By venkat-rk on
All the drupal sites on my reseller account with Site5 have been hacked. Take a look:
www.rkvweb.com: drupal-4.7.2
www.edchild.org: drupal-4.7.2
www.kcrds.org.in: drupal-4.7.2 (also test sites on 5 subdomains)
www.ciosa.org.in: drupal-4.6.5 (also test sites on about 4 subdomains)
I had scrupulously applied all the security updates. I think this is the last straw for many of clients.
Is there a way out? I am not even sure I can use the backup dbs now.
Comments
The cpanel of all the sites
The cpanel of all the sites of my reseller account have also been hacked. As has also Web Host Manager, the main interface for reseller accounts to add, delete accounts etc. I think the database server for the server I am on has been compromised as I can access the file system but not login to my database.
And, I am not the only one: http://forums.site5.com/showthread.php?t=11314
Customer service responded by pointing me to this post, but they are not owning up to the problem:
http://forums.site5.com/showthread.php?t=11313
More third-rate service from
More third-rate service from Site5. Sadly, my association with them doesn't seem to be working well. I really thought they had improved in the last month, and now this.
Having their custom WHM and cpanel hacked is truly mind boggling. I believe it shows major security holes in their software development. Fortunately, the hackers don't seem to have done anything else. Can you imagine what would be the situation if they had destroyed all the files and folders in each account? Or if someone ran ecommerce sites?
Don't you find it striking
Don't you find it striking that on these superficially "socialist hacker" pages there is a set of links supplied by Claria Corp, née Gator ?
A script links to http ://dist. belnk. com/4/placement/1390/ and, per www. belnk. com: "BehaviorLinkSM, a behaviorally targeted advertising network from Claria Corporation. The BehaviorLink network works with publishers and advertisers to deliver behaviorally targeted ads eliminating wasted impressions and obtaining a higher return on their online advertising investment."
Looks actually more like deceitful business practices than "traditional" hacking, does it not ? Maybe Claria should be warned their ads are being placed by alleged hackers ?
Thanks for the concern. I
Thanks for the concern. I didn't really see or click on any of the links on the hacked pages.
Meanwhile, it seems Site5 has acknowledged there was a hole in the kernel through which this happened and were working to fix it.
The following threads, while they last, (Site5 has recently acquired the thoroughly endearing and benevolent habit of deleting forums threads criticising their service) are most educative:
http://forums.site5.com/showthread.php?t=11319
http://forums.site5.com/showthread.php?t=11321
http://forums.site5.com/showthread.php?t=11315
http://forums.site5.com/showthread.php?t=11314
Apparently, some of their other servers got hacked last week, but they were slow to react.
Site 5 has closed the thread
I expected this. I was logged in and I tried to add another comment to the thread, but I was logged out when I submitted it and got a message it had been closed.
But, I copied the whole thread (minus the last two comments) into a word document as a record.
And, guess what- Todd Mitchell, the COO of Site5 has gone in and removed the following comment quoted by a user from another forum:
In its place, he has put in a statement saying the information is inaccurate. See comment #18 of http://forums.site5.com/showthread.php?t=11319
This makes it a downright lie, in my opinion as all those sites are still hacked. It's been 12 hours now. Surely, no hosting company needs 12 hours for changing the primary drive of a server?
Site5 are alienating their customers. I think they have lost their head.
Wow, that's pretty bad.
What's up with this...
Would like to think that 4.7.2 was a little more secure???
Not drupal
No, nothing to do with drupal. Site5 is running a badly configured/customised kernel.
Sorry to hear it...
...but glad to hear it in a way, too.
Maybe it's vps time for you. Can recommend Liquidweb if you go that way.
Political Physics
Thanks for the
Thanks for the recommendation. My account with Site5 has another 3 months and it looks like I need to think beyond shared hosting.
Bluehost
Try out Bluehost (affiliate link) if you're thinking of changing providers. They rock!
I use them myself, and i'm very happy with their service, support and uptime....
(Yes, I am an affiliate... but only because I like the service they offer... Can't see myself being an affiliate of a product I don't like and don't use myself..)
I'm on bluehost myself.
I'm on bluehost myself. Service is excellent but they are having problems with keeping their servers up. Half their systems went without backup generators causing a lot of problems. They are working on it but I wouldn't recommend them for the time being.
They like deleting posts in their forums too. Nothing new here..
–joon
http://www.dvessel.com
Is that true?? Are they
Is that true??
