Yes, it's via WP - i suspect Gravity Forms.
Looking at logs there were request to phyMyadmin.
So many issues that it caused router to be rebooted every 10-15 minutes.
I am going to look close at the logs, but that might still not be indication of the extent of the hack.
Administrator accounts were created in WP, so I am assuming that if they can inject into mySQL further access to Sentora could have been mitigated.
Let me know if I am wrong.
Thanks to all that work hard to keep sentora going.
Looking at logs there were request to phyMyadmin.
So many issues that it caused router to be rebooted every 10-15 minutes.
I am going to look close at the logs, but that might still not be indication of the extent of the hack.
Administrator accounts were created in WP, so I am assuming that if they can inject into mySQL further access to Sentora could have been mitigated.
Let me know if I am wrong.
Thanks to all that work hard to keep sentora going.