UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Reseller Hosting

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 22-04-2007, 03:45
Junior Member
 
Join Date: Nov 2006
Posts: 24
Unhappy How is security of the sever

How is security of the server ? is it safe against hacking ?
a group of hackers told me we can hack the server win1 ,
Reply With Quote
  #2 (permalink)  
Old 22-04-2007, 10:10
Member
 
Join Date: Apr 2007
Posts: 61
Default

I don't think it is the security of the server that would be at fault, rather your website hosting. I am sure that the server has the appropriate modules installed to protect against such attempts, but you may have scripts running on your website hosting that are vunerable to attacks, hence your website hosting may be at risk to a hacking attempt.

May I ask, what is your website hosting? Also, who were the group of hackers that told you they could hack the server, and what is their reason for doing so?
Reply With Quote
  #3 (permalink)  
Old 22-04-2007, 12:48
System Administrator
 
Join Date: Dec 2006
Location: localhost
Posts: 682
Lightbulb

Deep,
Such incidents are most of the time rumours/hoaxes, nothing to worry about them.
Our servers are well equipped to fight against such hack attempts & to keep them at bay. We have various tools (firewalls) running on our servers to monitor such events. None of our servers have been yet hacked, but unfortunately (as hairyfreak said) few website hostings are hacked due to insecure permissions set on files by their owners/webadmins.
If you received any such email from the hackers, please have it forwarded to our support dept.
__________________

Rock _a.k.a._ Jack L.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #4 (permalink)  
Old 22-04-2007, 13:11
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 346
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default Jaguar has been attacked

For the past 3 weeks website hostings on jaguar have had files changed - pornography, pharmaceuticals, shell scripts and even ring tones have all been added. Now i have been 'communicating' with support over these 'intrusions' the whole time. They have been polite and occasionally helpful - however there suggestions as to the causes have not been satisfactory.
Explanation 1. "It's individual website hostings where a weak password has been set and the hackers are using brute force methods." This is indeed posssible - however today following support's latest response I reset the password on 3 of my accounts (I'm a reseller with over 60 domains on this server) Within a couple of hours (less than 30mins in one case) the files had been altered to include links to woficlub.com. From my experience over Xmas, (see elsewhere in the forum) when a website hosting wide attack occured, I have a list of other domains on this same server that are nothing to do with me (300+ domains). I've just checked a random sample and yes they too have had the same links added.
Explanation 2 "There was trojan on server due to which the website hosting got infected.
We have updated the required security patches on server, so that such problem wont happen in future" - well it has - several times now. The most common has been to add a hidden iframe at the bottom of the index.html page.
I am at my wits end with all this. Every time i report infections and clean website hostings up another one happens. It has got so bad that yesterday I ordered reseller hosting from another provider - once that is set up and working properly I intend to migrate all my website hostings over and so after many years of reliable service (and i do think you guys geniunely try) and invaluable help all this time - not to mention this forum - i will have to bid adiou
If anyone else is on the jaguar server (64.38.20.21 you might like to check your website hosting and pay particular attention to the dates when files were last changed and check them (the code not just the look of the page in your browser)
Please sort this out EUK
Regards
David
Reply With Quote
  #5 (permalink)  
Old 22-04-2007, 14:37
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,563
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

someone was managing to use BFD on 64.38.20.218 to hack FTP passwords and individual website hostings were injected on the server. Logs show that ftp service was used to download webpages and injected webpages were uploaded again.

This server had such problems in November 2006 and the attackers have become aggressive in last 3 weeks. We have mirrored all data on this server on another server setup in same subnet and right now we are swapping IPs of both servers.

None of your website hostings will go down nor they will face any problems with any service as the reboot process will take less than 2 mins only.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #6 (permalink)  
Old 22-04-2007, 14:56
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 346
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default How will that help?

Other than changing the ip - how will that help. And how come the passwords are cracked so quickly? As I said it was less than 30 mins for one website hosting and I used a random 8 char password (generated by http://www.angel.net/~nic/passwd.html)
Also website hostings did go down for a while (minor quibble i know)
Reply With Quote
  #7 (permalink)  
Old 22-04-2007, 16:38
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

I've had exactly the same problem, DavidAllen.

My index.php files have had code injections of pornography and pharmaceutical links exactly how you described.

Support have assured me before that its been fixed, but yesterday my index.php was wiped and new links injected.

I was told the attacker IP has been blocked from the server, but I don't think this is acceptable (for the website hosting to be hacked 2 or 3 times).
Reply With Quote
  #8 (permalink)  
Old 22-04-2007, 16:52
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 346
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default I am not alone !

Chris - you don't know how happy that makes me. All the time I've been getting fob off from support - along the lines of Rocks original reply
Quote:
Such incidents are most of the time rumours/hoaxes, nothing to worry about them.
Our servers are well equipped to fight against such hack attempts & to keep them at bay. We have various tools (firewalls) running on our servers to monitor such events. None of our servers have been yet hacked
Which has done little for my sanity as it IS worrying.
Anyway - hope you have cleaned the lates one up - looks to be some script from jsp.gomyron.com god knows what it is meant to do - i've given up following these things to find out.
Regards
David
Reply With Quote
  #9 (permalink)  
Old 22-04-2007, 17:06
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

We need some decent customer support on this. I want one of the senior admins to start talking.

Unless I'll join you in moving my hosting elsewhere.

My cPanel was offline for a while there, and I can no longer access my email.
Reply With Quote
  #10 (permalink)  
Old 22-04-2007, 19:39
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Lol.

