icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » Shared Hosting » Horrible servers.

Shared Hosting Questions about your shared hosting account.

Reply
 
LinkBack Thread Tools Search this Thread
Old August 20th, 2007, 12:06 AM   #37 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
Quote:
Originally Posted by Drewish View Post
10 minutes later:

"Damn! I deleted my email account!"
You know cerjamz? You think it's possible that he deleted a table in his database?

__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:09 AM   #38 (permalink)
Registered User
Fresh Surpasser
 
Joined in Jul 2006
11 posts
Gave thanks: 0
Thanked 2 times
no, i dont think he deleted a table in his database, hes not a complete idiot.

but I do think this whole argument and bashing surpass thing is really childish and pointless.
Drewish is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:09 AM   #39 (permalink)
Registered User
Fresh Surpasser
 
Joined in Aug 2006
29 posts
Gave thanks: 0
Thanked 0 times
yes, i went into my own database and deleted the table WHILE I WAS ASLEEP!


drewish is an idiot, end of story.

and never got your email kayla, but got pw working via forgot password link. amazingly.
cerjamz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:12 AM   #40 (permalink)
Marketing Maven
Surpass Staff
 
Kayla's Avatar
 
Joined in May 2003
Lives in Orlando
24,749 posts
Gave thanks: 946
Thanked 806 times
When I reset that password it probably helped things along. Looks like like everything possible is working against this situation so far. I am glad you are able to reply to the ticket again now.
__________________
Follow Surpass on Twitter and Facebook
Check out the Surpass Blog



Kayla is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:13 AM   #41 (permalink)
Registered User
Seasoned Poster
 
Joined in Feb 2007
Lives in USA
Hosted on SH116
33 posts
Gave thanks: 1
Thanked 2 times
CPanel exploit?

You've got to be kidding me.

There was infact a remote access cPanel exploit a *while* back if I remember correctly, but considering Surpass always updates cPanel, I'm more than certain that couldn't have been it.

You're not running the latest version of vB (3.6.8 is newest).
3.6.4 suffers from SQL injection and Cross-site scripting. This might explain how your database got 'owned'. If you fell victim to either of these vulnerabilities, you are at fault, not Surpass.

Surpass does run Apache ModSecurity with quite a bit of rules added to it's configuration to help prevent a lot of common script exploitation from successfully being carried out. They've also got register_globals and allow_url_fopen disabled in their PHP configurations to prevent things like remote file inclusion.

Similarly, I lost a 200MB very large forum database a few years back because I had no backups. I know exactly how it feels.

Good luck getting your site back up and running.
Elite is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:16 AM   #42 (permalink)
Registered User
Fresh Surpasser
 
Joined in Aug 2006
29 posts
Gave thanks: 0
Thanked 0 times
i have to use dialup, hence why i cannot back it up as regularly as i'd like to. I leave it up to the staff, which the idiots havent done it for more than a week, it's not a big deal. Just pissed me off, and i'd have said it was a vbulletin exploit but all the cpanel logs had been wiped out.
cerjamz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:29 AM   #43 (permalink)
Registered User
Seasoned Poster
 
Joined in Feb 2007
Lives in USA
Hosted on SH116
33 posts
Gave thanks: 1
Thanked 2 times
Just because they got access to cPanel, doesn't mean you didn't get exploited via vB. You use similar usernames and passwords?
Elite is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:37 AM   #44 (permalink)
Registered User
Fresh Surpasser
 
Joined in Aug 2006
29 posts
Gave thanks: 0
Thanked 0 times
Nope, every user has its own pw and username. cpanel user and pw was random to anything ive ever used.
cerjamz is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old August 20th, 2007, 12:42 AM   #45 (permalink)
Registered User
Seasoned Poster
 
Joined in Feb 2007
Lives in USA
Hosted on SH116
33 posts
Gave thanks: 1
Thanked 2 times
I bet if someone used the right exploit on vB, they could wipe the cPanel logs. Due to PHPSuExec, PHP should be ran as whatever your account name is (with privledges for anything under your account). All you need to do is obtain a shell (phpshell) and you can own the whole damn account.
Elite is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On