Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 08-17-2005, 11:29 AM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
NT33 Possible Hack Attempt!!

We will be rebooting NT33 due to an attack on the system with in the next 10 to 15 min to fix some issues.

We will be sending out an email to all customers once this has been fully done, we will ask all resellers to notify there customers to change there FTP and SQL passwords at that time to be 100% safe. Please change your password at this time or ASAP if you are NT33.

The issue seems to have come from a Microsoft Hole in the OS that has now been fixed and patched after calling Microsoft about this issue. We have also applied this patch to all windows 2000 boxes.

We are also making a few changes that should also help prevent this from happening again, e.g. using Patch Quest ( http://www.securecentral.com/products/patchquest/ ) and Anti Virus software on all the systems to help keep you and them a bit safer.


We are also looking in to better fire walling the network, the issues there is passive FTP, we are going to talk about this today in our meeting to see if we can't find a work around for this today. This will help a lot if we can find a way to do this today.

Thank you and we are very sorry about the issue and are doing everything we can like I said to make our systems 100% safe.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:

Last edited by admin : 08-17-2005 at 02:56 PM.
Reply With Quote
  #2  
Old 08-17-2005, 01:41 PM
dpyers's Avatar
dpyers dpyers is online now
Vortech Inc. Customer
Vortech Inc. Customer
 
Quote:
Originally Posted by admin
We are also making a few changes that should also help prevent this from happening again, e.g. using ... and Anti Virus software on all the systems to help keep you and them a bit safer.
Would the AV be for user initiated ftp?
__________________
Reply With Quote
  #3  
Old 08-17-2005, 02:09 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
No this is more less to scan the boxes to keep them from getting a virus or hack attempt.

It will scan the files in your FTP to be sure there is no virus in there and remove it if there is. But it will not be checking that in real time.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #4  
Old 08-17-2005, 02:26 PM
drobee drobee is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: washington, dc
Easiest way to determine which users are on NT33

What's the easiest way to determine which users are on NT33?
Reply With Quote
  #5  
Old 08-17-2005, 02:41 PM
soky's Avatar
soky soky is offline
Don't touch the hair!
Vortech Inc. Customer
 
Location: Southern Kentucky (SoKy)
Send a message via Yahoo to soky
never mind
__________________
David Francis
Soky.net, llc http://www.SoKy.net
Soky Happenings Magazine http://www.SokyHappenings.com


Last edited by soky : 08-17-2005 at 02:51 PM.
Reply With Quote
  #6  
Old 08-17-2005, 02:48 PM
generic's Avatar
generic generic is offline
guess who.. :)
Vortech Inc. Customer
 
Location: chicago
was just trying to figure that out myself....got to be an easy way..
__________________
goodbye idevaffiliate, you can kiss my @$* with your poor support and broken script, I am now using post affiliate pro 3
Reply With Quote
  #7  
Old 08-17-2005, 02:50 PM
soky's Avatar
soky soky is offline
Don't touch the hair!
Vortech Inc. Customer
 
Location: Southern Kentucky (SoKy)
Send a message via Yahoo to soky
I was able to find mine quickly enough by...

1) Opening admin account
2) Searching for all accounts
3) Logging on to each account in the list
4) Clicking the file manager in the quick access page
5) Read the address bar and it will show the box (http://nt38.domain.com......)

It was quick enough since Vortech keeps their servers so clean and the HSphere control panel is so responsive. (whew)

I'm a Windows only reseller so I don't know about Unix garba... eh... stuff. (Laughing... don't kill me.)
__________________
David Francis
Soky.net, llc http://www.SoKy.net
Soky Happenings Magazine http://www.SokyHappenings.com

Reply With Quote
  #8  
Old 08-17-2005, 02:55 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
Quote:
Originally Posted by soky
I was able to find mine quickly enough by...

1) Opening admin account
2) Searching for all accounts
3) Logging on to each account in the list
4) Clicking the file manager in the quick access page
5) Read the address bar and it will show the box (http://nt38.domain.com......)