My index files got hit again today, this time by the jsp.gomyron stuff you mentioned.

There's obviously a trojan running somewhere on eUKhost's server, or something.
Reply With Quote
  #11 (permalink)  
Old 22-04-2007, 20:22
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,563
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Servers has been swapped now and your website hostings are running from new server. All services are running smoothly from the new server so if you have any old injections then replace those.

New server has got latest version of pure-ftp and new version is highly secure as per updates on website hosting of pureftp.

Let me know if you see any kind of problems in next 24 - 48 hours as there should be absolutely no problems now on the new server.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #12 (permalink)  
Old 22-04-2007, 20:41
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 346
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default Email and WHM

Email is not working properly accross all my accounts (both catchall and specific names) - my WHM shows 0 accounts
Please can you fix this
Regards
David
Reply With Quote
  #13 (permalink)  
Old 22-04-2007, 20:44
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Ditto on the email problem. Can access inside cPanel, but Thunderbird still seems to want to connect to Jaguar.
Reply With Quote
  #14 (permalink)  
Old 22-04-2007, 21:54
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,563
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

name of new server is jaguar and its IP is 64.38.20.218 so thunderbird should have no problems in connecting. Please provide me with the exact error and I will look into it.

Alex is working on David's problem and I will look into your problem if you provide me with the error you get in thunderbird. I think you should logout from thunderbird and connect again as it might be looking to continue with old session which is not there on new server.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #15 (permalink)  
Old 22-04-2007, 22:11
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

I get the message:

Sending the password did not succeed. Mail server mail.scifiheaven.net responded: Maildir invalid (no 'cur' directory).

My password is correct, cause an incorrect password returns "Login failed".
Reply With Quote
  #16 (permalink)  
Old 22-04-2007, 22:51
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,563
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by ChrisMcQuillan View Post
I get the message:

Sending the password did not succeed. Mail server mail.scifiheaven.net responded: Maildir invalid (no 'cur' directory).

My password is correct, cause an incorrect password returns "Login failed".
please logout and relogin. If that doesnt work then change the password for your mailbox from the control panel and check if that works. If that doesnt work then let me know the email address in question and I will take a look into it.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #17 (permalink)  
Old 22-04-2007, 22:54
DavidAllen's Avatar
Premium Member
 
Join Date: Jan 2007
Location: Amersham
Posts: 346
Send a message via MSN to DavidAllen Send a message via Skype™ to DavidAllen
Default No joy

I did that (changed the password from cpanel/whm) and still get the same error as Chris
Reply With Quote
  #18 (permalink)  
Old 22-04-2007, 22:59
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Changed the password. Still no effect. Have tried from two separate machines.

Email is chris.mcquillan @ scifiheaven.net

Cheers
Reply With Quote
  #19 (permalink)  
Old 22-04-2007, 23:48
Junior Member
 
Join Date: Apr 2007
Posts: 15
Default

Problem seems to have been rectified.

Thank you for your help.

Best,
Chris
Reply With Quote
  #20 (permalink)  
Old 23-04-2007, 16:58
Brian's Avatar
Premium Member
 
Join Date: Nov 2005
Location: New Mexico
Posts: 683
Default

My last few problems have been the same David. I got an email from Google saying i was removed from the search engine due to URL's in the source code. I checked, and low and behold there was tonnes of the usual porn, viaga etc etc in my source code. I have been trying to reupload my HTML pages daily as a result, untill EUK can guarentee that this bout of attacks is over.

However, they did mess up my Coppermine gallery and EUK have been great in restoring it twice. In my gallery/albums/ directory there are tonnes of anal fisting yada yada folders there that when i deleted one of em, the whole website hosting borked up. EUK has done pretty good in regards to this and ill open a ticket about it if its not fixed.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 19:14.

 

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

VPS Hosting
VPS Hosting plans

Dedicated Server Hosting
Dedicated Server plans

Business Web Hosting
100% uptime Hosting

Cpanel Hosting
cPanel Shared Hosting

Reseller Hosting
Reseller Web Hosting

Windows Hosting
Windows Shared Hosting

Windows VPS

Windows VPS Hosting

Semi Dedicated Servers
Semi-Dedicated Hosting

Dedicated Server Mirroring
Dedicated Server Mirroring

Webhosting Knowledgebase
Frequently asked Questions

Web Hosting Blog
eUKhost Blog

Web Hosting Support
Support Helpdesk

UK Data Center
eUKhost Datacenter

Web Hosting Forum
eUKhost Forum

Support Tutorials
Online Flash Tutorials

Offsite Back-up Plans
Remote Backup Service

Customer Testimonials
eUK Customer Testimonials


knowledgebase articles

eUKhost.com Services

Pre-Sales Questions
Pre-sales FAQ's

Domain Names
Domain registration FAQ's

cPanel Hosting
cPanel Hosting FAQ's

Windows Web Hosting
Plesk Control Panel

Reseller Hosting
Reseller Hosting FAQ's

VPS Hosting
Virtual Private Server

Semi-Dedicated Servers
Semi-Dedicated FAQ's

Dedicated Servers
Dedicated Server Hosting


popular blog categories


Web Hosting
Website Hosting articles

UK Web Hosting
UK Hosting articles

Dedicated Server Hosting
Dedicated Server guidelines

VPS Hosting
VPS hosting articles

cPanel Hosting
cPanel Hosting articles

Linux Operating System
Linux Operating techniques

Windows Web Hosting
Windows plesk articles