Add to Favorites
Hosting Discussion
 

forgot password?


SPONSORED LINKS

Reply


Old
  Post #1 (permalink)   03-16-2007, 05:53 PM
HD Master
 
Join Date: Mar 2007
Location: B.C, Canada
Posts: 361

Status: Harry is offline
Anyone here ever had their server hacked or compromised? I've noticed there are a lot of servers being hacked these days. Not sure if it's due to people lacking updates for their software or just leaving ports and holes open. The one and only time I was ever hacked, happen't through IPB. We basically had to take it down and put up a vB
 
 
 


Old
  Post #2 (permalink)   03-19-2007, 07:35 PM
HD Amateur
 
Join Date: Jan 2007
Posts: 65

Status: Mabus is offline
I have heard of more servers being hacked through exploiting apache recently, aside from that more than likely they just did not have the proper security updates or firewall settings. Lack of monitoring a server can result in not being able to prevent someone exploiting the server before it happens also.
__________________
Peter | MabusHosting Staff
www.mabushosting.net - 100% uptime, affordable prices
www.vizzovps.com - VPS Control Panel
 
 
 


Old
  Post #3 (permalink)   03-20-2007, 05:34 PM
HD Master
 
Join Date: Mar 2007
Location: B.C, Canada
Posts: 361

Status: Harry is offline
I noticed my host hasn't updated any certificates or cpanel. It's things like this that make me want to leave hosts. I'd hate to have my files and databases compromised and in the hands of abusers/spammers.
 
 
 


Old
  Post #4 (permalink)   03-22-2007, 10:17 AM
HD Addict
 
Join Date: May 2006
Posts: 129

Status: alemcherry is offline
Do you have 100% managed services. Hosts are ideally not supposed to fool around with your software. I will prefer them to take care of the network and hardware issues.
 
 
 


Old
  Post #5 (permalink)   04-06-2007, 11:29 PM
HD Newbie
 
Join Date: Apr 2007
Posts: 31

Status: inworx is offline
Apache has many security holes. It better to install and external firewall or a firewall software.

If you can pay, then I would say buy at least a cisco 505e firewall connected with the server externally.

or if you dont have/dont want to pay much in external ones. Use APF or CSF firewalls availble freely

I would recommend CSF which is priced at no cost. Its an idela solution if you have low budget or dont want to pa for external firewall. Also, it is still recommended for those who have external firewalls installed as they have a limited functionality.
 
 
 


Old
  Post #6 (permalink)   04-10-2007, 08:16 PM
HD Newbie
 
Join Date: Jul 2006
Posts: 25

Status: Humbe is offline
Thats sad, when you are trying to get your business going and some kids come and start playing around with all your work done so far. They should caught them and put them in jail.
 
 
 


Old
  Post #7 (permalink)   04-10-2007, 11:04 PM
HD Addict
 
Join Date: Jan 2006
Posts: 203

Status: bandboy is offline
Quote:
Originally Posted by Cal813
The one and only time I was ever hacked, happen't through IPB.
Thats scary.

Can you share some more information because i also use IPB and would want to know the areas i need to focus upon.

Did you discuss it with IPS?
 
 
 


Old
  Post #8 (permalink)   04-10-2007, 11:50 PM
HD Newbie
 
Join Date: Jul 2006
Posts: 25

Status: Humbe is offline
Quote:
Originally Posted by bandboy
Thats scary.

Can you share some more information because i also use IPB and would want to know the areas i need to focus upon.

Did you discuss it with IPS?
I don't think the latest version of IPB can be hackable yet, maybe he was using a older version of IPB which are vulnerable. That's why I suggest everybody to update they software when a new patch or version comes out.
__________________
Looking for web hosting? Check out
Us-WorldWide-Hosting - Affordable Web Hosting
 
 
 


Old
  Post #9 (permalink)   04-11-2007, 03:29 AM
HD Moderator
 
ldcdc's Avatar
 
Join Date: May 2004
Location: Ploiesti
Posts: 2,446

Status: ldcdc is offline
Quote:
I don't think the latest version of IPB can be hackable yet
Just because there's no known public vulnerability, it doesn't mean a hacker doesn't know one.
 
 
 


Old
  Post #10 (permalink)   04-11-2007, 04:48 AM
HD Newbie
 
Join Date: Oct 2006
Location: USA
Posts: 36

Status: Jim2Macs is offline
Quote:
Originally Posted by ldcdc
Just because there's no known public vulnerability, it doesn't mean a hacker doesn't know one.
Dan is Exactly Correct! That's what these people do, they sit around all day and confir with other jerks just like them looking for vulnerabilities.
__________________
Jim2Macs - 2Macs H-Sphere Hosting
Since 2001 - H-Sphere Shared Linux & Windows Hosting
Fully Managed Services| Custom Web Designs
Unconditional, 30 Day Money back Guarantee!
 
 
 


Old
  Post #11 (permalink)   04-22-2007, 09:27 PM
HD Addict
 
Join Date: Apr 2007
Posts: 120

Status: hostingpuppy is offline
Quote:
Originally Posted by Cal813
Anyone here ever had their server hacked or compromised? I've noticed there are a lot of servers being hacked these days. Not sure if it's due to people lacking updates for their software or just leaving ports and holes open. The one and only time I was ever hacked, happen't through IPB. We basically had to take it down and put up a vB
I've had exactly one Linux server hacked in my life and it was due to a combination of an old 'test/test' account being left on the box and an exploit in either Apache or Horde (the damage was to great to track it down any further).

Thankfully this wasn't one of our hosting boxes, but it was still an eye opener.

If you've ever had anyone in your box doing work for you, I'd take a check through the /etc/passwd file to look for lame-O accounts like test/test. People don't do it on purpose, but sometimes you need a random account to test something with and may forget to delete it. Leaves a wide open hole for even a rudimentary brute-force attack to get through.
__________________
Hosting Puppy :: Shared Web Hosting With Offline (And Self-Restorable!) Backups Every 12 Hours
Premium: 24/7 Support :: 12-Hour Offline Backups
Budget: 12/7 Support :: Weekly Offline Backups

Reseller Accounts :: Live Chat :: http://www.hostingpuppy.com :: 1.866.968.4666
 
 
 


Old
  Post #12 (permalink)   05-03-2007, 02:16 PM
HD Newbie
 
Join Date: May 2007
Posts: 14

Status: forumpakistan is offline
Always make sure that all the ports and sockets on the server are closed. Just open necessary ports. It makes server more secure.
__________________
Pakistan Forum - Pakistani Forum TV, Dramas, News, Entertainment, Cricket
Web Development SEO | Make Website | Islamabad Realestate
 
 
 


Old
  Post #13 (permalink)   05-18-2007, 06:31 AM
HD Newbie
 
Join Date: May 2007
Location: Tampa, FL
Posts: 3

Status: SagoRyan is offline
Lucky for me, I've not had to deal with too many compromised servers where I work, but when I have, the thing that kills me is that an older version of service X was still being used. You've got to keep them up to date. The older the code, in my opinion, the more exploits there seems to be, or at least, the more the hackers might know about how to exploit.
 
 
 
Reply

Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On