I have a customer using MODx CMS. The site was hacked using a security flaw in FCKEditer which MODx uses for its WYSIWYG editing. The site was recovered from backup (ticket # KOW-47192-507) and a recommended patch applied. However, within hours it was successfully attacked again and another ticket raised - ISX-61171-402.
Apart from a response asking what patch I was talking about I have heard nothing - zilch.
That was approx 36 hours ago and the customer’s site is still down. The disk allocation has blown out to 112.19/60 MB and there are 3 copies of the customer’s site: domain.com
domain.com-hacked
domain.com1
The customer can not upload a new version of MODx as he is over disk allocation. The domain,com-hacked directory can not be deleted as it has root privileges, not user privileges.
MODx advises that the site should be run with register_globals off. I know that having them on should not be a problem with properly coded scripts, but who is able to give a 100% guarantee that their script is free of security flaws.
So another question is how can we set register_globals to off?
FCKEditor is used in many CMSs so there is a good chance many other CMSs with get hit as well. There appears to be an ongoing concerted effort by a large group of hackers to get at sites using the FCKEditor. Some attacks are just bring the site down, others are being used as a spam relay
The annoying thing is that I can’t help my customer until I know what is going on. There needs to be a serious revision by JH on how it handles its trouble tickets. These frustrating delays of not knowing if support are attending to a problem or not is making me prematurely grey, not to mention what it is doing to my blood pressure. This is unfortunately not a unique situation as these delays have prompted me to complain here before. Can anyone a JH let me know what is going on
Is see Ranjan is answering that ticket now, you should have a response momentarily
I apologise for the delay. I can see the last response to that ticket is 24 hours ago, that is not normal as we usually have a 30 minute turn around time on restore websites from backups (we have many requests each week).
Also, please do not hesitate in using live chat if you haven’t got an update on a ticket.
But JH must seriously look at the trouble ticket system. Slow responses seem to be the order of the day for me. See thread http://support.jodohost.com/showthread.php?t=8245 for many similar delays.
Unfortunately live chat can take over an hour for a first response, so in many cases, if it is much over that time, I just give up.
nzkiwi, I’ll be honest, we cannot always produce 60 minute responses. It depends on the nature of the issue. I’m sure if you compare our support with 99% of the hosts out there, our responses are consistently faster, more accurate.
If its an emergency, please always come on LiveChat. There are times when livechat is very busy, but 99% of the time you should get an operator rather quickly. if that doesn’t work either, please use [email protected].
This time however, there appears to be a slipup. I am looking into why it took so long. This isn’t the sort of issue that takes longer than an hour
I appreciate responses can will not ALWAYS happen within 60 minutes. My real concern is the ticket system does not indicate when a problem is being transferred to a higher level of support. The result is an apparent non-response, and this is what is so frustrating. It appears that nothing is being done.
In this particular case there may have been a slip up. I can accept that - mistakes do happen. But from my point of view the response was just the same as on several other occasions where although no response was sent to me, support was actually working on it “behind the scenes” so to speak.
The current ticket system does not have a way of indicating whether the ticket is being responded to or not. If it is being worked on, I don’t want to take them away from the task, but on the other hand, if it is not being attended to, then I want to give someone a blast. Problem is I am not able to tell which scenario it is.