By SciutoAlex
Hi there,
I got an alert that my droplet had been probing other sites for security holes. I emailed back and forth with the Digital Ocean support team, and they said “compromised droplets are backdoored and you will likely need to delete the droplet.”
Two questions:
How could this have happened? I thought I had secure passwords for my ssh access and for mysql. Were there other passwords I needed to be aware of?
How do I delete the droplet and make a new one? Is there anything I should be aware of concerning the compromised account? Could they have inserted files or something into my Wordpress blog database? Everything still looks normal.
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
There are many aspects to security. I’m a newbie myself, but I can tell you there is a lot more to securing a server than just making a good ssh and mysql password. Everything from closing any unnecessary open ports, to stopping unnecessary services, changing the default port of your ssh, there are whole books devoted to these issues also there are anti-virus scanners that you can run.
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.