All the drupal sites on my reseller account with Site5 have been hacked. Take a look:

www.rkvweb.com: drupal-4.7.2
www.edchild.org: drupal-4.7.2
www.kcrds.org.in: drupal-4.7.2 (also test sites on 5 subdomains)
www.ciosa.org.in: drupal-4.6.5 (also test sites on about 4 subdomains)

I had scrupulously applied all the security updates. I think this is the last straw for many of clients.

Is there a way out? I am not even sure I can use the backup dbs now.

Comments

venkat-rk’s picture

The cpanel of all the sites of my reseller account have also been hacked. As has also Web Host Manager, the main interface for reseller accounts to add, delete accounts etc. I think the database server for the server I am on has been compromised as I can access the file system but not login to my database.

And, I am not the only one: http://forums.site5.com/showthread.php?t=11314

Customer service responded by pointing me to this post, but they are not owning up to the problem:
http://forums.site5.com/showthread.php?t=11313

venkat-rk’s picture

More third-rate service from Site5. Sadly, my association with them doesn't seem to be working well. I really thought they had improved in the last month, and now this.

Having their custom WHM and cpanel hacked is truly mind boggling. I believe it shows major security holes in their software development. Fortunately, the hackers don't seem to have done anything else. Can you imagine what would be the situation if they had destroyed all the files and folders in each account? Or if someone ran ecommerce sites?

fgm’s picture

Don't you find it striking that on these superficially "socialist hacker" pages there is a set of links supplied by Claria Corp, née Gator ?

A script links to http ://dist. belnk. com/4/placement/1390/ and, per www. belnk. com: "BehaviorLinkSM, a behaviorally targeted advertising network from Claria Corporation. The BehaviorLink network works with publishers and advertisers to deliver behaviorally targeted ads eliminating wasted impressions and obtaining a higher return on their online advertising investment."

Looks actually more like deceitful business practices than "traditional" hacking, does it not ? Maybe Claria should be warned their ads are being placed by alleged hackers ?

venkat-rk’s picture

Thanks for the concern. I didn't really see or click on any of the links on the hacked pages.

Meanwhile, it seems Site5 has acknowledged there was a hole in the kernel through which this happened and were working to fix it.

The following threads, while they last, (Site5 has recently acquired the thoroughly endearing and benevolent habit of deleting forums threads criticising their service) are most educative:

http://forums.site5.com/showthread.php?t=11319
http://forums.site5.com/showthread.php?t=11321
http://forums.site5.com/showthread.php?t=11315
http://forums.site5.com/showthread.php?t=11314

Apparently, some of their other servers got hacked last week, but they were slow to react.

venkat-rk’s picture

I expected this. I was logged in and I tried to add another comment to the thread, but I was logged out when I submitted it and got a message it had been closed.

But, I copied the whole thread (minus the last two comments) into a word document as a record.

And, guess what- Todd Mitchell, the COO of Site5 has gone in and removed the following comment quoted by a user from another forum:

Hi,

Yes the server was hacked there was a hole in the kernel we have since updated the kernel on all of our servers. Dryads it was the same thing so early this morning we replaced the kernel on our entire fleet.

--Robert Bush
System Administrator
Site5 Internet Solutions, Inc.
http://www.site5.com

In its place, he has put in a statement saying the information is inaccurate. See comment #18 of http://forums.site5.com/showthread.php?t=11319

This makes it a downright lie, in my opinion as all those sites are still hacked. It's been 12 hours now. Surely, no hosting company needs 12 hours for changing the primary drive of a server?

Site5 are alienating their customers. I think they have lost their head.

calebgilbert’s picture

What's up with this...

Would like to think that 4.7.2 was a little more secure???

venkat-rk’s picture

No, nothing to do with drupal. Site5 is running a badly configured/customised kernel.

calebgilbert’s picture

...but glad to hear it in a way, too.

Maybe it's vps time for you. Can recommend Liquidweb if you go that way.

Political Physics

venkat-rk’s picture

Thanks for the recommendation. My account with Site5 has another 3 months and it looks like I need to think beyond shared hosting.

jacauc’s picture

Try out Bluehost (affiliate link) if you're thinking of changing providers. They rock!
I use them myself, and i'm very happy with their service, support and uptime....

(Yes, I am an affiliate... but only because I like the service they offer... Can't see myself being an affiliate of a product I don't like and don't use myself..)

dvessel’s picture

I'm on bluehost myself. Service is excellent but they are having problems with keeping their servers up. Half their systems went without backup generators causing a lot of problems. They are working on it but I wouldn't recommend them for the time being.

They like deleting posts in their forums too. Nothing new here..

–joon
http://www.dvessel.com

jacauc’s picture

Is that true??
Are they really also deleting posts from their forums?

