TheStorm wrote:
I figured out why it was going slow for me, I still had sshfs connected on my server and the sftp daemon is not a fan of multiple connections. I disconnected my server and it sped right up.
Very nice! My SFTP speed went way down, but it's still decent enough that I don't mind.
I didn't find anything untoward while glancing around the directory structure of /sfgp/, but I haven't looked at code yet. When Cemetech was compromised where did they place the payload?
elfprince13 wrote:
I didn't find anything untoward while glancing around the directory structure of /sfgp/, but I haven't looked at code yet. When Cemetech was compromised where did they place the payload?
.htaccess modification pointing to a single script in a new directory that pulled and stored a ton of .html files.
Hmm, I don't see any new directories or any new files. The timestamps on my .htaccess and all of my code files are intact going back to 08 and 09.
elfprince13 wrote:
Hmm, I don't see any new directories or any new files. The timestamps on my .htaccess and all of my code files are intact going back to 08 and 09.
Goodie, thanks for checking. I did a complete diff of the entire Cemetech source, including examining any code disparities between my local known-good copy and the server copy to look for exploits, and as far as I can tell, everything is free and clear.
Kerm, I would still look into getting ssh access if nothing else for rsync usage, so you can do incremental backups to any machine you want easily on a regular basis.
TheStorm wrote:
Kerm, I would still look into getting ssh access if nothing else for rsync usage, so you can do incremental backups to any machine you want easily on a regular basis.
Yeah, I'd like that, downloading a full backup at a time is a pain. I'm very happy to have SFTP access now, though.
Ooh, should I be able to switch to sftp as well?
elfprince13 wrote:
Ooh, should I be able to switch to sftp as well?
I don't see any reason why not. I'll give you the port for it the next time I see you in a private-messageable medium.
I just changed my client to SFTP, would you mind sending me the proper port as well?
comicIDIOT wrote:
I just changed my client to SFTP, would you mind sending me the proper port as well?
Not at all. I see that that warning is still up, and I noticed a small line about "up to a few weeks..." so I really hope that's not the case.
*necrobump*

Yesterday, Ultimate Dev'r alerted me that his site was similarly compromised; he is also hosted on Surpass. He also pointed out this Surpass topic:

http://www.surmunity.com/showthread.php/32454-I-ve-been-hacked

As you can see, I posted some strongly-worded posts there, and just updated my trouble ticket on the issue as follows:

KermMartian wrote:
To Whom It May Concern:

To update you on this, I did indeed scan every one of my computers (all the scans came up clean), change all my passwords, and switch to using SFTP instead of FTP to administer my website. A colleague of mine who frequents my website, to whom I had suggested Surpass for his own hosting needs and now uses your site, alerted me yesterday to the fact that his site was similarly attacked in the same time frame as mine, and I see that a third Surpass shared hosting customer had a problem on April 17th (note this thread: http://www.surmunity.com/showthread.php/32454-I-ve-been-hacked). This is hugely concerning, and suggests that the problem is a security breach at Surpass rather than a customer problem.

Because of this blackhat SEO attack, my website is (hopefully temporarily) nearly completely absent from Google search results, which has had a very negative impact on traffic to my website. If the fault was me using potentially compromised machines, poor access methods, or weak passwords, it certainly would be my fault and not at all your responsibility, but if a compromise of Surpass is the issue here, then I would appreciate being appraised of this security breach, provided assurance that the issue has been resolved to protect against future attacks, and my lost traffic addressed. I would appreciate any feedback on the issue at your earliest convenience. Thanks again for what I'm sure will uphold your excellent tradition of superb customer support in my experience.

Sincerely,
(me)
Quote:
and my lost traffic addressed


How do you value your traffic, and how you could you possibly expect them to abide by your own metric? I mean, you could value every hit at 1 billion dollars a piece. Then if you lost more than 15000, you could demand 15 Trillion dollars in reparation!
I have no monetary value on traffic, although if I had site advertisements, I could more precisely quantify monetary losses by lost pageviews * advertisements per page * cost per thousand impressions for advertisements. Anyway, they responded to me:

Quote:
Hello,

This attack is quite common. The FTP logs Ariel posted show a legitimate FTP login with legitimate credentials:

==
[redacted]
==

Hackers will typically compile gathered passwords\accounts into a large list and quite often get the credentials of two completely unrelated accounts that happen to reside on the same server. We are constantly working to keep our servers up to date and secure from vulnerable services on our end.

Regards,


Lukas K.
Security Analyst
Surpasshosting.com, LLC.
Maybe I missed this, but has Google moved forward on removing the label?
elfprince13 wrote:
Maybe I missed this, but has Google moved forward on removing the label?
The label is long gone (unless your question was based on actually checking and finding that it was not gone), but the search results have not yet been fully or even more than barely partially reinstated.
  
Register to Join the Conversation
Have your own thoughts to add to this or any other topic? Want to ask a question, offer a suggestion, share your own programs and projects, upload a file to the file archives, get help with calculator and computer programming, or simply chat with like-minded coders and tech and calculator enthusiasts via the site-wide AJAX SAX widget? Registration for a free Cemetech account only takes a minute.

» Go to Registration page
Page 2 of 2
» All times are UTC - 5 Hours
 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

 

Advertisement