UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Reseller Hosting

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #21 (permalink)  
Old 31-08-2008, 19:50
military-world.net's Avatar
Junior Member
 
Join Date: Sep 2007
Location: Cardiff Wales
Posts: 29
Default

Quote:
Originally Posted by Eidolon View Post
I promptly changed back to my alphanumeric password.

I would adjust it slightly but unfortunately my ISP (Virigin) has been denying me access to my sites hosted with eukhost since late Firday night. Anyone else using Virgin ISP and having connection problems?
About year mate been like this!!!!.....Internet Explorer cannot display the webpage..About 2 times day...Or 10000000000000s times day
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #22 (permalink)  
Old 31-08-2008, 20:37
eUK-Martin's Avatar
Windows System Administrator
 
Join Date: Nov 2005
Location: Earth
Posts: 457
Default

Quote:
Originally Posted by _Chris_ View Post
As mentioned before, my 100% strong passwords were changed ?
We have had a long list of users therefore to avoid the time involved in process to differentiate between the users that had weak or strong password we decided to change password of all users.
Quote:
Originally Posted by _Chris_ View Post
What time were the passwords reset and what time were the emails sent to let us know ?
There were 2 teams working on this task.. 1st team were resetting the passwords and after completing 1 complete server they forwarded the list of users and passwords to 2nd team.. who updated the password in Billing software and resent the welcome email. The entire process took about 24 hours to complete (between 29th Aug & 30th Aug) hence it would we very difficult to let you know the exact time of when was the password reset and sent.
__________________
Martin
Windows System Admin.


Windows VPS Hosting - Windows Dedicated Server - Web Hosting Tutorials

Email :: windows @ eUKhost.com AND support @ eUKhost.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #23 (permalink)  
Old 31-08-2008, 21:40
Daniel's Avatar
Got root?
 
Join Date: Aug 2008
Location: England, UK
Posts: 136
Send a message via MSN to Daniel Send a message via Skype™ to Daniel
Default

Virgin appear to have a bad link from what it seems. But what would you expect from the supposed "Mother of all Broadband"?
__________________
Dan Miller
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #24 (permalink)  
Old 01-09-2008, 08:11
new member
 
Join Date: Jul 2007
Posts: 8
Default

First I have heard of this is when 2 customers contacted me to tell me they could no longer login using their passwords. No email from EUK to any of my email accounts (and no I haven't changed my billing email at all).

If you've reset the passwords to all my clients accounts then how come I can still login to my reseller account with my original password?

J
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #25 (permalink)  
Old 01-09-2008, 08:24
Member
 
Join Date: Feb 2008
Posts: 88
Default

Quote:
Originally Posted by eUK-Martin View Post
We have had a long list of users therefore to avoid the time involved in process to differentiate between the users that had weak or strong password we decided to change password of all users.

There were 2 teams working on this task.. 1st team were resetting the passwords and after completing 1 complete server they forwarded the list of users and passwords to 2nd team.. who updated the password in Billing software and resent the welcome email. The entire process took about 24 hours to complete (between 29th Aug & 30th Aug) hence it would we very difficult to let you know the exact time of when was the password reset and sent.
Thanks Martin, those answers are appreciated - shame it had to take a few repeats of the same questions though ! It makes for happier customers when questions are not ignored !

For one moment Martin, can you please just imagine our frustration, when we laboriously (and it isn't a quick process for multiple domains), changed all 40+ of our domains with you, about a week ago, to ensure that they all had 100% strong passwords and then a few days later, they are changed again ! !

Then, not to be told until many hours after the event, and then to receive a very unhelpful reply from your support, to say that, if I want to change the password to something different, just log into your whm ? ? To change the password to a new one, you need to know the existing one ! !

So, it would be more helpful, if you don't change the passwords for the responsible people who have already changed their passwords to 100% strong, and more helpful emails in response to the problem.

Chris.

