The website ransomware attack should be a general attack. Because it is a website under development, only two people are logging in and checking the log. The attacker only did it a few times and then came in. Then he deleted the database and replaced it with the ransom information. .
The hacker's code should have exploited the PHP vulnerability, and must have obtained the database information of datebase.php, and because the database did not restrict the remote IP, it was hacked.
The problem lies in datebase.php. If it is encrypted, hackers are probably too lazy to decrypt it, so I ask the experts who know how to do it.
I feel that if PHP does not solve this mechanism problem, it will eventually be abandoned! !