CAM Posted May 12, 2009 Posted May 12, 2009 (edited) I came home last night to find my personal site had been shut down again. First time was nonpayment, fair enough. Now less then a week later after renewing, they shut it down again, this time citing a phishing scam as the cause. I tried to explain "No, I didn't post a phishing site on my account" but all I get is I have to change to a more expensive dedicated virtual server package with no support or help in keeping it running. They claim their upstream provider will shut the shared webhosting server off "if they have any more security issues" So here I am, strong FTP password, updated Wordpress installation and keeping a careful eye on permissions. Done everything to keep it secure...and everything from webmail to FTP access is shut down. To top it off, they received a letter from PayPal trying to brand me as the criminal. What do I do? I've only just resubbed, I'm just trying to get webhosting experience and this hits the fan! Edited May 12, 2009 by CAM
dwhyte85 Posted May 12, 2009 Posted May 12, 2009 Do you have the latest WP? You have checked your own machine for Keyloggers and trojans? Bit unfair of your provider, they would have it pretty locked down, if someone did compromise your site they should be able to do very little with the access they have. I once had a site of mine hacked, i added my own code to e107 and i didn't sanitise the inputs so they were able to do some damage on my VPS, if it's just a WP install i can't see how they'd be able to get in, AFAIK no 0day exists for WP on the latest version. 1
matt40k Posted May 12, 2009 Posted May 12, 2009 Move hosts, they sound insecure hosts. I use Mythic-Beasts, they don't do a web control panel, but it's easy enough to setup I'll lend a hand if need. Failing that I'm sure CS New Media on here is a good bet, or GoDaddy, or FastHost (I'm sure someone will moan for saying that). See: http://www.edugeek.net/forums/recommended-suppliers/22143-web-hosting-company.html FYI: FTP is insecure. 1
CAM Posted May 12, 2009 Author Posted May 12, 2009 I tried GoDaddy but I wasn't fond of them. And before then was ETGlobalSolution that was, well, never seen a whole company just vanish! I'll take a look at those guys Matt, thanks. Back on topic, I heard of a possible exploit in Wordpress where old bugs came back to cause trouble. All I know is I had the latest version. I have no idea how they got in but the webhost company refuses to do an investigation saying it isn't their job to do so. I can't investigate myself either. They just said they'd copy a recent backup to a "new miniserver order" but that could be hacked as well! The site itself worked no trouble, the hackers were just sneaky and hid a malicious phishing page deep in the Worpress folder structure si I didn't even know they compromised it. No page vandalism or anything.
dwhyte85 Posted May 12, 2009 Posted May 12, 2009 I tried GoDaddy but I wasn't fond of them. And before then was ETGlobalSolution that was, well, never seen a whole company just vanish! I'll take a look at those guys Matt, thanks. Back on topic, I heard of a possible exploit in Wordpress where old bugs came back to cause trouble. All I know is I had the latest version. I have no idea how they got in but the webhost company refuses to do an investigation saying it isn't their job to do so. I can't investigate myself either. They just said they'd copy a recent backup to a "new miniserver order" but that could be hacked as well! The site itself worked no trouble, the hackers were just sneaky and hid a malicious phishing page deep in the Worpress folder structure si I didn't even know they compromised it. No page vandalism or anything. Unless you've downloaded an old plug-in? Or on the control panel they have an outdated fantastico or scriptaculous (whatever they call it).
CAM Posted May 12, 2009 Author Posted May 12, 2009 Thanks. I'll have words with their MD as a last ditch effort (she used to be a in a gaming group with me hence why I really don't want to drag this through the mud). If nothing is resolved, I'll aim to get a refund. There was one addon but it was disabled. Image Gallery or something. Since the uploads folder was the target and the uploads/js-cache folder held the malicious page, that might be an answer.
CSNM-Carl Posted May 12, 2009 Posted May 12, 2009 Is there anything in the website logs to show how the domain got compromised? You should have access to these either via FTP or your hosting control panel.
CAM Posted May 12, 2009 Author Posted May 12, 2009 As I said, they locked it down compeltely. No HTTP(S). No EMail. No FTP. No CPanel. Hosting control panel, worthless. Nada, zip, nil. Just an external EMail address I have I can use to contact support (and cant access on my break at work) and a page saying "Account Suspended." I didn't even get an EMail, I had to stumble on it by accident when I tried accessing my EMail and had to initiate the chat with support who have told me "Move to a dedicated hosting solution with no tech support offered." Technically less secure then what they gave me since I have minimal server experience.
matt40k Posted May 12, 2009 Posted May 12, 2009 Can you post use your website address or PM me it? We should be able to find out the hosting company, sounds to me like they are someone with a resellers package or a VPS with Cpanel installed. Really if someone (public) was able to access /uploads/, they could change the permissions or even remove it, it's not difficult.
