am i the only one who got hacked?
i’m noticing that i have fix.html (and other fix.* files) in almost every directory.)
i’m guessing that either jodo was rooted or theres been a security breach there.
or i was just plain hacked.
Ranjan: Hi
daniel: hello
Ranjan: how may i help you?
daniel: it appears that i have been hacked
daniel: i have fix.asp, fix.htm etc… in every directory on my sites
daniel: the files say “hacked by eno7”
daniel: i’m the only administrator on these sites
Ranjan: what is your domain name?
daniel: i have a few
daniel: www.danwoolston.com
daniel: www.bishopsoftware.com
daniel: i’ve been deleting for a while
daniel: but there are so many files that theres no simple way for me to delete these fix.* files from all of them
Ranjan: if you are only administartor
Ranjan: please change your ftp password. database password
daniel: i’m about to do that
daniel: my main concern was getting the files off
daniel: it doesnt appear that theres any files other than the fix.* files
daniel: so theres nothing being served from the site
daniel: is there a faster way to delete all of these fix.* files from my sites?
Ranjan: you can delete through webshell
Ranjan: just login in your control panel
Ranjan: and click on ftp manager
daniel: k
Ranjan: then webshell windows will come
daniel: i’m there
Ranjan: then you will selete all files which are you want to delete
daniel: does that mean i have to go thru every directory one at a time?
Ranjan: yes sir
daniel: thats going to take forever because i have a bunch of dnn sites
daniel: i just did a search for fix.* and it says 3500 files
Ranjan: but there is a no any options to delete faster
Ranjan: you should going to directory one by one and delete all these files daniel: well as an admin you could right click on the root folder, do a search for fix.* and then delete them
Ranjan: yes i knoiw
Ranjan: but that is risk
Ranjan: so i request to you if you will delete that through web shell or ftp client software
Ranjan: it will be better
Ranjan: ok Sir
daniel: not for me it wont
daniel: it will take me days to do it this way
Ranjan: you can download domain directory at your end
Ranjan: and delete it by search at your local machine
Ranjan: then upload it
daniel: won’t that blow out my bandwidth usage for the month?
Ranjan: yes bandwidth will calculate for this month after download and upload
daniel: o.k. well i guess that’s what i have to do. it’s unacceptable and poor hosting.
also noticing issues when trying to back up all my sites.
i’ve tried 4 different ftp clients and they all do the same thing, so i’m assuming its jodohost. It’ll timeout all the time.
it’ll que up some of the files, but will hang up.
awesome.
this is turning into an absolute nightmare.
i cant back up my sites.
i cant delete the files.
i neeeeeed to find another host soon.
also:
do not assume that if you use h-spheres “archive” feature in the file manager that it is actually backing up the entire directory that you’ve selected. it will only include files that are one directory deep. it doesnt nest any farther.
glad i checked before deleting the original.
99% of the cases where a client has been hacked are due to an exploited script on the user’s site or poor password security. Submit a ticket and we’ll look into the logs and try to determine the entry point, but this will take time (24 to 48 hours).
If you need your files restored from backup, please open a ticket and we’d promptly do so. There is no need to delete individual files. Ranjan should have advised you of the option of a full restore which he didn’t, and I appologise for that
Search google for “hacked by eno7”, lots of sites in search result. It appears, hacker is exploiting popular script.
A few notes:
- this was only your site, someone found a hole in a software pacakge somewhere on your site.
- I can remove all the fix.asp files if you want
- This is not system-wide, so please do not go postal when something that is only you, and your site happens like this.
For FTP, try flipping the active/passive FTP switch on your FTP Client.
Also, looking through your site, it was actually hacked back on 10/16/2005 by most of the fix.asp datestamps, and then again on 12/11/2005, I am looking at the logs now to see if I can tell you what site they are getting in through to do this.
I didn’t “go postal”
if you read through the posts above, you’ll note that i did actually inquire “am i the only one who got hacked?”
i made zero presumptions on the cause of this. thats cool that you assumed that i did though.
gotta love it when the vendor says to the customer “dont go postal.”
X(
Please look at your topic and your posts, it is clear you are trying call this something systemwide when it was not.
wtf?
its clear that i’m saying its systemwide? lets review:
the topic:
jodohost rooted?
notice the question mark on the end? That is not a declaration but rather a query.
First statement:
am i the only one who got hacked?
hmmm.. still just a question. no accusations here.
Second Statement:i’m noticing that i have fix.html (and other fix.* files) in almost every directory.)
well..this statement doesnt really count as a defensive or offensive item as it is merely informing the user of the current situation. Lets move on.
Third Statement:
i’m guessing that either jodo was rooted or theres been a security breach there.
whooaaa! look out! There’s almost a “system wide” insinuation here. But wait! What’s that at the start of the sentence? “I’m guessing”. Well crap. That kind of negates the sentence following as a sincere accusation of fault, because I’m letting the reader know that “hey..this part could be true or possibly not. Consider that,since I am “guessing”,the possibility of the following words having complete accuracy may be in peril.”
Fourth Statement:
or i was just plain hacked.
well thats just plain silly. I’m obviously attacking Jodohost with this statement. There’s a clear pattern of aggressive behaviour in my forum post. Surely thats obvious to Joe reader. But wait..this is conversation is only confined to the “members only” page of the forum. Lets fix that. Let’s move this out (again) to www.geekswithblogs.com and share this with the rest of the world.
Bishopsoftware, you are plainly ignoring what we have already stated. Ranjan’s statement was a mistake already acknowledged at JodoHost. But the issue is restricted to security hole in your script. Nothing serverwide
You are already maliciously defaming us on a public forums. I have not responded publicly to any of your statements because you can expect to hear back from us legally within the next few weeks
[QUOTE=Yash]
99% of the cases where a client has been hacked are due to an exploited script on the user’s site or poor password security. Submit a ticket and we’ll look into the logs and try to determine the entry point, but this will take time (24 to 48 hours).
