cc9, others file were there but pointing wrong in most of the cases, hacks can happen sure, but it isn’t something systemwide. All this looks to be an issue in the Hsphere tools, which they have already escalated to their highest developers to research why these problems have happened.
the entire server was under attack for an extended time, but before this even it was scanned, and in fact every server online is scanned daily for exploitable versions of software, so always be sure any web app is up to date (just in general).
There’s also a chance that some AV scans have deleted some but it would not be an entire domain, just infected files. (so this is unlikely to be the issue.)
There is some systemic security thing going on. Have had an email spamming hacky thing, and then a db password changed… never had such issues in the past on the account, and nobody was given password. seem coincidental to be happening when there seems to be an uptick in such reports from others too.
Do you know when this happened? There is a chance someone has an end user password for hpshere access, while there were some hsphere bugs allowing actions to happen in illegit ways, those are patched for some time now(about a yearish?), but if someone has CP access, they can do the things you mention here.
Mine too…this is really becoming a very serious problem folks..there are peoples businesses here that haven’t been functioning correctly for a very long time…please do something to help/correct this!
According to techs this was very short problem due to hsphere reverting some domains back to orginal IP temporary, which we have seen happen when a domain on account uses hsphere to edit.
Since the Hsphere tool went haywire for moving the IP, they are having to go through development team at parallels to make a custom tool to undo it just a pure DNS server ip migration without touching Apache, and we were initially told today as deadline but last night got update of Dec 23rd moved. Since that has already moved twice I’d not be surprised if another.
Joe, I checked randomly on 15 domains from multiple resellers and all were opening correct websites, after your helpline mail a bit ago. If you have a domain doing this it should be included in the helpline mail so we can check, or at least a ticket reference for some domains, so we can fully check the issue you are seeing. Just saying as a request there.
I have personally, a bit of a sinus infection was was resting last night. I have already expressed my disappointment in not checking the customer forums and answering last night here.
Thanks for your hard work and complete dedication Stephen to working through and correcting these issues.
For my sites now on Web 17 they all appear to be corrected and actually probably were quite some time ago. After doing some cache flushing all of my sites appear normal.