This website uses WordPress as its core presentation software. Over the last few months, and especially the last week or so, www.randyphillips.net has been accessed by unknown people and rendered inoperable time and time again, apparently due to a basic vulnerability in my WordPress installation. I believe these people have been able to gain such easy access to my website code as a result of past lax security on the part of my web hosting company, which enabled them to plant a ‘back door’, allowing access without having to have any authentication credentials.
Most recently, the site was rendered inaccessible on Sunday, March 22, was restored by my web hosting company (IX Web Hosting) on Monday, attacked again later that afternoon, again restored by the hosting company, attacked again overnight Tuesday night/Wednesday morning, restored again (by me this time), and then was again targeted this morning, this time with references to a server in Latvia, registered to the Church of Scientology.
This is beyond my capabilities to remedy. IX Web Hosting has been mostly responsive in restoring the site, but appear to be unwilling or unable to reliably secure the site against intruders – they seem to be able to waltz in at will and do what they want with impunity. I’m writing this out of my frustration with WordPress for allowing such exploitation, and with IX Web Hosting, which has admitted security vulnerabilities in the recent past, the result of which is their inability to figure out how to protect my site.
I have completely deleted my current WordPress installation. I’m expecting a call from IX Web Hosting, during which I will ascertain their recommendation for one more try at a secure install. If further problems occur, I will be looking for a new hosting solution and expecting a refund for the remaining time on my hosting account.
In the meantime, the site will look quite different, and some features will be disabled for a while. Please bear with me as I traverse the morass.