Serverside .MBZ Restoration

Serverside .MBZ Restoration

by Steve Sawowski -
Number of replies: 8

Hello,

Wondering if anyone knows how to or where I can find documentation on how to go into the server where a Moodle LMS is set up and save the .mbz courses from that side.


Recently had a hacker hack my site and now I cannot access anything except the server files.

Greatly appreciate any guidance in this.


Best,
Steve

Average of ratings: -
In reply to Steve Sawowski

Re: Serverside .MBZ Restoration

by Ken Task -
Picture of Particularly helpful Moodlers

Don't think there is any official docs, but check your PM on this system for a link.

'SoS', Ken

In reply to Steve Sawowski

Re: Serverside .MBZ Restoration

by Ken Task -
Picture of Particularly helpful Moodlers

Follow up ... in the unfortunate event of a hacked site, it is a good practice to totally wipe out what's there and rebuild fresh operating system with supported versions of what makes Moodle go, then rebuild the moodle site as well.   This time keeping in mind security first.

Hacked site could leave continued backdoors etc. and restoring onto same machine could mean a revisit in short order.

So finding mbz files in moodledata/filedir/ is but the first step ... download to local machine ... all of those ... don't just restore to same site.

my 2 cents!

'SoS', Ken

In reply to Ken Task

Re: Serverside .MBZ Restoration

by Steve Sawowski -
Hi Ken,
Greatly appreciate the help.
Sorry for the question, but does PM mean Project Management?

We've built pretty extensive Japanese and Korean courses and we don't want to lose all of the data we spent 1 1/2 years building, so I was thinking I might go through every single file to see if there are files that have strange names like 6hokms43.php and just remove every file, or if there's a better way.

Never thought I'd get hacked because we haven't really had much exposure as a site, just the few students in our school.

So, basically, just go to: moodledata/filedir/ and see what I can fid there, right?

Thanks again,
Steve
In reply to Steve Sawowski

Re: Serverside .MBZ Restoration

by Ken Task -
Picture of Particularly helpful Moodlers

PM means Private Messages ... on this forum.  Look for the 'Bell' icon top right corner.

I sent you a URL to an article you need to read ... because ...

The only file you will see in moodledata/filedir/ that is humanly recognizable is the 'warning.txt' file ... do read it.  All of what you see in moodledata/filedir/ is really created and controlled by code talking to your DB for your moodle ... mdl_files table.

This query will get you a peak ...

select contenthash,filename from mdl_files where filename like '%.mbz';

The contenthash value is really the location and filename in moodledata/filedir/ - the filename column in that table is the humanly recognizable filename - the one you see in moodle if you could get to moodle.   In your case, you can't!

And ... Internet has never really been a 'friendly place' thus anything serving anything is 'game'.

'SoS', Ken

Average of ratings: Useful (2)
In reply to Ken Task

Re: Serverside .MBZ Restoration

by Steve Sawowski -
Thanks so much Ken!
I'll read it and try my best.

Looks like this situation might have been a part of a larger hacker attack on Godaddy that has been happening from September to November 17th. 1.2 million users have been affected and anything within the shared hosting got infected : /

Asked them for some help and they said nobody knows anything about Moodle there.

I really appreciate your help and will get on this the day after Thanksgiving, which is tomorrow.

Best,
Steve
In reply to Steve Sawowski

Re: Serverside .MBZ Restoration

by Ken Task -
Picture of Particularly helpful Moodlers

From what I read of GD's issues ... managed (them) WordPress sites - attacker acquired credentials.   Yep ... GD not known for moodle hosting ... but we do have a resident GD/Moodle user in these forums ... how about it Rick?  Did you have any issues with your GD hosted Moodle? (Rick, however, doesn't use 'shared hosting' on GD so maybe he didn't have any un-pleasant experience.

Best of luck!

'SoS', Ken


In reply to Ken Task

Re: Serverside .MBZ Restoration

by Steve Sawowski -
Hi Ken,

I think the link that you sent me somehow disappeared from my PM.

Could you please send it again?

Thanks,
Steve