That is really disappointing to hear!

venkat-rk’s picture

It seems no one can stand even fair criticism.

The situation with Site5 is really ridiculous because they have a supposedly customer-to-customer forum for resellers, but I can't post service issues there (can't even ask another customer if the server is down, more or less), have to mail customer care for answers when an outage happens and sit and wait for almost a day until I hear from them, as it happened last weekend. Now, how crazy is that:(

Thank god these hackers were benign. If they had gone about actually deleting files and dbs instead of merely replacing the index.php files, I don't know what would have happened.

The relative benevolence of the hackers plus Site5 backups, plus my own backups saved the day at least for me.

dvessel’s picture

Sorry for the late reply but Bluehost is behaving properly now. My site's been up for a month straight now with zero downtime. These things happen. Still not happy about them not being able to take criticism but overall I'm happy with them.

Now only if Dreamhost was more reliable with better performance. Their attitude and ability to communicate is beyond any other.

–joon
http://www.dvessel.com

venkat-rk’s picture

Thanks. I have another couple of months to go before my reseller account expires so I will have to make a decision pretty soon.

dvessel’s picture

Keep in mind that Bluehost doesn't provide reseller accounts. It's basically one size fits all with the ability to pay for added features. And I wouldn't run more than one site off a single account if it's high traffic. There's a 20% cpu limit over a 3 minute period -per account. Exceed that and the site goes off line for a few minutes. They do run quad Xeons so it's usually not a problem. Really depends on traffic and how heavy the drupal install is. Turning on cache obviously changes the equation though.

Good luck.

–joon
http://www.dvessel.com

jacauc’s picture

If you have a high traffic website, you might be interested in their new "high-cpu" offer.

An email I got from bluehost recently states:

We have an announcement for those heavy users that have been
getting "CPU Exceeded" error messages. We have new servers
ready for those users that are built specifically with you in
mind. The MySQL performance is about double that of our current
system and we will only put approximately 80 users per server.
The current CPU limit is set at 30 seconds per user per minute
of CPU time (Out of a total of 240 seconds). The new server
will allow 90 seconds of CPU time per user per second. This means
your processes are allowed 3 times the amount they receive now
to finish. The cost of this service is $19.95 per month instead
of the regular $6.95 price. This service is not necessary for 95%
of our users, but the 5% that need it need it badly. We hope this
will help alleviate problems for these users. If you would like
your account to be upgraded to this new option please call support
directly at (888) 401-4678 and ask to be upgraded to the "high cpu"
plan.

dvessel’s picture

I'm actually leaving them. I was questioning Heaton (CEO) on the normal plan in their forum. He basically couldn't take it and suggested I leave. Their $6.95 plan had its' CPU cap altered so I asked why. I wasn't being rude about it (at first), just wanted an answer. His response was that anything beyond a 60 second time frame for measuring the cap would break any shared server. No details about it.. Heaton would remind me that "I don't get it" when he wouldn't give me anything to get. Humorous to say the least. My site was working just fine with the old quota.. It was a take it or leave it attitude so I left.

If your curious, go to their forum and search for "CPU quota" and you'll find it. I don't want to link to it since he'll just end up deleting it if he notices any direct traffic.

Time for a new host.

–joon
http://www.dvessel.com

venkat-rk’s picture

I just don't get it why hosting companies will not provide details of why certain things happen the way they do. You would think this is the way to convince customers, but apparently not. But I suppose hosting companies aren't any different from other businesses and we all know customer service can often be an issue.

I remember the CEO of Site5 going hammer and tongs on webhostingtalk.com at someone who wanted resolution on a tricky issue. It showed him in a very bad light and many customers openly said so. That isn't good publicity, is it?

Thanks for sharing this.

dvessel’s picture

It was the CEO who gave out the new capping rules. 30 seconds of CPU time within a 60 second timeframe and he gives it out when the new plan is rolled out. Shortly before, there were a couple of threads on people hitting the cap with no change in their site. I mean, they are all obviously related. He initially put the information out there but any sort of explanation was out of the question.

The irritating thing is that he tried to play it both ways when he obviously couldn't. Letting us know was good and it made them look like an open host but they weren't willing to go the whole way.

–joon
http://www.dvessel.com

gymosphere’s picture

I have this problem. I am using HostMonster, a sister project of BlueHost. Try whois their domain, you will see they are the same company. Yes, forget about them saying unlimited domain and 999gig bandwidth. If each of your sites grow that large, it is going to exceed CPU quota and keep getting suspended. This is my experience.

I do not have really very high traffic, but I guess I have some inefficient scripts running, my site always exceed CPU quota. It is quite frustrating.

I guess I need a way, or my site will never grow anymore.

