AngryTechnician Posted May 15, 2009 Posted May 15, 2009 It's not particularly polite to repost private communications on a public forum. It's also not particularly polite to ignore a customer who has become a victim themselves and is genuinely asking for assistance, and give them a response that equates to 'you are not worth our time to help'. Granted that was not your personal approach, but it was the response given by your Marketing department so I can understand why some of the comments here have been made. Your Marketing Manager said himself that he would prefer only to be offering only more secure solutions, and that may well be sensible for all the reasons you've mentioned, but the fact is if you are offering a service you should not turn your back on a customer the moment something goes wrong. That is simply poor customer service. I would be interested to know if he really expected the customer to roll over and fork out more money given that poor level of support? We could debate the practicalities and financial viability of all this for hours, but what it comes down to in this case is that the response of your company to this incident was not handled well from a customer service perspective. My overall point is that you should ensure your own house is in order before lecturing other people on etiquette.
mbdrake Posted May 15, 2009 Posted May 15, 2009 (edited) We could debate the practicalities and financial viability of all this for hours, but what it comes down to in this case is that the response of your company to this incident was not handled well from a customer service perspective. My overall point is that you should ensure your own house is in order before lecturing other people on etiquette. That still does not excuse posting private correspondence to a public forum - poor customer service or not. That said, the points raised about customer service here has been noted and I ensure these will filter back to the right people. I can't comment about pricing - my duties directly relate to ensuring that our services are operational and secure. As for not supporting the shared hosting customers when they need help - this is absolutely not true. I (and my colleagues) have gone out of our way on many occasions to assist our shared hosting customer base. However there must be some limits to this support for these services. I've found that shared hosting takes up far more support time than providing support for VPS and dedicated server customers. We're now focusing on businesses rather than the consumer market (of which there are plenty of web hosts out there for home users) and indeed, our shared hosting facilities are being phased out (I don't believe you can buy any shared web hosting packages with us now). Regards, Martyn Edited May 15, 2009 by mbdrake
dwhyte85 Posted May 15, 2009 Posted May 15, 2009 That still does not excuse posting private correspondence to a public forum - poor customer service or not. That said, the points raised about customer service here has been noted and I ensure these will filter back to the right people. I can't comment about pricing - my duties directly relate to ensuring that our services are operational and secure. As for not supporting the shared hosting customers when they need help - this is absolutely not true. I (and my colleagues) have gone out of our way on many occasions to assist our shared hosting customer base. However there must be some limits to this support for these services. I've found that shared hosting takes up far more support time than providing support for VPS and dedicated server customers. We're now focusing on businesses rather than the consumer market (of which there are plenty of web hosts out there for home users) and indeed, our shared hosting facilities are being phased out (I don't believe you can buy any shared web hosting packages with us now). Regards, Martyn I have to admire your courage considering the thread was very much against you before you joined it! I think it shows the frustration and disbelief of an up and coming IT guy, he never purposely got hacked, support should have been there for him rather than threatening him/pushing him to take another package, I don't condone the pasting of the PM but you need to understand that approaching someone informally through a forum is unlikely to result how you want.
