Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 24, 2012, 08:56:17 AM

Pages: [1]   Go Down
  Print  
Author Topic: dpoon's site security issues  (Read 2615 times)
dpoon
Space Explorer
***
Offline Offline

Posts: 7


« on: October 13, 2009, 12:14:49 AM »

I am facing the same problem. I think my cpanel is being hacked by brute force. There's no way someone can do this. Does lunarpages have any measure against brute force attack? i..e a machine try every password combination. Eventually they'll get it unless there's measures to prevent repeat trial of different passwords by machines. This is very annoying.
Logged
dpoon
Space Explorer
***
Offline Offline

Posts: 7


« Reply #1 on: October 14, 2009, 10:13:56 PM »

Yes my site was hacked on Aug 11th, almost the same time as yours and since I have not FTP anything for over a year, I know for a fact there's no way the password would have been capture by malware or other viruses. I use Symantec Endpoint Protection v11 and it's been extremely good with any threats. And the same case as you I found that my site was compromised with code injected to my blogs through FTP. 2800 FTP requests went thru the same time from various IP location. I got it all cleaned though.

Now I know there's all these talks and I went thru the whole forums about this kind of infection, how it could be ME as the source of problem. And I can tell you it's all *. All the talsk about XSS or SQL Injection *. Why? Cos all of these will only touch one blog, not 5 blogs at once and certainly not 2800 files all in one go, and not via FTP. Lunarpages needs to own up to their end of responsibility too. How can I not be FTP'ing anything for so long to have my password exposed at any level??? In fact, it's much easier to have malware or keylogger capture my blog's password and deface my posts then to get the FTP password. Now once they have the FTP password, no security (e.g. upgrading to the latest version or anything like that) can help. The hacker could do anything to your site.

My conclusion is some sort of brute force attack happened. It just happened to CPANEL and continue to test and the password was 7 characters at the time so probably not need much to hack this one. You know, the worst thing is lunarpages' password doesn't even allow special characters, only A-Z 0-9, how easy is it to hack this, very easy. So I read that one admin advice you to type a 80 character long password and that'll overcome not able to use special character and will take forever to hack. Maybe. We'll see.

So anyway, to the person who posted this, can you let me know your lunarpages server name and maybe we can figure out if we happened to be on the same server?
« Last Edit: October 15, 2009, 04:54:15 AM by Mitch » Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12837


WWW
« Reply #2 on: October 15, 2009, 05:00:16 AM »

I dpoon, I went ahead and merged your two replies from older/unrelated posts into this one so you can have your own thread to discuss your issues. 

Your best source for information would be to talk directly with the server admins and support team members that are handling your ticket.  They'll be more than happy to tell you all the can about your account security issues, and what you can do to secure your web site better.

Hope that helps!
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
russellg
Trekkie
**
Offline Offline

Posts: 10


« Reply #3 on: October 15, 2009, 06:05:19 AM »

Daniel, my server is "naos".  And you're right, it sure sounds like something else is going on, if you haven't used FTP in over a year.  That was the case for my friend as well -- hadn't used FTP in months, but someone logged in with his FTP account around the same time they hit mine.  And in both of our cases, it was the primary FTP account, which just happens to be the same username and password as the LP account.  I think all of this is more than a coincidence.

Mitch, the thread he was replying to was the one I started about this.  Yes, it was older, but hardly unrelated, since he had the same problem at the same time.  I think it would have been better left as it was.  For anyone wanting to read the original thread, it was here:  Was your site hacked at 3am on August 12th?

Russell
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12837


WWW
« Reply #4 on: October 15, 2009, 06:25:02 AM »

russellg, thanks for providing dpoon with more information about your situation.  I have no issues with discussion about finding the cause or root of an issue, and as I mentioned before - if you contact the server admins or support techs that worked on your issue they will be happy to supply you with as much information as possible.  However, there are no grand conspiracy theories or things you are not being told because they are kept secret.  Trying to start rumors or debates on those false claims, is not going to help your cause any, because there are none to be had. 
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: