win39 DDOS

So is it done yet? I have one site down and on a temporary server (just static HTML.) When can I switch it back? Updates?

It is already provided:
Win39 Shared IP is null routed - unreachable, network update - Network Outages and Updates - JodoHost Web Hosting Community

Sunday at soonest…or on ticket we can help set you up with cloudflare but you need to move DNS to cloudflare servers.

This is the 3rd major DDOS attack on win39 based sites shared IP, and the attacks aren’t using HTTP traffic for the most part, so they do not log to places we can see the host headers (aka the domain) Makes it very hard to know the target. We do know another attack earlier in week and about max 20 domains and about 30 subdomains/aliases were pointing to the original under attack shared IP. upon moving some of those off that shared IP, DNS updated, 8-12 hours later the attacks were back and bigger than ever, and on the other shared IP address. So simply changing the IP is of no use, moving server of no use, it will simply follow whatever is being attacked.

Stephen, I have multiple sites on win39 that are down because of this DDOS. Can you please help me understand how the cloudflare account would help? Am I able to use a single free account to handle multiple domains?

Stephen,

Is this the solution to bring the sites back online? I have 8 main web sites that are still down. I submitted a ticket [RS #ZMK-40284-537]
and posted on Facebook and was told to look in the forums for a solution. DNS changes are an option but it will take time. Would getting a single, dedicated IP for all my domains on WIN39 help and provide insight if it’s one of my sites being attacked? I can also move these sites to another plan in HSphere using WIN33 or WIN34 but it would help if they could be imported in some way instead of configured manually. What is the best way to proceed?

If I need to update the DNS for these domains it needs to happen quickly to prevent costumer service issues on Monday and email downtime. Most of these sites have the DNS set up at Jodo and the MX records pointing to external mail servers.

Additionally, several of my sites on WIN39 have been hacked in the last 6-12 months, the last time was in the last week or two. I went in and removed the hacked content on these sites but this makes me think there is something else occurring on that server. Maybe some user has elevated privileges or there is some other security issue allowing these sites to be modified? After the last hack in the fall I updated all my passwords, turned off and removed all the EasyApps, turned off all unused services, etc… only to have it happen again. Most of these sites are very simple and do not have complex functionality so it’s concerning that they continue to get hacked.

Lastly, I am seeing spam in the Jodo forums here that makes me concerned that there are more issues overall. I’ve never seen spam in the forums before.

We have made required DNS changes in Hsphere as well as at server end. Now you need to wait for few hour. Domain should start works fine.

We are suggestion to move DNS on cloudfare to prevent DDOS attack further. However, It is not force to do it immediately. you may do later as per your convenience.

dman,

We remove 30+ spam every night in the forums. I was flat out exhausted this weekend and wasn’t here deleting any until tonight I checked in. Prior to Friday night I had 2 weeks of living hell with issues. I slept 22 hours in 2 weeks, I have help, but so many of the issues were advanced beyond normal tech help, and we also have a new business sector which needed to be tended locally. I’ve slept almost as much now since Friday, thankfully! Much needed it was.

Win39 has no security issue on the server itself, hacking is very common, I don’t think you had any easyapps on, those have been disabled for years now.

There are LOADS of wordpress sites that haven’t been updated in years. Moving to cloudflare doesn’t impact MX records pointing elsewhere. I did a check and tried to disable the major xmlrpc and other big known holes in the 2012/2013 wordpress installs, just because they ere glaring holes and some had already been hijacked.
There’s certain security aspects I’d love to do like shut off FTP entirely, using only FTPS and more, but we cannot do so with Hsphere, and we are working on long term solutions for this but they are not ready now.

WE really do need the cloudflare on the addresses, because if your sites the ones under attack, we’ll have everyone down again, and that’s been the big deal. Cloudflare will read your current DNS and clone it across, then you can rapidly change DNS there faster than we can here, changes there are anycast and nearly instant because they maintain a low TTL. We can modify records here to a low TTL, but the defaults are a bit high.

Its very good to go in and cleanup accounts in any case, so many have unused apps installed, and think that they aren’t linked they are not a problem, but google and other search engines find them and skiddies abuse them.

Tonights eye rolling spam log! Not quite to 30 yet!

Hey Stephen and Shubham,

Thanks for your replies! I missed these previously…

Stephen, I know the feeling of not getting enough sleep, I’ve been there recently for worked related projects, and it’s not fun. Makes me wonder why I’m doing this work at times.

Good to know that the forum spam is not new or at least known about. I presume it’s too much to moderate the posts which is why it requires cleanup. I’m also surprised there isn’t some spam filter option.

