Web5 Exploited, Sites Defaced

Yash

Bass
Dated: August 10, 2006

A large number of websites have been defaced on Web5. We are looking into the issue and have been going through server logs.

The hacker exploited Web5 using a security hole in a forum package used by a customer. He was able to then deface index files on many sites by replacing it. No other files have been affected and the privelages gained by the hacker weren't sufficient to do major system damage.

At the moment we are continuing to analyse log files. We will be restoring index files from backup shortly.

I believe this is only our second exploit at JodoHost that has affected customers, in our 4 years of operation. The last one being on a Windows server. We take security very seriously and this issue too is going to be investigated thoroughly and the hole plugged permanently
 
We ran a script that deleted all index.* files on Web5. We are now running a restore procedure that restores files that have been deleted.

So if you now upload your own replacement index.* file from your own backup, it will not be overwritten by our restore
 
If a use see "directory listing denied error" then you can mention your index page in ticket and will be restored quickly (please include website and account username). You may also restore it yourself

Please DO NOT use live chat to report Web5 issues. We are being FLOODED. Open tickets and they are being looked into a priority basis.
 
The hacker has used a complicated script that has defaced a large number of other files using wild cards. Hence we have come to the decision to replace all modified files in the last 24 hours with original copies

We are copying files from our backup source to Web5. The backup is less than 24 hours old. The entire procedure could take upto 12 hours.

If your site is down and you need it urgently up, you can submit a ticket and we'd manually update your website. Please submit tickets..
 
The restore is moving along well. The file copy process is on schedule and should be done within the 12 hours Yash mentioned.

We are still available via ticket if you have an urgent request.
 
We have restored all websites and we checked more than 50 websites , found all of them opening perfectly now.

If you still see any issue with your website then please update us via ticket.
 
Back
Top