.carey’s picture

Check out NetworkRedux.com. I have reseller account with them to handle all my websites. They have great customer service.

venkat-rk’s picture

Thanks! The more choices I have the better, especially since Site5 have quietly pulled the plug on their reseller service.

jivyb’s picture

Another option--total choice hosting. They seem to be fanatical about security. I don't have a reseller account, but i have three different shared accounts. So far they've been excellent for the year I've used them. And two months ago, they doubled my space and bandwidth without charging any more...Can't beat the price too.

The owner also posts in the forums all the time and posted on a thread I started that was a suggestion for improvement. He personally jumps all over any of his tech people not offering good customer service. Also, they don't do affiliates so I also am recommending only based on my own experience.

http://www.totalchoicehosting.com

www.robcomm.net

venkat-rk’s picture

Thanks, jivyb:-)

venkat-rk’s picture

especially since Site5 have quietly pulled the plug on their reseller service.

To be fair to Site5, they are allowing resellers to renew their plans and even upgrade. See the first sticky on this page: http://forums.site5.com/forumdisplay.php?f=68

I will probably stick with Site5 for low traffic and personal sites.

danny_8’s picture

I've been with Parcom.net a few months. I'm pretty happy with them. I have no incentive to recommend them other than my satisfaction. Their prices seem quite reasonable. The owner is involved and there is a private forum for customers.

The owner seems very competent and responds to forum questions all the time. I wonder about the censorship aspect you mentioned regarding your negative comments being deleted. I've seen negative comments in Parcom's forums and they weren't deleted. The owner responded in a very cordial manner and never "took the bait". But I do wonder about what people's rights are, at least in regards to content on their own web sites.

Parcom doesn't allow adult content on their servers (fine with me). They also don't want customers using their server space for non-site related files like huge backup files, et cetera. It was mentioned that folders not linked to a site's home page are frowned upon. I have a few directories not linked to my home page—site backup folders and such—and no one from Parcom has complained to me about them.

They let it be known that customer sites are periodically scanned to ensure customers aren't running a 'warez site or doing other misdeeds. I'm glad for the vigilance, but it makes me just a little queasy.

Parcom uses Windows 2003 servers, so that might be a concern for you. I can't run cron jobs so I use poormanscron. I have no shell access to the server that I know of. I had a Linux host before where—theoretically—I could do more, but Parcom's servers are much faster, ticket response time is shorter (very fast), and the company is far more pleasant doing business with. Finally, they cost less than half of what my Linux host cost.

If they were hacked, I believe they'd inform customers immediately. The impression I get from their whole operation is that their people have top-shelf ethical values. I couldn't find the post, but I thought I'd seen an account of an SQL or database server attack that struck them in '05. If I find it I'll update my post.

Just my two cents.

PS - you can type your web address in at www.dnsreport.com and it'll tell you interesting stuff about your host's DNS servers. My previous host had some DNS configuration errors, my new host Parcom has zero errors.

venkat-rk’s picture

Awfully nice of you to write such a detailed post. I can see you are having a very positive experience:-)

I like the fact that dissenters are not gagged and that adult sites aren't hosted- the last thing I want is someone blocking my email because my site has an IP address in the same range or close to sites that host adult content. Happens with quite a few hosts, I would think. Besides, I have strong personal reservations about hosting on companies that allow adult content- this is why I didn't go for trkhosting.com, who are excellent otherwise.

The Windows hosting is a bit of a dampener for me, but it's certainly worth checking out.

Thanks again.

danny_8’s picture

…bit of a dampener for me,

Yeah, me too. I went with them mostly for their low price, plus I had a bit of curiosity about Windows-based hosting, which I've never used before. So far, it's working out for me. When I have more money I'll get a second account somewhere else, definitely a Linux host, to cover both sides. It's just my own site, I don't have clients.

I don't like their control panel too much (shoot, I don't like any host control panel much. I use dial-up service and they all seem slow), and I had to delete an .htaccess file here and there, but no real problems to speak of. I'd like to have a real cron, though. Most of my problems are my own brain limitations, heh.

r0g’s picture

<strike>Thanks for that link, I can now see how shonky my clients current web company are in glorious detail, splendid! :-)</strike>

Whoops, scratch that! Just followed up the wrong post! duh!

r0g

freehunter’s picture

To be fair, Drupal was not hacked. Your site was hacked, and once they have access to your server and databases, there is pretty much nothing you can do. They can open all the files and find the passwords once they have root access to your server. This would have happened with any software. Drupal security is top notch, this was not a problem with Drupal.

venkat-rk’s picture

True, but I never said Drupal was hacked.

EDIT: See http://drupal.org/node/73937#comment-137447

sepeck’s picture

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide -|- Black Mountain

-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide

venkat-rk’s picture

Thank you, Sepeck. That will teach me to pay more attention to my subject lines:-)