Last edited by _Chris_; 01-09-2008 at 09:18.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #26 (permalink)  
Old 01-09-2008, 14:22
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,773
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com Send a message via Skype™ to eUKhost.com
Default

Quote:
Originally Posted by Jaselpool View Post
First I have heard of this is when 2 customers contacted me to tell me they could no longer login using their passwords. No email from EUK to any of my email accounts (and no I haven't changed my billing email at all).

If you've reset the passwords to all my clients accounts then how come I can still login to my reseller account with my original password?

J
Passowrds were changed for only those accounts which were on list of the Spanish hackers. If your main reseller account username was not on their list then there was no need for us to change your password.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #27 (permalink)  
Old 02-09-2008, 17:42
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 5,611
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Just for future note for the eUKhost team: If my account details are ever on any list of spanish hackers or any other hacking team - please please please please please immidiately change my password even if you cant notify my beforehand.

I'd rather stay secure than try and clean up the mess of an injected site - its happened once before around a couple of years ago and that was enough. The site was that messed up I had to delete it all and reupload a backup of it but unfortunately it was over a month old so I lost quite a lot of work and user data .
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
http://djdavid.dpscomputing.com (My DJ Website) - Updated for Christmas 08!
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website) - Temporarily Unavailable .
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #28 (permalink)  
Old 02-09-2008, 20:31
Member
 
Join Date: Feb 2008
Posts: 88
Thumbs down

Quote:
Originally Posted by DPS Computing View Post
Just for future note for the eUKhost team: If my account details are ever on any list of spanish hackers or any other hacking team - please please please please please immidiately change my password even if you cant notify my beforehand.

I'd rather stay secure than try and clean up the mess of an injected site - its happened once before around a couple of years ago and that was enough. The site was that messed up I had to delete it all and reupload a backup of it but unfortunately it was over a month old so I lost quite a lot of work and user data .
Yep, it's always a big mess after someones hacked into your site, we've been through it a couple of times - but no-ones asking eukhost to let us know beforehand - we're just asking that they let us know about the passwords changing for our websites as soon as possible afterwards - not many hours later !

Security and letting us know, are not mutually exclusive !

Anyway, time to move on now.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #29 (permalink)  
Old 02-09-2008, 22:40
eUK-Martin's Avatar
Windows System Administrator
 
Join Date: Nov 2005
Location: Earth
Posts: 457
Default

Yes, we very much understand your frustration but we tried our level best to get the sites secured.

I think the problem happened because it were all humans who were involved in getting the password reset and resent to our clients. We will make a note of this and try to get a script integrated with our Billing system to send emails so that there are no human errors involved. I think we will need to concern this with our R&D chief. We will surely get better with this next time.

Thank you once again for your patients and co-operation.
__________________
Martin
Windows System Admin.


Windows VPS Hosting - Windows Dedicated Server - Web Hosting Tutorials

Email :: windows @ eUKhost.com AND support @ eUKhost.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #30 (permalink)  
Old 03-09-2008, 07:54
Member
 
Join Date: Feb 2008
Posts: 88
Default

You trying to secure the websites has never been the issue Martin - how and when you let your customers know about the changes that affect them IS.

Apart from that, many thanks for that excellent response Martin, it shows you care about how you treat us!

Chris.

Last edited by _Chris_; 03-09-2008 at 07:59.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #31 (permalink)  
Old 03-09-2008, 09:08
jc8654's Avatar
Moderator
 
Join Date: May 2007
Location: Santa Barbara, CA, USA
Posts: 1,438
Send a message via MSN to jc8654
Default

Quote:
Originally Posted by _Chris_ View Post
Yep, it's always a big mess after someones hacked into your site, we've been through it a couple of times - but no-ones asking eukhost to let us know beforehand - we're just asking that they let us know about the passwords changing for our websites as soon as possible afterwards - not many hours later !

Security and letting us know, are not mutually exclusive !

Anyway, time to move on now.
Surely in that case, if eUK had to change 1000 passwords they should be doing that before resending passwords. As you said above, it's a pain if your site gets hacked so if you were the 999 person in the list of accounts they needed to change you'd want them to get down the list as fast as possible to minimise the threat of hacking during that time? And surely that means get as many support hands on it as possible?

