Previous | Next

I Don't Believe It

  • Jul. 9th, 2009 at 12:39 AM
Wuh?
It's not just the server my site is hosted on. No, it seems to be sweeping across all of them. Servers are falling left and right, and all that is left in the stead of the web sites they once served is a page telling people to download a file which contains a virus. I just scanned the server status page, and there are at least ten servers downed by this hacking.

I find myself completely dumbfounded and astonished this has happened. Over the years, my web site has been hosted on some really crappy servers and with some really crappy hosts. I would not have, up until now, put A Small Orange in that category. Sure, there have been the occasional problems, but they are attentive and, I wouldn't have thought, not completely stupid or just in it for money. They try to do a good job, and for the most part, they succeed. Until now, of course.

A single web site getting hacked is one thing. A couple of web sites getting hacked on the same server (or not) that are all running the same software is another thing. A single server getting taken down is a big thing, and a slew of servers falling to hackers is, as far as I am concerned, a death knell.

It's just freaking insane!

And at the very f*cking least, they could take the servers that have been hacked offline to work on them, because seriously ... how many web sites are sitting there serving up a virus that quite a number of anti-virus programs won't detect right now? I have no idea, but mine is, and that is making me excessively angry.

Back to drinking and refreshing forum pages.

Tags:

Comments

( 9 Have Spoken! — Speak! )
[info]dawna wrote:
Jul. 9th, 2009 05:55 am (UTC)
someone in that company really really pissed someone off.

its still unforgivable that they haven't removed the servers from active status.
[info]orbie wrote:
Jul. 9th, 2009 06:16 am (UTC)
An employee, working at home on a compromised computer. Hackers got his password ... for an employee account. Some files were lost forever, they say, and they also say the malicious code is down now, which it is not. My site is still serving up fresh virus.

I might have been able to be talked down from hating them forever, had it been only my server, they offered something good and valuable to sooth my feelings, and kissed my ass for a while ... as well as firing the moron who caused it. But leaving that malicious code up for hours is pretty much unforgivable. That's bad karma on my site, man. Bad Google and Firefox karma. It's the kind of thing that gets web sites blocked. Pisses me right off. I work hard for my Google rating dammit! :P
[info]dawna wrote:
Jul. 9th, 2009 06:23 am (UTC)
holy shit are you fucking serious? why the hell did they not ensure that their remote employees have a safe fucking computer. Yeah, wow that is just insane.

*hugs you* I am so sorry this happened :(

Do you need a temporary host? what is your bandwidth numbers look like, I can handle quite a bit... until you get situated.. you can at least point your domain elsewhere until you decide what to do.
[info]orbie wrote:
Jul. 9th, 2009 06:39 am (UTC)
Mind boggling, isn't it?

Thanks for the offer, but if my site is still missing in action tomorrow, I'll point my important domains over to my LJ. Google has already found me over here. Google loves me. Now all I have to do is keep it distracted by posting over here so it doesn't noticed the freaking VIRUS sitting on my blog space.
[info]dawna wrote:
Jul. 9th, 2009 06:52 am (UTC)
Yeah, it really is just crazy.

The offer stands hon.. just let me know <3
[info]orbie wrote:
Jul. 9th, 2009 06:55 am (UTC)
Thanks.

I'm going to try to sleep now. Nothing I can do but sit here and bitch and fret, and I do have to be awake again in three-ish hours. A little sleep might be nice. Who knows what tomorrow will bring, right? LOL!
[info]slipdragon wrote:
Jul. 9th, 2009 06:42 am (UTC)
As a 10-year IT professional, first, let me say that I am very, very sorry.

Second, this sort of thing happens when the people behind a server hosting company get lazy and complacent.

It means that the home employee got themselves compromised, and didn't report it. It means that they have poor password policies. It means that their intrusion detection systems are out of date, and probably their entire security structure.

And, due to the lack of response...

...it means that their IT department has no idea how to cope with an incident of this magnitude.

You're going to need a new hosting service, I'd suggest someplace like Godaddy or Pair.

Luck,

--Brian, random Austincommunity surfer.

PS: It is sad, but, do not rely on a host to backup your files and data. Do it yourself. :) If you need help, you can ask me, I work on this kind of stuff for free.

[info]orbie wrote:
Jul. 9th, 2009 06:48 am (UTC)
Yeah, I pretty much won't be able to trust that this won't happen again (or something equally awful). It's definitely time for a new host.

I tell myself to make weekly backups, because I post a lot (and a lot of photos), but I get them done about monthly. I'm not entirely unhappy about losing a month of stuff, since most of what I post is nonsense and drivel anyway. ;)

Thanks for the comment and offer of help. If I find myself needing assistance figuring out the best way to do regular backups after I get on a new host, I might just have to look you up! :)
[info]memoryanddream wrote:
Jul. 9th, 2009 02:52 pm (UTC)
I'm not on ASO but I've been catching up on Orb's posts overnight and it's got me thinking how horrible a crash would be. If you have any easy (and free) suggestions for backing up files from a domain on a regular basis, I'd love to hear them. Doing it manually is rather tedious and time consuming, and tends to lend itself to, well, just not doing it. Thanks in advance.
( 9 Have Spoken! — Speak! )