So, one of my client’s EE sites got hacked and they are on the horrible host Network Solutions. I’ve been following all the proper steps and we may even just move them onto mediatemple or another better host if client approves. But before any of that happens I have a question about upgrading.
Many files have been compromised and edited. I believe the hackers are scanning every directory for index.php or index.html and then proceeding to edit and add their spam links. There are also additional non ee files that have been uploaded. They are currently running 1.6.0 and I now have 1.6.3 to upgrade them too. My concern is whether or not I should upgrade the hacked files on their current host before doing anything else. I assume this will overwrite all EE files that have been compromised.
Also, from reading the KB on moving to another server I know it says to get the current version working on the new server before upgrading.
To recap:
- Do I upgrade on the hacked site first?
- I don’t have the 1.6.0 version anymore to install if we get a new host
I’ve backed up the DB, the template files and am in the process of backing up the entire site currently. My hope is we move to a new server by tomorrow but I’m not sure the proper procedure moving a current EE install that has been hacked into a new server. I am able to access the CP with no problems.
thanks!