AnnDroyd Posted November 30, 2007 Posted November 30, 2007 (edited) Anyone suffered any ill-affects of Fasthost's recently security scare? I tried to log on to an FTP site this morning to find my password being rejected. Apparently they have reset a lot of their customers passwords because someone has recently hacked into their system and obtained customer account details. Edited May 2, 2008 by AnnDroyd
tech_guy Posted November 30, 2007 Posted November 30, 2007 Yeah, I had the email from them this morning - apparently some of the accounts have been compromised and whoever did the hack has been ftping into sites and changing stuff.... "Dear Customer, We wrote to you on 18th October 2007 advising that you change all of the passwords on your Fasthosts accounts (including control panel, FTP, database and email), in order to prevent any unauthorised account access following the network intrusion we previously communicated. Whilst we have found the vulnerability that caused this issue, and have instigated a system wide security audit to improve and enhance our current security, we also advised you to change your control panel, FTP and email passwords as a precaution. Today we have been made aware that a small number of our customers who did not change their passwords have experienced a compromise to their FTP space. As a result, in order to totally protect all of our customers, we have today implemented an automatic password change for every control panel, FTP or SQL password that was not previously reset. In 10 days time we will also reset all unchanged email passwords. To ensure complete security when communicating your new passwords to you, we will first take the stringent measure of sending the new control panel password via Royal Mail. Once you have received your new control panel password, you will then be able to go into your control panel and immediately change your FTP, SQL and email passwords. Please note that the email password reminder system will not work from the time you receive this mail, to the time you log in with your new control panel password. If you have already changed your control panel password, you will still need to go into your control panel and change ALL the FTP, SQL and email passwords associated with your accounts that haven’t already been changed. UNDER NO CIRCUMSTANCES WHATSOEVER SHOULD YOU TRY TO REUSE ANY OF YOUR OLD PASSWORDS We apologise for the inconvenience that this will cause you during this period, but trust you understand that our primary concern is for our customers and for the security of their websites and data. Unfortunately, an automatic password change is the only way of ensuring that all of our customers are totally secure. If you have any questions relating to this, please contact our Customer Support team on 0870 888 3600 or [email protected], and they will be more than happy to help you. Thank you once again for your understanding and cooperation in this matter.Yours sincerely, The Fasthosts Team"
pete Posted November 30, 2007 Posted November 30, 2007 What's even more annoying is that it took them about 8 days after the Register broke the story* (and the comments section was enlightening about their questionable security practices) to email me about the breach. So yeah, between that and the continued poor performance and support, we don't use them anymore. * http://www.theregister.co.uk/2007/10/18/fasthost_police_hack_investigation/ http://www.theregister.co.uk/2007/10/19/fasthosts_banking_hack/
ninjabeaver Posted November 30, 2007 Posted November 30, 2007 Same here. I've moved all my accounts over to 123reg. I hope they are better. I was even more annoyed at how they automatically took £6 odd for renewal fees 30 days before expiration of the domain, without even telling me. They told me they had sent numerous emails about it, none of which I got, but the invoice for £6 came through fine. Never going to use them again. From what I have also read on the net, many people are doing the same.
intrigue Posted November 30, 2007 Posted November 30, 2007 well speaking of website security when i worked at longslade community college the embc or someone similar hosted their websites and the username and password for FTP was something like "siteID" "tuesday" then you got logged into the folder /siteID/ out of interest i went up a folder and could happily download/remove the websites of over 150 schools (i obviously didnt) but was shocked about the lack of permission based security. Not surprising though as we all know these consortiums are ran by cowboys. matt
mac_shinobi Posted November 30, 2007 Posted November 30, 2007 Just out of pure curiousty who would you recomend over fasthosts ?
intrigue Posted November 30, 2007 Posted November 30, 2007 dreamhosts have been good for me but not for everyone. I have also used servage.net in the past and they were ok although the databases seem to run a bit slow at times. Thanks Matt
Rozzer Posted November 30, 2007 Posted November 30, 2007 I have been with fasthost for 1 year and i found them to be pretty poor. I had a billing issue where i had a new debit card issued and did not think to update there billing records. So the pay did not go through so they wanted to charge me 30 pounds for it. So i just closed my account and went with dreamhosts which are cheap and cheerful Ross
tech_guy Posted November 30, 2007 Posted November 30, 2007 I'm with FastHosts and touch wood have not had any issues (apart from their security breach the numbnuts). Have you heard the horror stories about 1and1?
Dos_Box Posted November 30, 2007 Posted November 30, 2007 EduGeek is hosted on a Fasthosts server. When the security breach came t light I spent an awful evening alerting all the site admins and changing passwords ad-nausium. Needless to say the service we have received in the past year has really not been up to scratch and better hosting will be sought next year after our contract is up (I've paid for the year). Hopefully a nice company will allow us to live on their server farm if we purchase our own server.
pete Posted November 30, 2007 Posted November 30, 2007 @ Intrigue Last time I bothered to check, that hadn't changed. Trusting county to care about securing your data (export of pupil data via ftp, anyone?) is asking for trouble. We're currently using http://www.positive-internet.com and in the 28 days trial period still. So far they haven't sucked, and the guys we quizzed on the phone before committing to a trial knew what he was talking about _and_ knew about Moodle. It's too early to tell whether we'll continue with them as "better than fasthosts" isn't really hard to achieve. For personal websites, I've used http://www.purplecloud.net for nearly 4 years and they're brilliant but (last time I checked with them) they don't reccommend themselves for business websites. @Webman Surely "...poor service, we reccommend $foo instead?"
