

    Glad to see that you are back up again. I blogged about you yesterday: http://www.adamok.net/2007/06/hongkiats-blog-hacked.html

    comment

  17. Don’t get hacked! » Sha Money Maker dot com

    June 27th, 2007 at 8:05 am

    [...] not upgrade to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their [...]

    comment

  18. CincauHangus

    June 27th, 2007 at 9:38 am

    earl: caaan… i order for you.. you pay lar..

    u two, tonite mau?

    comment

  19. Prevent Wordpress hacking » Sha dot Com Anak Melayu boleh blog! Mana gadis manis melayu aku?

    June 27th, 2007 at 9:47 am

    [...] not upgrade to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their [...]

    comment

  20. Jason

    June 27th, 2007 at 10:30 am

    HongKiat.com is back!! Yeah…

    comment

  21. Upgrade your wordpress, don’t get hacked! - jusupov.com

    June 27th, 2007 at 11:15 am

    [...] Hong Kiat was hacked, he blogs about it on his blog here. His blog was hacked because he didn’t upgrade his wordpress to a newer version. Because of [...]

    comment

  22. mrBadak

    June 29th, 2007 at 9:14 am

    aisey… looks like someone got jealous over you being a problogger? ignore those kids!

    comment

  23. syahid ali

    June 29th, 2007 at 9:22 pm

    based on the writings on the defaced page, i think the script kiddies are malaysian. feel sorry for your site though.

    comment

  24. WordPress 2.2.1 Upgrade | romantika.name

    June 30th, 2007 at 1:28 pm

    [...] I promised myself to steal some time to upgrade during this weekend. A very recent attack was on HongKiat.com, a full time blogger in [...]

    comment

  25. belle

    July 1st, 2007 at 3:27 pm

    = = ” i knw who to find if i kena..u babi

    comment

  26. melvin,foong

    July 3rd, 2007 at 5:19 am

    HAHA, knowing what I am capable of, you should give me a lunch treat. Else I hax0r you. HAHHAHAHAh!!!!1one

    comment

  27. Fenton

    July 3rd, 2007 at 12:23 pm

    People sometimes are really notorious. Anyway, great to have you back.

    comment

  28. tihopilik

    July 9th, 2007 at 12:38 am

    Hello

    I can’t be bothered with anything these days, but shrug. I just don’t have anything to say recently.

    Bye

    comment

  29. New Mozilla Firefox 2.0.0.5

    July 19th, 2007 at 1:04 am

    [...] If you are using any version lower than that, you really should update yourself to that. I have bad experience of delaying an application update, and that really cost me something, so be quick or be ready to [...]

    comment

  30. ananth77

    July 24th, 2007 at 4:16 am

    Glad that you are back online … so shall i wish welcome back .. or has it been too late to do so? :p

    comment

  31. hongkiat

    July 24th, 2007 at 5:38 pm

    Ananth77: Haha, it makes me wonder how come you are getting this news so late, probably you came from google links or probably reach this page from a link back. Hongkiat.com is back online 1 month ago. Thanks for the concern though :-)

    comment

  32. Prevent Wordpress hacking | Anak Melayu Boleh Blog

    October 8th, 2007 at 9:04 pm

    [...] not upgrade to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their [...]

    comment

  33. Wordpress Upgrades/Updates Benefits and Tips

    February 7th, 2008 at 5:58 pm

    [...] being hacked is going up recently. Hong Kiat learned his lesson for not upgrading frequently and found his blog hacked in June 26th, 2007. This is just one of the few accomplishments by Wordpress blog [...]

    comment

  34. Prevent Wordpress Hacking | Anak Melayu Boleh Blog

    March 4th, 2008 at 1:41 pm

    [...] has been bloggers on v2.2 like Hongkiat and coolkevman, who got [...]

    comment

  35. Don’t Get Hacked | Sha Money Maker

    March 13th, 2008 at 11:38 pm

    [...] not upgrade to Wordpress v2.2.1, please do so immediately. There has been bloggers on v2.2 like Hongkiat and coolkevman, who got hacked. The hackers search for blogs with v2.2 keyword string and did their [...]

    comment

  36. Happy April Fool Day From Hongkiat.com

    April 1st, 2008 at 12:32 am

    [...] those who visit hongkiat.com with browsers, Happy April Fool Day. So you think I got hacked again? [...]

    comment


Leave a reply