<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>hacked — LowEndSpirit</title>
        <link>https://staging.lowendspirit.com/index.php?p=/</link>
        <pubDate>Thu, 09 Apr 2026 17:14:35 +0000</pubDate>
        <language>en</language>
            <description>hacked — LowEndSpirit</description>
    <atom:link href="https://staging.lowendspirit.com/index.php?p=/discussions/tagged/hacked/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Security Breached. what do i need to do?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5948/security-breached-what-do-i-need-to-do</link>
        <pubDate>Mon, 22 May 2023 10:09:02 +0000</pubDate>
        <category>Help</category>
        <dc:creator>milkboy</dc:creator>
        <guid isPermaLink="false">5948@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>So one of my Hosting DA panel got hack. <br />
My 30++ years old "i-got-hacked" cherry has been popped.  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/blush.png" title=":3" alt=":3" height="18" /> <br />
It is only sending Spam emails on a few accounts.<br />
All of the password are &gt;20-key generated.</p>

<p>As this is my first, I'm unsure nature of the breach and what i need to do.<br />
I have check a few sites (i.e haveibeenpwn) for breaches, but found none</p>

<p>As a precaution i have:</p>

<ul>
<li>Suspended the DA user account and server for a day. (i control both user and reseller account)</li>
<li>Change all user password in the domain.</li>
<li>Change SSL (after i unsuspend later)</li>
<li>Notify the provider of the breach</li>
</ul>

<p>So do i need to do anything else?<br />
How do i know if its a simple password breach or much worse?</p>

<p>EDIT:<br />
changed the title to reflect nature of the breach<br />
Found the offending pc. office user brought their laptop to a 3rd party services during the weekend.<br />
so far seems to be a spambot, scanned all the other check the entire office pc seems good.<br />
wasted entire day  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/cry.png" title=":'(" alt=":'(" height="18" /></p>
]]>
        </description>
    </item>
   </channel>
</rss>
