Webmaster Forum


Go Back   Webmaster Forum > Web Development > Web Hosting Forum
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Web Hosting Forum Discuss web hosting related stuff.

   

Reply
 
LinkBack Thread Tools Display Modes
Old 09-26-2006, 02:55 PM   #1 (permalink)
Contributing Member
 
labrocca's Avatar
 
Join Date: 01-24-06
Location: Las Vegas
Posts: 268
iTrader: 1 / 100%
Latest Blog:
None

labrocca is just really nicelabrocca is just really nicelabrocca is just really nicelabrocca is just really nicelabrocca is just really nicelabrocca is just really nicelabrocca is just really nicelabrocca is just really nice
Send a message via AIM to labrocca Send a message via Skype™ to labrocca
Hostgator rocked by hackers via cpanel exploit.

http://www.seopedia.org/internet-mar...-in-mass-hack/

I never been a fan of cpanel. Now you know why.

Scary stuff really.

Quote:
cPanel (all versions) Security Hole Exploited in Mass Hack

Using a new undiscovered security hole, hackers compromised all of HostGator’s servers, and inserted trojans into their client’s websites :

HostGator says hackers compromised its servers using a previously unknown security hole in cPanel, the control panel software that is widely used by hosting providers. “I can tell you with all accuracy that this is definitely due to a cPanel exploit that provides root access and all cPanel servers are affected,” said HostGator system administrator Tim Greer. “This issue affects all versions of cPanel, from what I can tell, from years ago to the current releases, including Stable, Release, Current and Edge.”

This happens after the last 650 websites mass defacement, which happend in just a single day. Is it just me or the so called “stable and secure software” is becoming increasingly insecure with each passing day ? Ar we supposed to switch to Windows (Plesk) ? Or just buy hosting packages without Cpanel ? Or actually learn to secure Cpanel better ?

PS: This is a LIVE VML infection video of what happens to a workstation when it visits an infected website (like Hostgator’s hacked websites):

After we visit the infected site, we log into a PayPal account to show you an example of the information that can be stolen. This keylogger operates by indiscriminately capturing the entire contents of EVERY web form on any page — all data entered into your financial, webmail, and Intranet sites can be captured. We added some commentary to the end of the video to provide a brief explanation of what happens behind the scenes.
labrocca is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-26-2006, 04:49 PM   #2 (permalink)
V7N Addict
 
talkwebz's Avatar
 
Join Date: 09-21-06
Location: █Ontario, Canada█
Posts: 1,605
iTrader: 1 / 100%
talkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nicetalkwebz is just really nice
Send a message via MSN to talkwebz Send a message via Yahoo to talkwebz
OoooO
wow.
cpanel is like phpnuke then. easy to hack. lol
talkwebz is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-26-2006, 05:09 PM   #3 (permalink)
Mia
Contributing Member
 
Mia's Avatar
 
Join Date: 04-28-06
Location: Lake Geneva, WI.
Posts: 296
iTrader: 0 / 0%
Latest Blog:
Obama and Red Gold?

Mia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web proMia is a highly respected web pro
Send a message via AIM to Mia Send a message via Yahoo to Mia
I would not say that. Just about anything can be hacked. It is only a matter of time. How fast a developer patches a security hole should be taken into consideration, more than the hole itself.

Millions have happily dealt with holes in the MS OS for years, yet all the while waiting long periods of time for patches. As I understand it cPanel was patched quite quickly.

The best way to secure a computer is to unplug its power from the wall.
__________________
Jeremy Anthony Kinsey
Bella Mia, Inc.
Host Drive Web Hosting
Get a FREE Credit Report?
Mia is online now  
Add Post to del.icio.us
Reply With Quote
Old 09-26-2006, 08:33 PM   #4 (permalink)
Moderator
 
ToddW's Avatar
 
Join Date: 01-11-04
Location: Folsom
Posts: 2,646
iTrader: 0 / 0%
ToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest order
Send a message via AIM to ToddW
IE Only problem from what I believe.
Disable VML:
Start-->RUN
Type:
Press Enter

regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll

__________________
Learn about Bear Grylls, Les Stroud, Man Vs. Wild & SurvivorMan at Survival TV Shows
Order Exciting Inspirational Posters from Inspirational Posters at great value.
ToddW is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-29-2006, 07:59 PM   #5 (permalink)
Inactive
 
dbay's Avatar
 
Join Date: 02-07-05
Location: on a 3
Posts: 49
iTrader: 0 / 0%
Latest Blog:
None

dbay is on the right pathdbay is on the right path
dang...it finally happened
dbay is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Web Development > Web Hosting Forum

Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Free Blogs With PR - WPMU Exploit Resurrection Blogging Forum 4 09-24-2007 08:19 AM
SERP different: "Hostgator rebates" and "Hostgator rebate" charlesgan SEO Forum 2 03-04-2007 08:36 AM
vBulletin 3.0.X exploit fishfreek Web Hosting Forum 0 02-14-2005 12:14 PM
Does Google exploit voluntary translators? astrab Google Forum 0 10-22-2004 08:16 AM


Sponsor Links
Get exposure! Get exposure! Find Scripts Web Hosting Directory Get exposure! SEO Blog


All times are GMT -7. The time now is 10:55 AM.
© Copyright 2008 V7 Inc