Archive for April, 2009

Phishing Sites on Gnome

Several accounts have been reported on this server as having fraud sites (of banks, Paypal, etc) and the server has been put on probation by the data center for cancellation.

We encourage all our clients to manually check their accounts for suspicious files or scripts not belonging to their account. We do not want this server to be disconnected by the data center for repeated offense.

April 19th, 2009

Internal Server Error on Warden

We discovered a problem with the Warden server (72.232.240.26) this morning that all sites return an Error 500 (Internal Server Error) when loading PHP files.

Accounts with simple HTML are not affected by the problem. We are figuring out the cause of this issue and is trying to resolve the problem as soon as possible. We will update this post for additional information along the way.

Update 1: File and folder permissions of accounts are fine as well as ownership. Memory limits in PHP.ini have been adjusted.

Update 2: Running cPanel Update and updating all Perl Modules. (Will run EasyApache next). Still running cPanel update….

Update 3: Recompiling PHP thru EasyApache.

April 11th, 2009

DNS Problem on Gravatar Server

We discovered the problem with Gravatar server a bit late. Our monitor showed it was running fine but it turns out there was a problem with the DNS. This was fixed right away.

April 9th, 2009

Phishing Attack on Gnome

Today, the Data Center has shut down the Gnome server (72.232.186.26) for several hours after discovering two accounts from our clients hosting a phishing website for Bank of America and Wells Fargo.

We coordinated with the DC engineers to get the server back online so we could investigate and remove the phishing sites.

It turns out that the two accounts by clients have folders that were open and allowed culprits to upload a zipped file of the fake website and extract them. We have deleted the files and secured the folders. We’re still looking into other client accounts that may have similar cases.

We request all clients to regularly and actively check their accounts for open folders (CHMOD them to 644) and update any add-on scripts or web apps they have installed so to avoid similar incidents in the future.

April 5th, 2009


plogHost Web Services

Calendar

Related Posts

April 2009
M T W T F S S
« Feb    
 12345
6789101112
13141516171819
20212223242526
27282930  

Posts by Month

Posts by Category