I"m still a bit confounded on how my sites get hacked. My user and FTP passwords are very secure and long, and I changed them recently so it’s unlikely this hacked surface but I know it’s not FTPS. None of my sites use Wordpress or any other framework or CMS I did find a few left over EasyApps directories that I removed on the hack mitigation in the last 2 weeks. I hope these hacks stop or I will have to find other solutions to prevent them.

yes anything leftover can certainly be a cause. Those must have been ancient since EasyApps hasn’t been enabled in at least 4 years. I know during the DDOs attacks I found Wordpress installs from 2011, so it is very possible to leave old apps around.

FTPS isn’t something Hsphere can do now, but we are working to support it in the future on our new direction which is in progress, but not available now.

Thursday 10th March 2016

I’ve been having terrible trouble with Web 4 being hacked - lots of backdoor php files uploaded.

I’ve changed the FTP password (again!), changed the MySQL passwords and the Wordpress and Joomla admin passwords (and the admin is not called admin either).

When I find a backdoor, I delete all the code then re-upload it (size zero) and change the file permissions to owner read only - this should prevent it being overridden.

in .htaccess I only allow uploads of 10bytes.

However, despite all this - the problem continues. Very frustrating!

BlueJag, are file permissions 777? That’s one of the biggest issues I see in many, other than outdated software.

We have replied on your ticket regarding this issue.

BTW, it seems to be due to so many domains, any one of them having an issue makes the whole account vulnerable.

We’ve got one client I know that have 100’s of domains and subdomains in one account, this makes the server suffer(lot to move/setup/resetup/doenst ditribute load like Hsphere intends) as well as the domains because of the way permissions work one ‘minor’ issue in any domain makes them all vulnerable.

Hi Stephen - none of the file permissions are set to 777! I try and make them 400 which is the Owner - Read Only or 444 failing that

Outdated software - again I keep Joomla and Wordpress bang up to date. Altogether just 9 small sites which don’t receive much traffic at all.

In all the (happy) 11 years I’ve been with Jodo I’ve never seen such hacking activity - just look at the forum today. Someone out there really has it in for the company.

Anyway, as always, good advice. Thank you.

It’s like fighting a forest fire :frowning:

“In all the (happy) 11 years I’ve been with Jodo I’ve never seen such hacking activity - just look at the forum today. Someone out there really has it in for the company.”

Really I am not sure what you are iplying here, forum spam is a huge issue, it is 99% automated by stupid posting bots, We remove it using stopforumspam on a nightyl basis reporting the new IPs and schemes that prevent that from being as regular the next days. Its an ongoing battle, has absolutely nothing to do with anything about ‘out for the company’

Yes, there are loads of bot based defacements and infections as well, that could be the only minor ties to relate the two, but there aren’t real people behind most of these, just pure and simple spam bot networks of trojan computers and malware infected computer’s being a conduit for automated spamming networks to post. These same type of posts get send to form mails that both are and aren’t captcha protected. The forums here are on signup captcha protected, and on a per IP basis captcha protected from posting it is called a ‘post discouragement’
The techs and admins all do a good job on this, removing it on an ongoing basis.

Hi Stephen - not implying anything other than I’ve been perfectly happy with Jodo for the past 11 years. It’s just sad to see the amount of grief caused by these stupid bots. One wonders what the long term future of the internet is. The company I work for had a major hack a couple of weeks ago which caused major problems, and they had all the latest firewalls etc etc. It must be a continual nightmare for banks and large corporations.

oh, most certainly. It is a continual battle. We are making a new product that will roll out over time to cover everything hsphere does + a LOT more, and it will have some really neat features and alerting of changes made to add/remove/modify files, making sure secure permissions from the baseline, and more. We have been working on it a while now but it’s just now something I am willing to mention. It won’t be a full replacement at launch, but it will be a very solid unix product. In addition we’re working on the ability to put it being WAF (web application firewalls), either in house or cloud based, as well as geo distributed. It won’t solve hacking/defacing issues, but such can be a big help. It will be able to run on a shared server as seamlessly as a VPS or dedicated as well, which is a huge point of relevance for clients and end users.

OH and about bots, just take a look at the http access logs of what you think is an idle site one day, you will see a lot of attack attempts against wordpress, joomla, mambo, drupal and others all running automated, sometimes even 1000s a day on a site with zero traffic. It’s really an issue, this is where large WAF systems can come into play, analyzing those botnets and stopping them as a colective before they even have their request reach your web server and feed back to the legit clients. This is essentially what cloudflare does now, but they can be over agressive according to some, or they are down on DNS a bit more than other places, and now a common point of attack against them directly because of protecting questionable sites as well, so that’s why we’d like to offer it in house and as a choice for external provider.