EduTech Posted May 12, 2009 Posted May 12, 2009 Can you post use your website address or PM me it? We should be able to find out the hosting company, sounds to me like they are someone with a resellers package or a VPS with Cpanel installed. Really if someone (public) was able to access /uploads/, they could change the permissions or even remove it, it's not difficult. agree : ) lets have a look who is behind this and see what we can do
CAM Posted May 12, 2009 Author Posted May 12, 2009 The company in question is Memset I was on their 2 year Webhost 1000 Account. They have been a bit expensive but support seemed good up until now. However, browsing their Support Matrix the cost of fixing something that goes wrong if I do move is high! Far too much to warrant keeping the blog if something happens. They were good until the site was compromised and 2 days after intiating contact with support (who haven't even told me when the account was suspended) I feel they are just trying to sell me a new server instead of fixing the damage after locking it down far too much. "Blah blah the server cant take all the extra traffic from spam and we are being threatened with closure" etc etc etc. The site is http://www.ssib.co.uk but chances are, LEAs are now blocking it due to anti-phishing services blacklisting my domain. I've also been with them since 2007 no hassle apart from denying me shell access and having to ask them to delete some folders after permission trouble.
matt40k Posted May 12, 2009 Posted May 12, 2009 (edited) memset.com Prices seem too cheap. Windows 2003 license standard £10, web is £8. How can they charge £5? Not even gold partners get it that cheap! Has an postal address listed Has a resellers account with tucows.com for domain reg. Appears to be a Ltd company is Surroy. Colo\rent whatever from dedipower.com, which is (mainly) managed stuff. Public website seems to only offer VPS really, can't find web hosting (easily) Personally, cut you loses and move hosts, only thing worth maybe getting is domain name moved to new provider. On the home page they say KFC is hosted with them, pretty sure rackspace (i suppose kfc too) will be naffed off. More thoughs in the morning EDIT: Read web hosting as py not pm. Edited May 12, 2009 by matt40k In need of sleep
EduTech Posted May 12, 2009 Posted May 12, 2009 Dam you matt your too quick for me lol The company look like a total waste of space to me i would just move away if you can. Do you have a backup of your site so you can restore it on another sever? if not maybe give them an email and ask if you can just take a backup of the site. I'll send you a PM might be able to help you out though. James. 1
mossj Posted May 12, 2009 Posted May 12, 2009 I can sort you out with some free *tempory* hosting if you like (a donation through paypal would be nice), PM me with what your site requires in bandwidth/space/databases/email and I'll let you know.
CyberNerd Posted May 13, 2009 Posted May 13, 2009 Prices seem too cheap. Windows 2003 license standard £10, web is £8. How can they charge £5? Not even gold partners get it that cheap! Muliple virtual installations on one physical server ?? IIRC one 2003R2 license can be installed four times on one server.
matt40k Posted May 13, 2009 Posted May 13, 2009 So PcPro awards = nothing. Summary of last nights info. Will wait for someone to correct me.
CAM Posted May 13, 2009 Author Posted May 13, 2009 Thanks for the hosting offers, someone has stepped forwards though (and their PM box is full ). I also have a backup domain name, http://www.pitchblack.me.uk , that hasn't cropped up in any phishing reports to my knowledge. Would that help and be low traffic if all the spammers are clicking on a link to ssib.co.uk?
CAM Posted May 13, 2009 Author Posted May 13, 2009 Apparently, their actions are because I am not economically viable. I'll post the transcript later (checked it on my phone) but the Marketing Manger stepped in to the dispute saying "30mins of a technicians time fixing hacked accounts equates to 6 months subscription fee." He then said it'd cost £5 extra per month to swap to a dedicated virtual server and £20 to patch it up to make it secure (I expect only once though!). Apparently they shove customers with breached accounts to a new server so they can grant shell access (which is denied on shared hosting for security reasons) and leave them to do the security.
plexer Posted May 13, 2009 Posted May 13, 2009 It's their fault for letting customers host vunerable versions of sofware ala wordpress. Why did their technicians jump in and fix your files all you need to do was delete and upload a good install. If your db wasn't attacked then your data would be safe. Ben
ICTNUT Posted May 13, 2009 Posted May 13, 2009 He then said it'd cost £5 extra per month to swap to a dedicated virtual server and £20 to patch it up to make it secure (I expect only once though!). Sorry that I am coming to this late but I am sorry mate if a host as me to pay for a secure server ON TOP of what I pay monthly I would walk away. I would expect the server (dedicated or VPS) to be secure from the point I got it, now there are things such as SLA's and non managed servers in that from this point onwards its down to you but the least they could do is give you a secure server in the first place. Not good if you ask me.