Are they really also deleting posts from their forums?
That is really disappointing to hear!
It seems no one can stand
It seems no one can stand even fair criticism.
The situation with Site5 is really ridiculous because they have a supposedly customer-to-customer forum for resellers, but I can't post service issues there (can't even ask another customer if the server is down, more or less), have to mail customer care for answers when an outage happens and sit and wait for almost a day until I hear from them, as it happened last weekend. Now, how crazy is that:(
Thank god these hackers were benign. If they had gone about actually deleting files and dbs instead of merely replacing the index.php files, I don't know what would have happened.
The relative benevolence of the hackers plus Site5 backups, plus my own backups saved the day at least for me.
Sorry for the late reply but
Sorry for the late reply but Bluehost is behaving properly now. My site's been up for a month straight now with zero downtime. These things happen. Still not happy about them not being able to take criticism but overall I'm happy with them.
Now only if Dreamhost was more reliable with better performance. Their attitude and ability to communicate is beyond any other.
–joon
http://www.dvessel.com
Thanks. I have another
Thanks. I have another couple of months to go before my reseller account expires so I will have to make a decision pretty soon.
Keep in mind that Bluehost
Keep in mind that Bluehost doesn't provide reseller accounts. It's basically one size fits all with the ability to pay for added features. And I wouldn't run more than one site off a single account if it's high traffic. There's a 20% cpu limit over a 3 minute period -per account. Exceed that and the site goes off line for a few minutes. They do run quad Xeons so it's usually not a problem. Really depends on traffic and how heavy the drupal install is. Turning on cache obviously changes the equation though.
Good luck.
–joon
http://www.dvessel.com
If you have a high traffic
If you have a high traffic website, you might be interested in their new "high-cpu" offer.
An email I got from bluehost recently states:
I'm actually leaving them. I
I'm actually leaving them. I was questioning Heaton (CEO) on the normal plan in their forum. He basically couldn't take it and suggested I leave. Their $6.95 plan had its' CPU cap altered so I asked why. I wasn't being rude about it (at first), just wanted an answer. His response was that anything beyond a 60 second time frame for measuring the cap would break any shared server. No details about it.. Heaton would remind me that "I don't get it" when he wouldn't give me anything to get. Humorous to say the least. My site was working just fine with the old quota.. It was a take it or leave it attitude so I left.
If your curious, go to their forum and search for "CPU quota" and you'll find it. I don't want to link to it since he'll just end up deleting it if he notices any direct traffic.
Time for a new host.
–joon
http://www.dvessel.com
A pity
I just don't get it why hosting companies will not provide details of why certain things happen the way they do. You would think this is the way to convince customers, but apparently not. But I suppose hosting companies aren't any different from other businesses and we all know customer service can often be an issue.
I remember the CEO of Site5 going hammer and tongs on webhostingtalk.com at someone who wanted resolution on a tricky issue. It showed him in a very bad light and many customers openly said so. That isn't good publicity, is it?
Thanks for sharing this.
It was the CEO who gave out
It was the CEO who gave out the new capping rules. 30 seconds of CPU time within a 60 second timeframe and he gives it out when the new plan is rolled out. Shortly before, there were a couple of threads on people hitting the cap with no change in their site. I mean, they are all obviously related. He initially put the information out there but any sort of explanation was out of the question.
The irritating thing is that he tried to play it both ways when he obviously couldn't. Letting us know was good and it made them look like an open host but they weren't willing to go the whole way.
–joon
http://www.dvessel.com
Exceed CPU quota
I have this problem. I am using HostMonster, a sister project of BlueHost. Try whois their domain, you will see they are the same company. Yes, forget about them saying unlimited domain and 999gig bandwidth. If each of your sites grow that large, it is going to exceed CPU quota and keep getting suspended. This is my experience.
I do not have really very high traffic, but I guess I have some inefficient scripts running, my site always exceed CPU quota. It is quite frustrating.
I guess I need a way, or my site will never grow anymore.
Check out NetworkRedux.com.
Check out NetworkRedux.com. I have reseller account with them to handle all my websites. They have great customer service.
Thanks! The more choices I
Thanks! The more choices I have the better, especially since Site5 have quietly pulled the plug on their reseller service.
Another option--total choice
Another option--total choice hosting. They seem to be fanatical about security. I don't have a reseller account, but i have three different shared accounts. So far they've been excellent for the year I've used them. And two months ago, they doubled my space and bandwidth without charging any more...Can't beat the price too.
