General Chat
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Codewalkers ForumsGeneralGeneral Chat

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Codewalkers Forums Sponsor:
  #1  
Old September 26th, 2005, 01:11 AM
DeadlySin3 DeadlySin3 is offline
Codewalkers Newbie (0 - 499 posts)
 
Join Date: Apr 2007
Location: Pueblo, Co. USA
Posts: 105 DeadlySin3 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
Send a message via ICQ to DeadlySin3 Send a message via AIM to DeadlySin3 Send a message via Yahoo to DeadlySin3
Rant & Rave!

I've just recently gotten an e-mail from my website host, telling me this:

Hello,

I apologize, when I saw your email address I realized what your domain name was.

The reason your account was suspended is because it uploaded hacks on the server and was running them, causing server downtime. Can you list for me all the PHP scripts used on this account?

Her-Name Here

Her-small-company-name

------------------------

My site has been down now for like 4 days total due to this "problem" and i've had a suspended page put up for that entire time.

--
This Account Has Been Suspended
Please contact the billing/support department as soon as possible.
--

ALL of my billing is taken care of, i'm not late with a single payment. That page is somewhat of an embarrassment as i've got clients who use my website on the daily.. and they're asking me about this.

I'm about to move hosts as I can't take 4 days of downtime with this message in place of my site too lightly.

What would YOU do in this situation?

Reply With Quote
  #2  
Old September 26th, 2005, 02:40 AM
Matt Matt is offline
Contributing User
Codewalkers Specialist (4000 - 4499 posts)
 
Join Date: Apr 2007
Location: Florida
Posts: 4,158 Matt User rank is Private First Class (20 - 50 Reputation Level)Matt User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 h 12 m 16 sec
Reputation Power: 7
RE: Rant & Rave!

Sounds to me that there was an exploitable php script in your web site somewhere. The host should have been able to track down which one by greping through the apache logs....

Reply With Quote
  #3  
Old September 26th, 2005, 07:43 PM
pickleman78 pickleman78 is offline
Codewalkers Novice (500 - 999 posts)
 
Join Date: Apr 2007
Location: Dallas,TX,USA
Posts: 582 pickleman78 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 3
Send a message via AIM to pickleman78
RE: Rant & Rave!

Man, I wish one of my hosts was that competent. Let me describe to you some of the horribleness that recently happened to us.

So apparently we have an exploitable upload script, which allowed a user to upload a PHP script, into a directory our host put in our home directory with 0777 permissions. The person then uploaded a script into this directory (I forgot what it was, some online WYSIWYG editor that the host randomly stuck in there), and he used it to run shell commands, which he then ran on our sql connection script and got our password. (Part of this was a foolish mistake on our part, however it was still annoying). He then proceeded with downloading all our sql data, all our pages, and several other things, and began cracking our members passwords.

We sent numerous request to the host to have them help us find the problem, however we were always met with absolutely NOTHING. They told us the problem was that our / directory was world writable (not set that way by us), and that would fix all of our problem (which it won't), and they claimed no responsibility or knowledge of what happened. They apparently "don't keep server logs, FTP logs, or any kind of logs", and "all of the raw logs are accessable to you via cpanel"... which is a lie, what they meant were awstats was accessable for previous months, which helped a little bit, but not very much. Even more insulting was after I repeated my question, which the support person failed to answer, they never answered back, still holding this was entirely my fault....He was also able to read the password files of several other hosting accounts on the server, and able to modify some other site on that server because of the world writeable home.... but the host hasn't noticed, nor have they said anything, nor have they been able to help. BAH!!!!! Thats what I have to say.

Reply With Quote
  #4  
Old September 26th, 2005, 08:18 PM
Matt Matt is offline
Contributing User
Codewalkers Specialist (4000 - 4499 posts)
 
Join Date: Apr 2007
Location: Florida
Posts: 4,158 Matt User rank is Private First Class (20 - 50 Reputation Level)Matt User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 h 12 m 16 sec
Reputation Power: 7
RE: Rant & Rave!

Any host that is not capable of grepping through access logs to find what script is causing a problem shouldn't be hosting anyone.

Reply With Quote
Reply

Viewing: Codewalkers ForumsGeneralGeneral Chat > Rant & Rave!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

Request Your Free Technology Downloads!
 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

Request Your Free Technology Downloads!
 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

Request Your Free Technology Downloads!
 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

Request Your Free Technology Downloads!
 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

Request Your Free Technology Downloads!
 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 12 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek