ADP benefits: LifeMart phone and movie discounts preventative 100% covered UHCCPUHPD-AHFA-1000-80-KC-FL Full Cycle Notes TO DO: my super dispatch - push after they add fields to their CRMs quickbooks coronet window - make new plugin using chris' boilerplate, then add in all the files from the class - have the wp activate feature create db tables to hold invoices and invoice_line_items - use existing curl call to get data to insert into tables - download qb trial and load up qbw file to test pulling in data from xml generated in new plugin. DONE ditmco subscription site - put it on server after it's setup top of the list blockchainwater - make branch and push __________________________________________ vagrant passwd in ssh is vagrant nginx fix for vagrant box (kill process, start service) sudo fuser -k 80/tcp service nginx start WIFI Edison Spaces volt.0.Arbor gmail 6e^De}81DFR@1 google maps api key AIzaSyCXnFs8XkhJSVccZg6Z6e5-MsGs5lkDzBg 6e^DgdfgdfFR@1 altarbridal user/pass jthomas !mzp#hl5zPu3Ejk% ubuntu ffbkc superuser user = fullcycle pass = fullcycle SFTP Address: Port Number: 2222 user is romcorp-jthomas pass is C!W$PmGO$1JDSPI# romcorp for wp-login jthomas C!W$PmGO$1JDSPI# safe fleet new STP user SFTP Address: Port Number: 2222 sfnews-jthomas C!W$PmGO$1JDSPI# jthomas &XcSKc1H!B6d%3OQ wave account !NL!$unWTWKNlPxE safefleet jthomas !NL!$unWTWKNlPxE master slack account 6e^De}81DFR@1 jetbrains phpstorm 7g)b3zdFl]z)7&q 7g)b3zdFl]z)7&q You are added to the mysuperdispatch server ssh I think your password is FullCycle0! you have sudo rights wordpress mysuperdispatch. jthomas qu8dBU)KxQG9wXe0*!Sk@&Zn blockchainwater aws account ID 730549969381 username Joshthomos password 7g)b3zdFl45654 hubspot api account 6e^gTTTfe}4FR@1 HAPIkey = 778079f2-1250-49d4-980e-eea72507f00d app name = limelightmarketing_get_blog app id = 194095 client id = 3a8c60fa-0595-4be9-be66-3d8ec5924c3a client secret = 60f27e24-e43b-4be1-9938-c8fed43d31f8 6e^g9789fe}4FR@1 git permissions issue, showing too many files on git status git config core.filemode false ssh key for virtualbox password is pinkgirl !NL!$unWTWlP !Qh$5WV(mO7unKxE ffbkc google map api full cycle unrestricted google map api key AIzaSyBcon-jVc5QEl4iDsHR_vsqIi8zkmkRpbE github joshfullcycle 6e^DDDfe}4FR@1 leagueapps joshewolfsoft 6e^DDDfe}4F545454 jthomas CA8ffYb9S5Wnr5wC lastpass 6e^De}45eDFR@1 flywheel 6e^De}4FR@1 Riverwatch Beef SFTP: Username: riverwatch-jthomas Password: u6bjngeq1AyN Host: Port: 2222 (edited) jthomas sa(FIAbkc*ON*OEo gooogle auth for riverwatchbeef secret - 2VUVEK4H5Q7TFPJL recovery code - 44eda305f2613db1095e44fa armor 6e^De}4FR@1$%3 postgres local root pass is pinkgirl localhost mysql josh pinkgirl postman on ubuntu joshfullcycle 6e^De}4FR@1$%3 ubuntu mysql localhost update user set authentication_string=PASSWORD("pinkgirl") where User='root'; update user set authentication_string=PASSWORD("pinkgirl") where User='josh'; root has no password local mysql mysql -u teamply1 -p teamplay1db < "C:\teamplayone\teamplay1db.sql" mysql -u root -p teamplay1db < "C:\teamplayone\teamplay1db_data.sql" wpengine 6e^De}4FR@14534 dobies dev site to get into the folder... dobies dobiesdev wordpress user jthomas Z#MqhENZQdZc3NcG SFTP user for dobies staging SFTP Address: Port Number: 2222 dobiesstg-joshfullcycle Z#MqhENZQdZc3NcG localhost/ditmco ditmcoadmin IkAx0Ivh@iEV*yG!Eh Just got you added to the dev site for FFB. Your login is: joshthomas 1w2us04Fh90I ffb tunnel name = JoshFullCycle EU$Wn4RbRzqi%Mj5 bitbucket joshfullcycle is name 6e^De}81DFR@1 teamplayone 6e^De}81DFR1 teamplay db user: josh pass: pinkgirl db: teamplay1db host: Just copy it locally to work with it. email 6e^De}81DFR23%% virtualbox - done vagrant - done docker - done lastpass - done make me admin - done phpstorm - done pycharm - done vs code - done rubymine - done flywheel account mylastpass account - done slack account - done toggl account - done install vagrant mobstub image install docker image asana account - done install python and django - done to do work ___________________________ site fix links in header and all other pages. turn on mod_rewrite permalinks to get rid of nasty urls - done on contact us page - remove all