CAM Posted May 13, 2009 Author Posted May 13, 2009 (edited) Guess the consensus is to jump ship then. Now the fun of fighting for a refund! [Anonymised Tech Transcript logs removed by the OP since it causes so much offence to their techs. :/] Edited May 15, 2009 by CAM
CSNM-Carl Posted May 13, 2009 Posted May 13, 2009 It's their fault for letting customers host vunerable versions of sofware ala wordpress. Why did their technicians jump in and fix your files all you need to do was delete and upload a good install. If your db wasn't attacked then your data would be safe. Ben I think this is a little unfair. It's not the hosting providers responsibility to ensure customers keep their scripts up to date. It would be impossible to do this, we have recently purchased some software which scans a server for popular scripts and fetches version details of the script, if a script is out of date it alerts us of this. It is then up to us to notify the customers, however when you have several hundred domains with out of date scripts on it's very time consuming... However it is the providers responsibility to keep the servers secure & related software up to date (PHP/MySQL/Apache etc). It's also good idea for hosting providers to educate their customers on the importance of keeping popular scripts such as Wordpress (and especially Joomla!) up to date to avoid them getting comprimised. We usually do this as a little reminder in newsletters and offer assistance to customers on updating their software It sounds like the company in question are simply trying to get you to upgrade to a premium package as they've almost given up on shared hosting. VPS's do have their place in hosting, but I'd personally not put anything on a 512MB server. You also need the technical ability (and time) to look after a server/VPS. The normal way we deal with compromised sites is: 1. Try and find how the site got compromised in the first place via logs 2. Attempt to try and clean up the site and get it back on-line 3. If it can be cleaned up and offending code removed, upgrade the customers script to the latest version and secure appropriately (with correct permissions on files/folders). 4. If it cannot be cleaned up, we will restore the domains content from our backups, bring the site on-line and update the script/secure it. 5. Notify the customer of the importance of keeping scripts up to date/secure, should it be compromised again and we have to use our own backups there will be a charge of £15 + VAT (our standard rate for backup retrievals). 1
CAM Posted May 14, 2009 Author Posted May 14, 2009 (edited) After cancelling my Memset account, they replied "If you feel that way then fine, we will supply a full refund" and they have also granted me access to the my data and EMail system to recover my stuff. I can hopefully investigate the logs too. Thanks guys. EDIT - And to keep things fair, post the good reply now I am back from work and can copy the message. [Good anonymised transcript removed too by OP]. Edited May 15, 2009 by CAM
mbdrake Posted May 15, 2009 Posted May 15, 2009 (edited) I must state my intentions here - I'm a systems administrator at Memset. Any web hosting company worth their salt will suspend/deactivate any web site that has been compromised. WordPress has had it's fair share of vulnerabilities over the years that have allowed hackers and phishers to upload their own content. Joomla also has suffered it's fair share, and we've seen many compromised sites who have not updated when security updates have been released. What happened in the original poster's case was that he was running an insecure version of WordPress and a phisher had found and exploited a vulnerability in the WordPress (or plugin) module that allowed them to upload the phishing site. We suspended the account because (a) we had received complaints from our upstream provider and (b) it is a potential threat to our other customers, our server and our network. When phishing sites are detected, what happens is that the security companies acting on behalf of the company that the phishing site is trying to spoof will contact both the web hosting company AND their upstream provider. Whole servers and networks can be blacklisted, null routed and various other fun things if they do not remove sites/code/whatever that is a threat to their operations. In the case of unmanaged web sites at Memset - it is assumed that the customer is fully responsible for the system administration and maintenance of their own web site INCLUDING security patching, etc. If not, sites are suspended. We have to do this to protect ourselves and other customers, as I have said. On the shared hosting service, we manage the main OS patching, Apache patching, MySQL patching, etc. but it is up to the customer to ensure their applications are kept patched and up-to-date. Unless you're on a fully managed support contract with *whatever* web hosting provider you're using, I am confident that pretty much every other web host would have done the same thing in our position. I am thoroughly disappointed with some of the ill-informed comments on this thread. Surely most of you should understand that patching software such as WordPress, vBulletin, Joomla, etc. is very important - as is keeping yourself informed of what security vulnerabilities are out there. Regards, Martyn Drake P.S. - It's not particularly polite to repost private communications on a public forum. Edited May 15, 2009 by mbdrake
mbdrake Posted May 15, 2009 Posted May 15, 2009 However it is the providers responsibility to keep the servers secure & related software up to date (PHP/MySQL/Apache etc). It's also good idea for hosting providers to educate their customers on the importance of keeping popular scripts such as Wordpress (and especially Joomla!) up to date to avoid them getting comprimised. We usually do this as a little reminder in newsletters and offer assistance to customers on updating their software The problem with shared hosting is that if one customer requires a particular version of MySQL, PHP or a PHP module, etc. it could have profound effect on other customers. VPSes are an ideal way of getting around that limitation. cPanel/WHM is a good way for relatively novice users to manage their own server. And a lot of providers (Memset included) offer a fully managed service with them that takes care of the responsibility of keeping the OS, Apache, PHP, MySQL, etc. updated and patched. Regards, Martyn
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now