It was quick enough since Vortech keeps their servers so clean and the HSphere control panel is so responsive. (whew)

I'm a Windows only reseller so I don't know about Unix garba... eh... stuff. (Laughing... don't kill me.)


Soky there is an easier way to do this.

1) Opening admin account
2) Searching for all accounts
3) Click the account ID number.


We have a way on our side to search for users on servers but it just lists all the users. We can't cut it down to just a reseller or I would offer to do that to make it easier.

It is safe to now change all passwords and please do this ASAP.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #9  
Old 08-17-2005, 02:58 PM
admin's Avatar
admin admin is offline
Vortech Inc. Owner
Owner
 
Location: Orlando FL
Send a message via ICQ to admin
The new firewall rules are also now in place. If you have any issues please let us know.

We are also updating our rules for snort as well, so we will be watching ports 1024 and up very close for things that should not be there now.
__________________
Brad Pugh
http://www.vortechhosting.com
------

Local System/Network Monitor
http://nagios.hsphere.cc/
Login:guest Pass:guest
XML FEED http://nagios.hsphere.cc/feed.xml
------

My Other Life:
Reply With Quote
  #10  
Old 08-17-2005, 03:00 PM
soky's Avatar
soky soky is offline
Don't touch the hair!
Vortech Inc. Customer
 
Location: Southern Kentucky (SoKy)
Send a message via Yahoo to soky
Quote:
Originally Posted by admin
Soky there is an easier way to do this.

1) Opening admin account
2) Searching for all accounts
3) Click the account ID number.



Oh... yeah... that's slick. Thanks.
__________________
David Francis
Soky.net, llc http://www.SoKy.net
Soky Happenings Magazine http://www.SokyHappenings.com

Reply With Quote
  #11  
Old 08-17-2005, 03:10 PM
glebreck glebreck is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
I am having problems with Using passive FTp on NT39 as well as NT9. Is this the same issue?
Reply With Quote
  #12  
Old 08-17-2005, 04:01 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
True Hack attempt? or just Zotob which started doing the rounds yesterday ?
Reply With Quote
  #13  
Old 08-17-2005, 04:44 PM
devorem's Avatar
devorem devorem is offline
"right to lifer"
Vortech Inc. Customer
 
Location: Cow Country, USA
I couldn't tell you for sure if it was related or not, but one of my clients (on NT33) had their index.htm file replaced over the weekend with one that featured some gruesome pictures of mutilated children and it said:

YOU ARE CAUSE OF ALL THAT HAPPENED

FOR IRAQ,

FOR AFGHANISTAN,

FOR PALESTINE,

FOR ALL COUNTRIES UNDER SIEGE LIKE ABOVE.

TO BE CONTINUED...

HACKED BY Cool_Baby & sanaleskiya

TURKISH HACKERS

I was able to replace the file with a copy from Google cache. Apparently, my client didn't catch it in time and the hacked copy had already been backed up so Vortech wasn't able to restore it. I bought a copy of "Site Shelter" to back up my client's sites as a result of all of this.
Reply With Quote
  #14  
Old 08-17-2005, 04:55 PM
Jim Nayzium Jim Nayzium is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
If I am on NS1 - NS4 only, then I have no worries and don't need to change my passwords correct??

NT shows up nowhere on my ID listings....
Reply With Quote
  #15  
Old 08-17-2005, 05:00 PM
devorem's Avatar
devorem devorem is offline
"right to lifer"
Vortech Inc. Customer
 
Location: Cow Country, USA
Those are your name servers/DSN servers. That is not what we're talking about. You need to check to see what web server your sites and the sites of your customers are on.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
NT33.hsphere.cc byron Network / Server Status 2 07-23-2005 02:35 AM
phpBB Continues To Be a Hack Vector admin Chit Chat Public 5 05-09-2005 03:08 PM


All times are GMT -5. The time now is 04:51 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.87590 seconds with 26 queries
[Output: 116.33 Kb. compressed to 107.17 Kb. by saving 9.16 Kb. (7.87%)]