Butuz Posted November 30, 2007 Posted November 30, 2007 Fasthosts are RRRRRRRRubbish with a capital R. Used to have a reseller account years ago with them, but had to drop them after they repeatedly emailed the account admin password to me in clear text despite me never even requesting it. Useless. And if they have had further security breaches since then, it doesnt suprise me. I think someone need to pop in and actualy explain to them what security means? Butuz
ChrisP Posted November 30, 2007 Posted November 30, 2007 i've now noticed somthing that i'm not too hapy with about fasthosts i have used them for years. and i use catchall mail forwarding so i can use throwaway email addresses eg: [email protected], [email protected] 12345@@website.com etc. However i'm now getting loads of junk mail sent to different addresses I used ONLY ONCE from years ago. So it poses the interesting question of how those addresses got out. Either Fasthosts has been hacked before or more likley, someone within Fasthosts is selling email addresses.
tech_guy Posted November 30, 2007 Posted November 30, 2007 @ChrisP That's an interesting observation as I have FastHosts email and I get spam in accounts where I have never ever used or given out the email address.
GrumbleDook Posted November 30, 2007 Posted November 30, 2007 well speaking of website security when i worked at longslade community college the embc or someone similar hosted their websites and the username and password for FTP was something like "siteID" "tuesday" then you got logged into the folder /siteID/ out of interest i went up a folder and could happily download/remove the websites of over 150 schools (i obviously didnt) but was shocked about the lack of permission based security. Not surprising though as we all know these consortiums are ran by cowboys. matt Hi Matt The problem with EMBC (as with many RBCs) is that when they set things up they do it in bulk, and then pass it on to the LAs to change things or train schools how to. This is one of the problems that is happening with moving to the new contract, ensurig that the data is clean and that schools, LAs, EMBC and Synetrix all know who has what information and that everyone is happy. It is ... erm ... interesting. The scariest thing is working out how many schools just have site level filtering set at level one and *don't* have any internal filters either.
mrbios Posted December 3, 2007 Posted December 3, 2007 guy i work with once had an interview for fasthosts, he says his first impression was not knowing where he was going, turning a corner into an open door and where did he find himself? stood in there server room :|
theriver Posted December 16, 2007 Posted December 16, 2007 I have a theory on hosting companies, that they go in cycles of good -> rubbish -> good. @ninjabeaver, I used to use 123-reg in their Webfusion guise, and had excellent service for a couple of years followed by a period of torment that prompted me to move some stuff over to Fasthosts. Webfusion fixed their infrastructure problems and appear to be OK again. While I haven't had much in the way of direct problems with Fasthosts, I currently have a support issue unrelated to the current security problems, but haven't been able to access their support line 'cause it's been engaged, presumably with irate people who can't access their servers. I managed to edge into the queue (at 35th place!) this evening - 3.5 hours ago! Am now third in the queue. Wonder if my call is important to them? Oh! Just been bumped up to second! Best case scenario: knowledgable person fixes problem in 5 minutes Worst case scenario: numbnut cuts me off What do you reckon will happen?
Michael Posted December 16, 2007 Posted December 16, 2007 I also used Fasthosts once (on their dedicated service), but then I moved to their shared or semi dedicated service which has proven to be much better value for money! Fasthosts undoubtedly have made a very, very, very stupid error, as this problem originated from their user logon page which was not secured using SSL. They've also included an image verifier so must type out the relevant letters. Does this have a proper name? I feel the reason(s) to change everyone's passwords is simply because they had no real indication of how much information (if any at all) was leaked, so they had no choice. The situation could be a lot worse than it is now, but we'll never know for sure. They have seriously damaged their reputation and I can only imagine their phone lines have been buzzing over the last few months now. Hopefully lessons have been learned, however on a positive, there haven't been any reports of websites hacked or modified, or anyone losing money as a result and this is all a precautionary measure. For the time being I will be staying with Fasthosts, but, the next 12 months should be interesting and hopefully this will never happen again!
webman Posted December 16, 2007 Posted December 16, 2007 They've also included an image verifier so must type out the relevant letters. Does this have a proper name? CAPTCHA.
Michael Posted September 12, 2008 Posted September 12, 2008 I've just had another bad experience with Fasthosts - this time, they've renewed a domain and taken payment for it, without notification that this was due to happen, and are refusing to refund it. It's only a few pounds, but that's not really the point. If you fleece every customer for a couple of quid, you'll soon make a fortune! (particularly if you supplement your income by selling customer email addresses as ChrisP suggests! Fasthosts have (for some time) adopted a policy whereby domains are automatically renewed for your convenience (as they put it), but as you say, in practice it means if you don't opt out it will get renewed. Ironically I suspect I will receive lots of reminder e-mails when some of my other domains are up for renewal which I no longer use. It's all about money this game.
CSNM-Carl Posted September 19, 2008 Posted September 19, 2008 Fasthosts have (for some time) adopted a policy whereby domains are automatically renewed for your convenience (as they put it), but as you say, in practice it means if you don't opt out it will get renewed. Ironically I suspect I will receive lots of reminder e-mails when some of my other domains are up for renewal which I no longer use. It's all about money this game. This is actually normal practice in the hosting industry, and we have the same policy. If you have a credit/debit card on file and have not switched off the option for automatic renewal the domain will be automatically renewed. We do send plenty of reminders before the renewal though. Automation all the way!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now