Koozali.org: home of the SME Server

Hacked website, restore files using AFFA

Offline ber

  • ****
  • 239
  • +0/-0
Hacked website, restore files using AFFA
« on: April 16, 2017, 12:05:57 AM »
Hi one of my domains was hacked last week and I would like to use my Affa backup to restore thefiles.
I have a SME 9 backed up by another SME server running SME 9, with Affa 3.

Ive used Affa in the past to upgrade to new hardware pretty much using the default settings.
Ive tried to look at information regarding restoring just ibays or restoring to a previous archive. Ive hit a snag regarding defining with "archive" I want to restore back to.
I am confident that I have archives of the server available before the website was hacked.
Here is a display of the

[root@affa ~]# affa --list-archives backup-smeserver


+----------------------------------------------------------------------------------------------------------------+
| Job: backup-smeserver                                                                                          |
| Description: Backup of 192.168.0.254 server                                                                    |
| Directory: /var/affa/backup-smeserver/                                                                         |
| Hostname: 192.168.0.254                                                                                        |
| Email: john@ber.net.nz                                                                                         |
+----------------------------------------------------------------------------------------------------------------+
| Run   | Completion date                           |    buTime | ddTime | ddYld | Files |  Size |  Sent | Recvd |
+----------------------------------------------------------------------------------------------------------------+
| M 0  | Sun 2017-02-26 22:30                       |     0m34s |      - |     - |  433k |  115G |  123k |   16M |
+----------------------------------------------------------------------------------------------------------------+
| W 3  | Sun 2017-03-12 22:30                       |     0m44s |      - |     - |  470k |  143G |  197k |   20M |
| W 2  | Sun 2017-03-19 22:30                       |     0m48s |      - |     - |  491k |  144G |  156k |   45M |
| W 1  | Sun 2017-03-26 22:30                       |     0m34s |      - |     - |  410k |  142G |  121k |   16M |
| W 0  | Sun 2017-04-02 22:30                       |     0m35s |      - |     - |  408k |  168G |  190k |   23M |
+----------------------------------------------------------------------------------------------------------------+
| D 6  | Sun 2017-04-09 22:30                       |     0m41s |      - |     - |  423k |  189G |  128k |   16M |
| D 5  | Mon 2017-04-10 22:30                       |     0m40s |      - |     - |  427k |  189G |  201k |   18M |
| D 4  | Tue 2017-04-11 22:30                       |     0m39s |      - |     - |  428k |  189G |  129k |   17M |
| D 3  | Wed 2017-04-12 22:30                       |     0m43s |      - |     - |  433k |  198G |  165k |   22M |
| D 2  | Thu 2017-04-13 22:30                       |     0m45s |      - |     - |  434k |  198G |  197k |   17M |
| D 1  | Fri 2017-04-14 22:30                       |     0m41s |      - |     - |  435k |  198G |  170k |   17M |
| D 0  | Sat 2017-04-15 22:30                       |     0m44s |      - |     - |  436k |  198G |  125k |   16M |
+----------------------------------------------------------------------------------------------------------------+
| S 0  | Sun 2017-04-16 08:30                       |     0m44s |      - |     - |  436k |  198G |  132k |   18M |
+------------------------------------------------------------------------------------------------------------
What I'm uncertain about is what is the file name of the archive for the backup completed on 26th Feb 2017.
I wish to ruin a full restore using the rise feature so that the whole system is restored to that date. I will then extract the website files, check the database and sort out some other things.

The command I wish to use for the rise feature is:
affa --rise [--all] backup-smeserver [ARCHIVE-??]

Thanks in advance.


Offline JohnG

  • ***
  • 88
  • +0/-0
Re: Hacked website, restore files using AFFA
« Reply #1 on: April 16, 2017, 07:41:06 PM »
The name of your Feb 26th run should be "monthly.0" Check the /var/affa/backup-smeserver directory and it should be there, along with the weekly, daily and scheduled archives.