I agree that yes, it may have been an inconvenience not being able to log in to things but to me the top priority would be to get all the passwords changed and then do the emailing.

Just to point out in this, was it just the main account passwords that needed resetting? If so, can that not just be done from WHMCS and then click on the resend welcome details info again with the new password? If that was the case then it may have been easier to do it at the time but if it's all ftp passwords on the server then what I've just said in this paragraph is a pointless comment!
__________________
Jonathan Crass
Joint Partner in Checker Design

North East Website design
UK based monitoring
Cheap UK Web Hosting

Save Jodrell Bank: www.savejodrellbank.org.uk

eUKhost Forum Moderator
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #32 (permalink)  
Old 03-09-2008, 11:16
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,773
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com Send a message via Skype™ to eUKhost.com
Default

Our CTO had to reset all passwords in one go using some scripts. He then assigned task to his team members to change passwords once again and resend to customers. One should not question his potential as he does fantastic job in managing his team and his awareness has prevented us from a major mishap.

We've had previous experience of all such stupid things done by Hackers and crackers and we know how to keep our servers safe. We are taking legal action against the spanish proxy provider whose IPs were used for this FTP based injection.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #33 (permalink)  
Old 03-09-2008, 12:33
Member
 
Join Date: Feb 2008
Posts: 88
Default

Quote:
Originally Posted by jc8654 View Post
Surely in that case, if eUK had to change 1000 passwords they should be doing that before resending passwords. As you said above, it's a pain if your site gets hacked so if you were the 999 person in the list of accounts they needed to change you'd want them to get down the list as fast as possible to minimise the threat of hacking during that time? And surely that means get as many support hands on it as possible?

I agree that yes, it may have been an inconvenience not being able to log in to things but to me the top priority would be to get all the passwords changed and then do the emailing.
It's never been in any doubt that security is always the main priority, but emailing the clients of eukhost, should be done very soon after the clients own passwords have changed, not many hours later.

From Martins post above :

"We will make a note of this and try to get a script integrated with our Billing system to send emails so that there are no human errors involved. I think we will need to concern this with our R&D chief. We will surely get better with this next time."

On that basis, I'm happy to assume that things will be better handled next time.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 11:54.

 

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

VPS Hosting
VPS Hosting plans

Dedicated Server Hosting
Dedicated Server plans

Business Web Hosting
100% uptime Hosting

Cpanel Hosting
cPanel Shared Hosting

Reseller Hosting
Reseller Web Hosting

Windows Hosting
Windows Shared Hosting

Windows VPS

Windows VPS Hosting

Semi Dedicated Servers
Semi-Dedicated Hosting

Dedicated Server Mirroring
Dedicated Server Mirroring

Webhosting Knowledgebase
Frequently asked Questions

Web Hosting Blog
eUKhost Blog

Web Hosting Support
Support Helpdesk

UK Data Center
eUKhost Datacenter

Web Hosting Forum
eUKhost Forum

Support Tutorials
Online Flash Tutorials

Offsite Back-up Plans
Remote Backup Service

Customer Testimonials
eUK Customer Testimonials


knowledgebase articles

eUKhost.com Services

Pre-Sales Questions
Pre-sales FAQ's

Domain Names
Domain registration FAQ's

cPanel Hosting
cPanel Hosting FAQ's

Windows Web Hosting
Plesk Control Panel

Reseller Hosting
Reseller Hosting FAQ's

VPS Hosting
Virtual Private Server

Semi-Dedicated Servers
Semi-Dedicated FAQ's

Dedicated Servers
Dedicated Server Hosting


popular blog categories


Web Hosting
Website Hosting articles

UK Web Hosting
UK Hosting articles

Dedicated Server Hosting
Dedicated Server guidelines

VPS Hosting
VPS hosting articles

cPanel Hosting
cPanel Hosting articles

Linux Operating System
Linux Operating techniques

Windows Web Hosting
Windows plesk articles

Web Hosting
Web Hosting Service