mbdrake
Members-
Posts
6 -
Joined
-
Last visited
Reputation
5 NeutralAbout mbdrake

Personal Information
-
Occupation
Systems Administrator
-
Location
Guildford, Surrey, UK
-
We do have a complaints and/MD contact point for when people feel as though they're not getting the service they feel they're getting (rightly or wrongly). I know it feels good taking out frustrations in public like this (and goodness knows I've done it myself), but it doesn't really do anybody any good in the long run. I see you've already spoken to Kate, and am pleased that things have been resolved. Absolutely - that's one of the best features of Wordpress is that it can also update itself (along with relevant plug-ins). As I said, I wasn't responsible for the suspension or technical dealings with this particular incident (although yes, I mis-read/interpreted your original post) but from what you say here, the plug-in may well be the culprit. I've seen a fair few image gallery systems compromised through it's upload functionality. That seems the likely reason. Regards, Martyn
-
We'll have to agree to disagree. Whether or the emails were published or not, the thread would have been spotted at some point. Google is very handy for keeping an eye on what's being said. The point is that it's not good etiquette to post private correspondence regardless. What's more important is that the company or individual being complained about has the right to reply. There is no need to publish such correspondence in order to be able to do that. Regards, Martyn
-
Nobody sets out to be hacked (well, unless you're looking to become a honeypot), but even so, clearing up after vulnerability is both time consuming and costly in terms of support (there is also the issue of replying to those reported the phishing site, the upstream provider, etc. to tell them that we have dealt with the issue and re-assure them that this will not happen again from the same customer). When you weigh that against the cost charged for the actual hosting and the clean up operation, it an becomes expensive process. The balance of giving lots of support to shared hosting customers and VPS/dedicated customers is a difficult one. Sometimes it doesn't work out - like it has here. I've used a lot of web hosts myself over the years. I started my career as a technical manager/systems administrator/developer for small ISPs/web hosts before working for six years in the film industry for a busy visual effects facility in London. I used a LOT of web hosts during that time and none of them gave me the kind of level of support that my employers give our customers - especially those shared hosts that I used (and gave up before moving over to VPSes and dedicated servers). Sometimes paying that bit more money to get quality support is a necessity. Oversold cheap hosts do not work out well at all. I DO believe in good customer service, yes, absolutely. But I feel that our recommendation of upgrading to a miniserver was a reasonable one given the circumstances. Regards, Martyn
-
That still does not excuse posting private correspondence to a public forum - poor customer service or not. That said, the points raised about customer service here has been noted and I ensure these will filter back to the right people. I can't comment about pricing - my duties directly relate to ensuring that our services are operational and secure. As for not supporting the shared hosting customers when they need help - this is absolutely not true. I (and my colleagues) have gone out of our way on many occasions to assist our shared hosting customer base. However there must be some limits to this support for these services. I've found that shared hosting takes up far more support time than providing support for VPS and dedicated server customers. We're now focusing on businesses rather than the consumer market (of which there are plenty of web hosts out there for home users) and indeed, our shared hosting facilities are being phased out (I don't believe you can buy any shared web hosting packages with us now). Regards, Martyn
-
The problem with shared hosting is that if one customer requires a particular version of MySQL, PHP or a PHP module, etc. it could have profound effect on other customers. VPSes are an ideal way of getting around that limitation. cPanel/WHM is a good way for relatively novice users to manage their own server. And a lot of providers (Memset included) offer a fully managed service with them that takes care of the responsibility of keeping the OS, Apache, PHP, MySQL, etc. updated and patched. Regards, Martyn
-
I must state my intentions here - I'm a systems administrator at Memset. Any web hosting company worth their salt will suspend/deactivate any web site that has been compromised. WordPress has had it's fair share of vulnerabilities over the years that have allowed hackers and phishers to upload their own content. Joomla also has suffered it's fair share, and we've seen many compromised sites who have not updated when security updates have been released. What happened in the original poster's case was that he was running an insecure version of WordPress and a phisher had found and exploited a vulnerability in the WordPress (or plugin) module that allowed them to upload the phishing site. We suspended the account because (a) we had received complaints from our upstream provider and (b) it is a potential threat to our other customers, our server and our network. When phishing sites are detected, what happens is that the security companies acting on behalf of the company that the phishing site is trying to spoof will contact both the web hosting company AND their upstream provider. Whole servers and networks can be blacklisted, null routed and various other fun things if they do not remove sites/code/whatever that is a threat to their operations. In the case of unmanaged web sites at Memset - it is assumed that the customer is fully responsible for the system administration and maintenance of their own web site INCLUDING security patching, etc. If not, sites are suspended. We have to do this to protect ourselves and other customers, as I have said. On the shared hosting service, we manage the main OS patching, Apache patching, MySQL patching, etc. but it is up to the customer to ensure their applications are kept patched and up-to-date. Unless you're on a fully managed support contract with *whatever* web hosting provider you're using, I am confident that pretty much every other web host would have done the same thing in our position. I am thoroughly disappointed with some of the ill-informed comments on this thread. Surely most of you should understand that patching software such as WordPress, vBulletin, Joomla, etc. is very important - as is keeping yourself informed of what security vulnerabilities are out there. Regards, Martyn Drake P.S. - It's not particularly polite to repost private communications on a public forum.
