Community Forums

Important Notice:

Two sections of this forum are available only to registered customers. In order to receive access to the Customer Forums and ResellerCentral Forums, you must first register on these forums or login to your existing forum account. If you are an existing HostNine customer, be sure to register using the email address on file for your billing profile.

Go Back   HostNine Community Forums > H9 Customer Forums > Reseller Hosting

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-22-2009, 05:30 AM
sulis sulis is offline
Newbie
 
Join Date: Aug 2009
Posts: 13
Unhappy Exploited Site!! Help

Today, I was really shocked, all my post from August 6th till today is gone.. and it affected all my blogs..

I have contact the support and got the reply that my cpanel account/blog account/mysql account has bad and insecure password (not sure which one of it).. it mention that I have used (123456) password which is vulnerable.. I obviously didn't use such lame combination, but maybe it did not strong enough.

My question, is it possible that this unsecured password can result some data get lost or broken?

Is it means that there someone has breach my account and make fun of it and just deleted some database for certain date and do it over and over again with another blog?

FYI, before this issue happen, my database is unreachable twice this week and it solved it self after couple of hours.. could it be a sign that there's an error on the database..?

I am very newbie about this thing and desperate to seek help from anybody that can explain to me about this EXPLOITED WEBSITE issue..

Any help will do..
Reply With Quote
  #2  
Old 08-22-2009, 11:22 PM
H9MattR
Guest
 
Posts: n/a
Default

Hello,

An unreachable database can happen for a variety of reasons.

1) Very, Very, Very high Load on the server (Very, very, very rare)
2) /var filling up quickly because of a website landing on Stumbleupon and that persons web logs getting slammed with data entries (possible cause, not too common, though)
3) Too many persistent MySQL connections coming from your user (the most likely cause)

When it comes to your exploited website, there are countless reasons as to why this had happened.

I remember working on your support ticket, and the password provided was definitely insecure -- could have been broken in a matter of moments with some Mod6 math.

Now, that being said, that may not even be the root cause of the exploit.

There are many different types -- To break your password would require quite a few computers attempting to try as our servers blacklist IP addresses if they fail an X amount of times concurrently in under an X amount of time.

It's veyr likely that there was a vulnerability in wordpress that someone has exploited.

Regardless of which version you are running -- if it's the most recent version or not -- people will find a way to break into it. Especially since Wordpress is everywhere. Absolutely everywhere.

That, and it's web based and uses POST and GET information ,but that's another story.

The best way to keep your site secure is to use a secure password, keep your scripts as up to date as possible, and to make sure that no one has access to the files except for you.

Thanks,
Matthew Rosenblatt
Reply With Quote
  #3  
Old 08-23-2009, 05:24 AM
sulis sulis is offline
Newbie
 
Join Date: Aug 2009
Posts: 13
Default

Just curious... is there anyone here experience the same problem like me? especially for user who host their website at node56 / IP 75.125.143.18

PS: thanks you Matt for the explanation
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sick of [[having my account exploited]] banai Shared Web Hosting 2 11-24-2009 06:45 PM
Exploited Sites H9Alex General Announcements 0 06-17-2009 03:49 PM


All times are GMT -5. The time now is 08:32 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.

Host Nine

Our mission began in 2006. Thousands of awesome clients later, we are now one of the most popular hosters in the world.
Most of this is because of our fantastic support. Join us, you'll be glad you did - that's a given.