Community Forums

Important Notice:

Two sections of this forum are available only to registered customers. In order to receive access to the Customer Forums and ResellerCentral Forums, you must first register on these forums or login to your existing forum account. If you are an existing HostNine customer, be sure to register using the email address on file for your billing profile.

Go Back   HostNine Community Forums > H9 Customer Forums > Reseller Hosting

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-17-2009, 10:07 AM
dst dst is offline
Junior Guru Wannabe
 
Join Date: Jun 2008
Posts: 73
Default Probelm being a reseller.

Since I have joined hostnine I have found that my joomla sites get hacked. I doubt there is a connection with the server per se but when I ask hostnine to restore the site using the backup - this never happens - ever.

Can anyone suggest a solution other than 1) leave hostnine or joomla?
Reply With Quote
  #2  
Old 06-17-2009, 10:16 AM
dst dst is offline
Junior Guru Wannabe
 
Join Date: Jun 2008
Posts: 73
Default

I have been told the backups dont work unless I catch the hack and get in touch with Hostnine in less than 24 hours.

I cannot control what sites I backup, how and when so I have my own copies from a central location using reseller central, are their alternative interfaces of software that will let me do this?

thanks
Reply With Quote
  #3  
Old 06-17-2009, 11:54 AM
zanass zanass is offline
Permanently Banned
 
Join Date: Mar 2007
Location: Wisconsin-GO PACKERS
Posts: 617
Default Know what your clients have hosted

Quote:
Originally Posted by dst View Post
Since I have joined hostnine I have found that my joomla sites get hacked. I doubt there is a connection with the server per se but when I ask hostnine to restore the site using the backup - this never happens - ever.

Can anyone suggest a solution other than 1) leave hostnine or joomla?
If your Joomla sites are getting hacked why use them, I don't blame H9, when sites like that get hacked it blacklists the server because they send out spam. Know what your clients have hosted, tell them you have a ZERO tolerance policy, if their sites get hacked, they are gone.

Just my 2 cents
Greg V
Reply With Quote
  #4  
Old 06-17-2009, 12:04 PM
H9Alex's Avatar
H9Alex H9Alex is offline
HostNine Support
 
Join Date: Jan 2007
Location: Jupiter
Posts: 1,148
Default

As stated in the ticket.


Keep all scripts up to date. And passwords good and secure.


This only happens when these things are not done. Plenty of users use these scripts and keep them up to date with out any issues.
__________________
Alex
Hostnine Support

*********Important Links************
Helpdesk: http://support.hostnine.com/
Blog: http://www.hostnine.com/blog/
Forums: http://forums.hostnine.com/
********************************
Reply With Quote
  #5  
Old 06-17-2009, 12:41 PM
H9NickH H9NickH is offline
Retired Staff
 
Join Date: Jul 2008
Location: Central New York
Posts: 401
Send a message via AIM to H9NickH
Default

Hello,

You should also realize that your security concerns are with Joomla, not us. They are the ones that continually release software with security flaws present in it. You may wish to consider a new software that takes a better approach in testing their software for security holes before releasing it.
Reply With Quote
  #6  
Old 03-07-2010, 03:52 PM
olivetreestudio olivetreestudio is offline
Newbie
 
Join Date: Nov 2009
Posts: 15
Default

I've been running several Joomla sites without being compromised for a couple of years now.

What you need to do is go through the security checklist.

Joomla, like all CMS's patch their software to cover up exploits.

I'm sorry to see HostNine people slamming Joomla, since every software has this issue. Plus the exploints they cover are usually things that cannot allow someone access to FTP/Administration features. It usually has to do with host configuration (which they cannot control). It also isn't fair to expect a host to change its configuration as they attempt to host a wide variety of sites.

Anyways, here is that list:

Security Checklist 7 - Joomla! Documentation
Reply With Quote
  #7  
Old 03-13-2010, 05:40 AM
PascM PascM is offline
Junior Guru Wannabe
 
Join Date: Mar 2009
Location: 127.0.0.1
Posts: 48
Send a message via MSN to PascM Send a message via Skype™ to PascM
Default

Well...in joomla 1.5.15 i don't know any site been hacked and to blame joomla.
Some times it's our fault since they hack the site with the ftp pass, which they probably have stolen from us.

I am hosting Joomla sites on H9 servers and so far i didn't have any problems.
Reply With Quote
  #8  
Old 03-27-2010, 03:29 PM
olivetreestudio olivetreestudio is offline
Newbie
 
Join Date: Nov 2009
Posts: 15
Default

You really need to go through the Security Checklist. I was hacked 1 time, now I go through this list every time, and so far, my sites have been untouched (on 2 different hosts, including H9)

Category:Security Checklist - Joomla! Documentation
Reply With Quote
  #9  
Old 03-28-2010, 03:00 AM
badjerzeeboy badjerzeeboy is offline
Newbie
 
Join Date: Jul 2009
Posts: 28
Post tips to optimize Joomla! security

Quote:
Originally Posted by zanass View Post
If your Joomla sites are getting hacked why use them, I don't blame H9, when sites like that get hacked it blacklists the server because they send out spam. Know what your clients have hosted, tell them you have a ZERO tolerance policy, if their sites get hacked, they are gone.

Just my 2 cents
Greg V

Change the default database prefix (jos_)

Most SQL injections that are written to hack a Joomla! website, try to retrieve data from the jos_users table. This way, they can retrieve the username and password from the super administrator of the website. Changing the default prefix into something random, will prevent (most / all) SQL injections.

You can set the database prefix when installing your Joomla! website.


Use the correct CHMOD for each folder and file

Setting files or folders to a CHMOD of 777 or 707 is only necessary when a script needs to write to that file or directory. All other files should have the following configuration:(I think h9 have something install on they server so you can use 755 without any problem not sure about this)

* PHP files: 644
* Config files: 666
* Other folders: 755

Delete leftover files

When you installed an extension that you didn't like, don't set the extension to unbublished. If you do, the vulnerable files will still be on your website. So simply use the un-install function to totally get rid of the extension.

Last edited by badjerzeeboy; 03-28-2010 at 03:03 AM.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 12:22 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

Host Nine

Our mission began in 2006. Thousands of awesome clients later, we are now one of the most popular hosters in the world.
Most of this is because of our fantastic support. Join us, you'll be glad you did - that's a given.