mbdrake Posted May 15, 2009 Posted May 15, 2009 (edited) I have to admire your courage considering the thread was very much against you before you joined it! I think it shows the frustration and disbelief of an up and coming IT guy, he never purposely got hacked, support should have been there for him rather than threatening him/pushing him to take another package, I don't condone the pasting of the PM but you need to understand that approaching someone informally through a forum is unlikely to result how you want. Nobody sets out to be hacked (well, unless you're looking to become a honeypot), but even so, clearing up after vulnerability is both time consuming and costly in terms of support (there is also the issue of replying to those reported the phishing site, the upstream provider, etc. to tell them that we have dealt with the issue and re-assure them that this will not happen again from the same customer). When you weigh that against the cost charged for the actual hosting and the clean up operation, it an becomes expensive process. The balance of giving lots of support to shared hosting customers and VPS/dedicated customers is a difficult one. Sometimes it doesn't work out - like it has here. I've used a lot of web hosts myself over the years. I started my career as a technical manager/systems administrator/developer for small ISPs/web hosts before working for six years in the film industry for a busy visual effects facility in London. I used a LOT of web hosts during that time and none of them gave me the kind of level of support that my employers give our customers - especially those shared hosts that I used (and gave up before moving over to VPSes and dedicated servers). Sometimes paying that bit more money to get quality support is a necessity. Oversold cheap hosts do not work out well at all. I DO believe in good customer service, yes, absolutely. But I feel that our recommendation of upgrading to a miniserver was a reasonable one given the circumstances. Regards, Martyn Edited May 15, 2009 by mbdrake 1
CAM Posted May 15, 2009 Author Posted May 15, 2009 Right, as per your request I have removed theanonymised transcripts from my posts. I'm sorry for doing it and may have made a mistake, butI saw no wrong in posting them and felt it would provide better clarity to the situation as I have never been in this situation before and didn't want to come accross as one sided. Yes, there are a few "angry customer" moments but what do you expect when you are left feeling like your dangling from the end of a rope with EBay's legal sharks circling below you? In response to your claims of an old version of Wordpress, if you read the thread you will see I posted that as far as I knew, it was the most up-to-date version. The control panel bugs the hell out of me if I don't update, so I do. We all know that keeping web software up to date is as critical as keeping Windows up to date. It may have been Image Gallery which I assumed would be no threat if disabled in the control panel. But I did ask for this information plus more and it wasn't given, hence why I opted to leave. I have spoken to the company MD who I have to say was incredibly good and helped calm the situation down and clarify the potential source of confusion. I have dealt with the matter and putting it behind me to move on and deal with more important things (like dodging the camera lenses of our school leavers ).
localzuk Posted May 15, 2009 Posted May 15, 2009 That still does not excuse posting private correspondence to a public forum - poor customer service or not. I disagree. Would you have looked at this issue in the detail you have done if it had not been for the airing of this dirty laundry? I think not.
mbdrake Posted May 15, 2009 Posted May 15, 2009 I disagree. Would you have looked at this issue in the detail you have done if it had not been for the airing of this dirty laundry? I think not. We'll have to agree to disagree. Whether or the emails were published or not, the thread would have been spotted at some point. Google is very handy for keeping an eye on what's being said. The point is that it's not good etiquette to post private correspondence regardless. What's more important is that the company or individual being complained about has the right to reply. There is no need to publish such correspondence in order to be able to do that. Regards, Martyn
mbdrake Posted May 15, 2009 Posted May 15, 2009 Right, as per your request I have removed theanonymised transcripts from my posts. I'm sorry for doing it and may have made a mistake, butI saw no wrong in posting them and felt it would provide better clarity to the situation as I have never been in this situation before and didn't want to come accross as one sided. Yes, there are a few "angry customer" moments but what do you expect when you are left feeling like your dangling from the end of a rope with EBay's legal sharks circling below you? We do have a complaints and/MD contact point for when people feel as though they're not getting the service they feel they're getting (rightly or wrongly). I know it feels good taking out frustrations in public like this (and goodness knows I've done it myself), but it doesn't really do anybody any good in the long run. I see you've already spoken to Kate, and am pleased that things have been resolved. In response to your claims of an old version of Wordpress, if you read the thread you will see I posted that as far as I knew, it was the most up-to-date version. The control panel bugs the hell out of me if I don't update, so I do. We all know that keeping web software up to date is as critical as keeping Windows up to date. It may have been Image Gallery which I assumed would be no threat if disabled in the control panel. But I did ask for this information plus more and it wasn't given, hence why I opted to leave. Absolutely - that's one of the best features of Wordpress is that it can also update itself (along with relevant plug-ins). As I said, I wasn't responsible for the suspension or technical dealings with this particular incident (although yes, I mis-read/interpreted your original post) but from what you say here, the plug-in may well be the culprit. I've seen a fair few image gallery systems compromised through it's upload functionality. That seems the likely reason. Regards, Martyn
GrumbleDook Posted May 15, 2009 Posted May 15, 2009 I'm glad to see that there is a good level of discussion going on now between the OP and the hosts but I'm just wondering how hosts can expect their client to resolve an issue if they are given very little chance to resolve an issue due to majority of access to the site is removed. The hosts involved aren't the only people to do this and I have been in a similar situation (and when I did a bit of a search on various forums other than here there are a goodly number of examples). What would people expect to be a reasonable level of access to try and resolve these sorts of issues ... remembering that many people use the *cheap* packages that mean that there will be limited support or help from the hosts (remember the old adage ... you get what you pay for!).