social media icons except fb ( ) NOTE: make more social media pages later fixed all links that went nowhere (header of main page --- all "hire us" links now go to the contact us page --- all "learn more" links go to the services page contact us mail form just hangs, eventually throws 504 Gateway Time-out error front end for trigger systems set up new email account - done Printing: Business Hours: (Note that they lock the doors at 5pm on Thursday) Rules and Regulations: Office Door: After-Hours Access: Our office door code is: 0131 The external door code is: 30105# ServerAdmin DocumentRoot "C:/Users/josh/PhpstormProjects/teamplay1/TeamPlay1/public" ServerName Options FollowSymLinks MultiViews Order deny,allow Allow from all seondev WP jthomas fm1Z(8eq@YTcFME2 ___________________________ group3 solutions dit-mco knowledge base s3 cost is up see why it's not backing up anyone that logins has access --they don't get much --request further access monarch real self _____________________________ full ffbkc quote SSL Cert - 3 hours (remove certbot without invalidating ssl certs requires some backing up of main files and checking into server versioning issues) eBook promo panels within blog posts - 12 (after looking into just adding hyperlinks, this seems like a complicated task since i'm having to create a custom slug, something that drafttail (wagtail's wysiwyg doesn't support) eBook promo panels randomizing - 2 (after making the eBook slugs, randomizing them seems easy) Hyperlinks open in new tab - 4 (could have to rely on jquery link checking to see if they want ALL external links to open in new windows, and all internal links to open in the same window) Buttons within rich-text editor - 6 (after making slugs, this might not take that long, but any wagtail modification is going to be a fight) Google Translate nav & symbol issue - 8 (jquery iframe issues and CORS issues, maybe completely replace their link with onsite translation) Exclude Form Success pages from on-site search results - 4 (there is decent documentation on how to add this feature to wagtail) Forms Enhancement - add text fields for disclosures - 4 (again, modifying drafttail, the wysiwyg editor, might not be that bad after the above updates) Setup use my location - 5 (works on refresh but i'm not sure how it's pulling the location data, so there's some digging and researching to be done there) hack notes hunmidwest whm root Rkc$DU1O3xwn lots of GET /wpad.dat 404 errors from then it probes.... hey tam, on the hacking, it looks like whoever was in there might have wiped their logs. the people that run the site said they changed all their passwords, and i've checked everything there is to check, i even had brad see if i was missing anything. something they should know though is that lightedge (the hosting space) isn't responding to some of the security updateinfo yum commands, their hosting company should look into that... "root@huntmidwest [/var/log/apache2]# yum updateinfo list security all Loaded plugins: fastestmirror, priorities, security, universal-hooks [Errno 14] PYCURL ERROR 7 - "couldn't connect to host" Trying other mirror. [Errno 14] PYCURL ERROR 7 - "couldn't connect to host" Trying other mirror. Error: failure: repodata/c50609926f2a2d57198b8ccb2ad32032795a8257a97b806015673d1b3dedcd04-updateinfo.xml.bz2 from epel: [Errno 256] No more mirrors to try." their os (CENTOS 6.9) version is getting old, so i'm not sure if that's related to this issue. after seeing the notes in their emails about how they don't have any backups ("We are working on getting backups on a regular basis. They were running before but we need to reduce the size of what is being backed up as the backups usually are in the 8-10 GB range. Thus they timeout and never finish. " - Jacob McDaniel) and ("Eric, according to LightEdge there aren’t any backup jobs regarding your server on their backend. I’m not sure if this aligns with your expectations but that means we wouldn’t have had a backup to resort to had Jacob and team not had their own backups." - Justin Johnson), and looking at their logs and whm and cpanel settings, they never had anything successfully backup online, so when chris said "restore