Long story short, an angry individual (after a good deal of back and forth via email) is claiming he's determined to destroy our WordPress/Xenforo site and will pay hackers to do so.
Real smart, warn your enemy you're going to attack, I know. But, regardless, some of the language he's using gives me an uneasy feeling that this might be more than a bluff.
If today you received what you assumed was a legit threat that someone was determined to destroy your site, what would you do?
What I've done (and it feels extremely minimal):
a.) A full site backup via cPanel, left on server and copied to local hard drive and cloud
b.) Checked Cloudflare firewall rules are in place
c.) Confirmed server software and Wordpress/Xenforo fully updated from top-to-bottom
Other than that, I'm just kind of watching Cloudflare stats to see any unusual activity.
I'm sitting here thinking how powerless I feel. Do I just rely on Cloudflare to catch it, or what?
I only have four WAF rules in place, leaving me one available. Any ideas for that?
				
			Real smart, warn your enemy you're going to attack, I know. But, regardless, some of the language he's using gives me an uneasy feeling that this might be more than a bluff.
If today you received what you assumed was a legit threat that someone was determined to destroy your site, what would you do?
What I've done (and it feels extremely minimal):
a.) A full site backup via cPanel, left on server and copied to local hard drive and cloud
b.) Checked Cloudflare firewall rules are in place
c.) Confirmed server software and Wordpress/Xenforo fully updated from top-to-bottom
Other than that, I'm just kind of watching Cloudflare stats to see any unusual activity.
I'm sitting here thinking how powerless I feel. Do I just rely on Cloudflare to catch it, or what?
I only have four WAF rules in place, leaving me one available. Any ideas for that?
 
 
		 
					
				 
						
					 
 
		 
 
		
 
 
		 
 
		 
 
		
 
 
		 
 
		 And the worst "breach" I've ever had were some script kiddiez who got in and defaced phpBB back in the mid 2000s.  (That software was a steaming turd, full of security holes, so in a way I could say I deserved it.
  And the worst "breach" I've ever had were some script kiddiez who got in and defaced phpBB back in the mid 2000s.  (That software was a steaming turd, full of security holes, so in a way I could say I deserved it.   )
)