CAM Posted May 15, 2009 Author Posted May 15, 2009 Martyn, I can assure you I was reluctant to reveal Memset's name but I had to in order to assist with the matter. I did not take the decision lightly, neither did I find it pleasant to do as you claim. This is a far from satisfying experience for anyone involved. Dealing with customer complaints never is.
dwhyte85 Posted May 15, 2009 Posted May 15, 2009 (edited) Nobody sets out to be hacked (well, unless you're looking to become a honeypot), but even so, clearing up after vulnerability is both time consuming and costly in terms of support (there is also the issue of replying to those reported the phishing site, the upstream provider, etc. to tell them that we have dealt with the issue and re-assure them that this will not happen again from the same customer). When you weigh that against the cost charged for the actual hosting and the clean up operation, it an becomes expensive process. The balance of giving lots of support to shared hosting customers and VPS/dedicated customers is a difficult one. Sometimes it doesn't work out - like it has here. Presumably you'll have something like Virtuozzo installed and just rebuild if it's a vps or just delete the account and hosting and recreate? Nobody sets out to be hacked but in this case he's been unfortunate, although... advice to resolve the issue is better than threatening or offering an alternative solution that requires him to buy something different, it very much seems like avoiding the problem. Unfortunately... people wont care about your costs they care about support and feeling like people care about them as a customer, i'm afraid i don't sympathise with Memset whatsoever or agree with your reasoning. If i went in to work Monday and decided that recovering a pupils work wasn't worth my time as Network Manager and that they should seek a data recovery specialist - I would be in jeopardy of my job, of course priorities come into it and time constraints but at the end of the day... it's my end user as he is Memsets, not just a PayPal account who's paid x amount of money. My opinions... i've used many webhosts, most of them don't give a monkeys about customers, the low prices they offer is a definite trade off with quality of customer services, cheap hosts with either the non existant support or outsourced support which cannot do the job, BodHost is a great example of that! Edited May 15, 2009 by dwhyte85
CAM Posted May 15, 2009 Author Posted May 15, 2009 (edited) Right, now that I have the files it's time to give the arguments a time out and get down to the real dirty business of the forums. The techy bits. Inspecting my logs, I noticed a number of attempts to access the reset password screen. Bandwidth transferred had also jumped from 24MB to 40MB. The attack has been pinpointed to May as April shows no evidence of the offending phishing site. Now the interesting bit. Someone, somewhere has granted 777 permissions on the Upload folder. Inside is an encrypted file consisting of garbled letters and number called .log.php which you guys may want to have a quick scan for on hosting accounts (if it is a file to be worried about). Now, to further pinpoint the attack date, I have checked the Last Modified field on Properties in Windows FTP. They read 11 Dec 2007 which is wrong since the account has been emptied completely many times since then and WP was installed late 2008. However, a PHP script called samris.php that holds the malicious attack code appears to point to an EMail [email protected] and the attacker's alias appears to be The sTronGer. Some files, the one above in particular, says 29 March on Last Modified. I am asuming it preserves the Last Modified date on file copy? Looking at the phishing mini-site's root folder though, it says 9 Nov 2009 was the date of the folder creation. Checking .log.php it states 1 May 2009 as date Last Modified. Is that the right sort of lines to help me pinpoint more evidence in the log? Took about 10mins of looking too! Edited May 15, 2009 by CAM
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now