whatever we have", as far as i can tell, we have nothing, i talked to chris around noon and he said we don't have any offline backups of their data. if it helps them at all, these are all the system commands run since the site was original reported as down yesterday at 11am. they all seem super standard and are related to the guys doing support in the email chain and me trying to see what happened. all system commands for several months before that are empty, so either they weren't hacked that way, or the hacker wiped the history. it's also possible that the downtime was just related to the corrupted mysql tables reported in the emails and that they weren't hacked, they just had corrupted data that caused the downtime. the site was brought back up before i looked at it, so i'm not sure if they lost files, or just had data corruption. 917 2019-04-02 13:16:36 php -version 918 2019-04-02 13:17:04 curl -version 919 2019-04-02 13:17:14 curl --help 920 2019-04-02 13:17:20 curl --version 921 2019-04-02 13:53:54 du | sort -n -r 922 2019-04-02 13:54:52 ls 923 2019-04-02 13:54:55 cd .. 924 2019-04-02 13:54:55 ls 925 2019-04-02 13:54:57 cd .. 926 2019-04-02 13:54:58 ls 927 2019-04-02 13:55:08 du | sort -n -r 928 2019-04-02 13:57:42 myisamchk -s /var/lib/mysql/*/*.MYI 929 2019-04-02 13:58:55 myisamchk -r /var/lib/mysql/dbname/wp_paaol654i7_wfHits.MYI 930 2019-04-02 14:00:47 myisamchk -r /var/lib/mysql/huntmidw_wp_stage/wp_paaol654i7_wfHits.MYI 931 2019-04-02 14:01:52 du | sort -n -r 932 2019-04-02 14:02:39 ncdu 933 2019-04-02 14:03:09 ls 934 2019-04-02 14:03:13 cd .. 935 2019-04-02 14:03:15 ls 936 2019-04-02 14:03:19 ncdu 937 2019-04-02 14:13:00 yum update 938 2019-04-02 14:13:36 curl --version 939 2019-04-02 14:22:58 sudo nano /etc/yum.repos.d/EA4.repo 940 2019-04-02 14:24:06 uname -a 941 2019-04-02 14:24:50 sudo nano /etc/yum.repos.d/EA4.repo 942 2019-04-02 14:26:05 yum update 943 2019-04-02 14:26:22 yum update --skip-broken 944 2019-04-02 14:29:14 sudo nano /etc/yum.repos.d/EA4.repo 945 2019-04-02 14:29:31 yum update --skip-broken 946 2019-04-02 14:30:06 curl --version 947 2019-04-02 14:31:17 php -r '$info = curl_version();echo $info["version"]."\n";' 948 2019-04-02 14:34:40 top 949 2019-04-02 15:07:06 ifconfig 950 2019-04-02 15:07:56 cat /etc/resolv.conf 951 2019-04-02 15:39:49 sudo nano /etc/resolv.conf 952 2019-04-02 15:41:46 cat /etc/resolv.conf 953 2019-04-02 15:42:27 host 954 2019-04-02 15:42:39 dig 955 2019-04-02 16:19:13 hostname 956 2019-04-02 16:19:34 cat /etc/resolv.conf 957 2019-04-02 16:19:38 sudo nano /etc/resolv.conf 958 2019-04-02 16:20:28 dig 959 2019-04-02 17:12:47 passwd 960 2019-04-02 17:13:13 exit 961 2019-04-02 17:21:12 less /etc/passwd 962 2019-04-03 10:23:40 yum updateinfo list security all 963 2019-04-03 10:25:09 yum update info list all 964 2019-04-03 10:25:31 yum updateinfo list all 965 2019-04-03 10:30:29 cd /var/log 966 2019-04-03 10:30:31 ls 967 2019-04-03 10:30:35 cd apache2 968 2019-04-03 10:30:37 ls 969 2019-04-03 10:30:53 head access_log 970 2019-04-03 10:31:02 tail access_log 971 2019-04-03 10:32:07 cat access_log | grep "/<200/>" |head 972 2019-04-03 10:32:20 cat access_log | grep "200" |head 973 2019-04-03 10:32:28 cat access_log | grep "404" |head 974 2019-04-03 10:32:38 cat access_log | grep "404" 975 2019-04-03 10:34:08 cat access_log | grep "404" | grep "02/Apr" 976 2019-04-03 10:34:14 cat access_log | grep "404" | grep "02/Apr" | more 977 2019-04-03 10:48:18 last 978 2019-04-03 10:48:43 date 979 2019-04-03 10:49:01 last 980 2019-04-03 10:51:59 find / -name "..." 981 2019-04-03 10:53:48 mkdir "..." 982 2019-04-03 10:53:55 ls -al 983 2019-04-03 10:54:14 find ./ -name "..." 984 2019-04-03 10:54:21 ls 985 2019-04-03 10:55:30 cat access_log | grep "404" | grep "02/Apr" | more 986 2019-04-03 11:02:58 tail -n 100 ~/.bash_history | more 987 2019-04-03 11:04:14 host 988 2019-04-03 11:04:25 cat /etc/resolv.conf 989 2019-04-03 11:06:16 history 990 2019-04-03 11:08:19 cat /etc/resolv.conf 991 2019-04-03 11:11:32 netstat | more 992 2019-04-03 11:13:17 netstat -an | grep :9000 998 2019-04-03 11:34:07 cd /var/spool/cron && grep . * 999 2019-04-03 11:45:58 history 1000 2019-04-03 11:46:08 tail -n 100 ~/.bash_history | more