If you need your files restored from backup, please open a ticket and we’d promptly do so. There is no need to delete individual files. Ranjan should have advised you of the option of a full restore which he didn’t, and I appologise for that
[/QUOTE]
[QUOTE=Stephen]
A few notes:
- this was only your site, someone found a hole in a software pacakge somewhere on your site.
- I can remove all the fix.asp files if you want
- This is not system-wide, so please do not go postal when something that is only you, and your site happens like this.
For FTP, try flipping the active/passive FTP switch on your FTP Client.
[/QUOTE]
once again…how am i “maliciously defaming” you? I’ve posted the conversations in their entirety and asked users to decide for themselves. And you’re going to seek “legal action” against one of your own clients because they’ve expressed displeasure at the service you’ve provided? You might want to think twice about that. I’ve merely provided to others a recap of my experiences, however negative they may be. I find it absolutely amazing that you would attack a customer that has been with you for years. My continued displeasure is primarily based upon the fact that Stephen continues to insist that I’ve insinuated and proclaimed that Jodohost had a security breach that had affected the collection of customer accounts. which plainly i have not. Because I had merely raised the question of whether Jodohost had been hacked, I was voraciously attacked and continue to be so. I’ve already stated that I understood that “i was just plain hacked.” But you guys just wont let it go. This is not how customer service is done.
Bishop, please just stop it, I already helped you delete the file from your domains, I would highly recommend you find another host very soon, as you continue to belittle staff and suggest that servers are hacked on websites other than here, it is not good to do this when it has been explained to you it was ONLY YOUR ACCOUNT, these hackers are quite a pest, and they find small vulnerbilities in many apps. You came to the forums and posted so many times before even one of us could reply, when a ticket alone would be enough…
- nevermind… none of my business…
Bishopsoftware,
There are two separate issues here ie (a) Did JodoHost do all that was possible to help you. (b) Was there a security issues at JodoHost which caused your problem.
a. When you noticed the problem, you visited JodoHost LiveChat. JodoHost immeditely attended your chat and suggested possible actions. All these options are documented in H-Sphere online help as well. So I do not see any issue in attending your issue instantaneously. Now the question is what extra JodoHost could have done (a) delete the files as required by you (b) Restore your files from backup. Ranjan did not delete the files. He thought of possible risk to your other files. However shortly, Stephen offer to delete the same for you. (ii) We do restore when customer asks for it all the time. Ranjan did not suggest full restore. He would have done it for you if you had asked for it.
b. As it is very clear from my post above. This hacker found a security hole in popular application that you or your customer were using. Hacker has not done this alone for you. Search google and you will find many other affected. We have tried our best to explain this issue to you at this forums. However you have went ahead and tried to defame us without letting blog reader know of JodoHost comments on this issue.
You are not justified here.
We have build a reputation of excellant Customer Service in last 3 years. We take our Customer Service very seriously at JodoHost. Where possible we go out and provide extra help to our customers.
At JodoHost Forums customers are free to express their views and problems all the time. In most customer’s comments, I read praises.
It hurts when someone try to put the blame or suggest one on JodoHost services when we are at no fault. We had contacted that blog, but received no response. You did not provide us an opportunity defend ourself.
Please either delete that post, or let blog reader also read JodoHost side. If you do not do this, in my openion, it is not legal. You will agree, that we too have right to defend our reputation.
i have no control over www.geekswithblogs.com inability to function correctly. its not my site. i have comments turned on. if you read other posts on that site, you’ll notice that others are having the same issue.
but i’m going to just let this go.
we’re both seeing different sides of the story and the best thing to do at this point is to agree that we disagree and move on. after the holidays, i’ll find another host and then we’ll both be happy.
to be really fair, I guess you?d have to “decompose” not only your first statement.
I agree with you, as in your first statement you are very balanced.
Yet, the several comments after your first post, are all very negative advertising to them, but the problem turned out to be on your end. ?(
I guess you “vented” your frustration. I do the same, it?s very natural, when things dont go right.
(in my opinion though, “go postal” seems pretty close to “venting”)
I’m not as shy (or perhaps appropriate) as KCWebMonkey.. ![]()
I’ve been on forums like this for a few years now, and these sorts of discussions do come up from time to time - it’s very very hard to address feelings of frustration in writing - whether on paper, email or in forums. It’s easy to hear someone’s feelings on the phone - both the frustration and the willingness to help - but not so much on the screen.
Like most who end up reading these exchanges, I generally feel for both sides. That’s the funny thing - nobody is usually right or wrong… but it’s obvious when feelings of frustration get out of hand. We’ve all done it.
I really just want to say I hope there’s no hard feelings here - patience is a must in these cases. And, as with all support situations, if you’re not getting the answers you want from one person, ask to speak to someone else. There were probably some communication problems going on initially.
My 2c: If there’s one universal truth that will never fail with customer service, it’s that the customer is always “right”. That is, they always have a valid case, and usually all they want to know is that they’re being listened to and their concerns addressed. The conversation should not leave the subject, and never get into discussions about who said what. Semantics is a linguistic science - like all sciences, it causes more arguments than it solves problems. ![]()
I find Jodo very helpful, especially Stephen, Yash and Atul. Sometimes one or two others, while trying to be helpful, are a bit hard to understand.. it may be a language thing. It’s always advisable to find the right person to talk to for the problem.
I think the term “go postal” should become a new geek word for venting-posts on forums! ![]()
Hope everyone had a fabbo Xmas!!
Actually I thought going postal online was venting, in person, it is a different thing. but anyway. Sometimes I go postal too ![]()