The owner also posts in the forums all the time and posted on a thread I started that was a suggestion for improvement. He personally jumps all over any of his tech people not offering good customer service. Also, they don't do affiliates so I also am recommending only based on my own experience.
http://www.totalchoicehosting.com
www.robcomm.net
Thanks, jivyb:-)
Thanks, jivyb:-)
especially since Site5 have
To be fair to Site5, they are allowing resellers to renew their plans and even upgrade. See the first sticky on this page: http://forums.site5.com/forumdisplay.php?f=68
I will probably stick with Site5 for low traffic and personal sites.
Take a look at Parcom.net
I've been with Parcom.net a few months. I'm pretty happy with them. I have no incentive to recommend them other than my satisfaction. Their prices seem quite reasonable. The owner is involved and there is a private forum for customers.
The owner seems very competent and responds to forum questions all the time. I wonder about the censorship aspect you mentioned regarding your negative comments being deleted. I've seen negative comments in Parcom's forums and they weren't deleted. The owner responded in a very cordial manner and never "took the bait". But I do wonder about what people's rights are, at least in regards to content on their own web sites.
Parcom doesn't allow adult content on their servers (fine with me). They also don't want customers using their server space for non-site related files like huge backup files, et cetera. It was mentioned that folders not linked to a site's home page are frowned upon. I have a few directories not linked to my home page—site backup folders and such—and no one from Parcom has complained to me about them.
They let it be known that customer sites are periodically scanned to ensure customers aren't running a 'warez site or doing other misdeeds. I'm glad for the vigilance, but it makes me just a little queasy.
Parcom uses Windows 2003 servers, so that might be a concern for you. I can't run cron jobs so I use poormanscron. I have no shell access to the server that I know of. I had a Linux host before where—theoretically—I could do more, but Parcom's servers are much faster, ticket response time is shorter (very fast), and the company is far more pleasant doing business with. Finally, they cost less than half of what my Linux host cost.
If they were hacked, I believe they'd inform customers immediately. The impression I get from their whole operation is that their people have top-shelf ethical values. I couldn't find the post, but I thought I'd seen an account of an SQL or database server attack that struck them in '05. If I find it I'll update my post.
Just my two cents.
PS - you can type your web address in at www.dnsreport.com and it'll tell you interesting stuff about your host's DNS servers. My previous host had some DNS configuration errors, my new host Parcom has zero errors.
Thanks!
Awfully nice of you to write such a detailed post. I can see you are having a very positive experience:-)
I like the fact that dissenters are not gagged and that adult sites aren't hosted- the last thing I want is someone blocking my email because my site has an IP address in the same range or close to sites that host adult content. Happens with quite a few hosts, I would think. Besides, I have strong personal reservations about hosting on companies that allow adult content- this is why I didn't go for trkhosting.com, who are excellent otherwise.
The Windows hosting is a bit of a dampener for me, but it's certainly worth checking out.
Thanks again.
bit of a dampener
…bit of a dampener for me,
Yeah, me too. I went with them mostly for their low price, plus I had a bit of curiosity about Windows-based hosting, which I've never used before. So far, it's working out for me. When I have more money I'll get a second account somewhere else, definitely a Linux host, to cover both sides. It's just my own site, I don't have clients.
I don't like their control panel too much (shoot, I don't like any host control panel much. I use dial-up service and they all seem slow), and I had to delete an .htaccess file here and there, but no real problems to speak of. I'd like to have a real cron, though. Most of my problems are my own brain limitations, heh.
Wicked site!
<strike>Thanks for that link, I can now see how shonky my clients current web company are in glorious detail, splendid! :-)</strike>Whoops, scratch that! Just followed up the wrong post! duh!
r0g
To be fair, Drupal was not
To be fair, Drupal was not hacked. Your site was hacked, and once they have access to your server and databases, there is pretty much nothing you can do. They can open all the files and find the passwords once they have root access to your server. This would have happened with any software. Drupal security is top notch, this was not a problem with Drupal.
True, but I never said
True, but I never said Drupal was hacked.
EDIT: See http://drupal.org/node/73937#comment-137447
updated subject for you.
-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide -|- Black Mountain
-Steven Peck
---------
Test site, always start with a test site.
Drupal Best Practices Guide
Thank you, Sepeck. That will
Thank you, Sepeck. That will teach me to pay more attention to my subject lines:-)