Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > Network / Server Status
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network / Server Status Please check often for network / Server updates here!

Reply
 
Thread Tools Display Modes
  #1  
Old 07-14-2003, 07:10 PM
Bladesnitz
Guest
 
07/14/2003 Cpanel2.nocspeed.com READ IMMEDIATELY

Due to the recent security issues all ssh access has been suspended. Also ALL accounts must change their passwords for ftp, mysql and control panel. Note the changing the password in the control panel also changes it for ftp.

You have 48 hours to change your passwords. Any user account that has not changed password at that time will have their password changed for them.

Examples of good passwords would be sKp19Dv25

We are going to re-evaluate our previos stance on ssh as it appears that a number of resellers were giving ssh access to all accounts. It is probable that ssh access will be removed from this machine.
Reply With Quote
  #2  
Old 07-15-2003, 04:51 AM
Hostlead Hostlead is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: www.hostlead.com
misread

remove this post if possible

HL

Last edited by Hostlead : 07-15-2003 at 05:55 AM.
Reply With Quote
  #3  
Old 07-15-2003, 05:35 AM
sean
Guest
 
Hostlead, we offer 2 control panels: Hsphere and cpanel. This is for our cpanel customers on the server cpanel2.nocspeed.com and has no effect on you or the other Hsphere customers.
Reply With Quote
  #4  
Old 07-15-2003, 05:46 AM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Like it or not, it is to your advantage to comply with their request. If any passwords have been compromised which is probably unlikely, though I don't know the full story on what happened but it sounds more precautionary to me, anyway if they have and it's your password used to enter the system becuase you couldn't be bothered changing it, and it's used to cause further "damage" then lets just say I wouldn't like to be you !.

Personally if it was me I wouldn't have given even 48 hours notice, I'd have changed all control panel and ftp passwords immediately.

Edit: Seems it doesn't effect you anyway!
Reply With Quote
  #5  
Old 07-18-2003, 02:54 PM
MichaelB
Guest
 
Even though this doesn't affect our H-Sphere clients I would recommend that everyone examine their passwords. We've been looking at some of the user passwords on our servers and there are people actually using "password" as their password.

Take some time and make yourself a strong password, replace some of the letters with numbers like replace a "i" with a one and capitalize a letter in the middle. You can take a weak password like "password" and make it "P@22W0rD" which will take weeks to guess. If you don’t like that find a pattern on the keyboard you like, if your first initial is "M" then "cderfgyhn" would make the shape of an "M" on the keyboard. Next month you can use "iopol.,./" for the letter "I".

Most of you already know this but I'm just repeating it for the newer people who may think passwords don't need to be strong if you're not working with state secrets. WRONG, make sure you have a strong password, if someone has your password they can carry out actions on the server just like you, in fact we will treat it just as if you did it so you would be responsible for their actions.

Bottom line, if your password exists in any sort of list somewhere, be it dictionary, fictional book or high school year book you are at risk. There is no fee to change a password and it only takes 10 seconds.

I will now step down from my soapbox.
Reply With Quote
  #6  
Old 07-18-2003, 08:09 PM
Brangwyn Brangwyn is offline
T3CHN0 STUD
Vortech Inc. Customer
 
Location: New Zealand (Wellington)
Actually I'd be more concerned that you can actually examine the passwords, this implies clear text storing of them somewhere and is probably a bigger risk than just weak user passwords.
Reply With Quote
  #7  
Old 07-18-2003, 08:10 PM
landiserve
Guest
 
Brangwyn, that isn't the case.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
12.08.2003 - cpanel2.nocspeed.com bigdave Network / Server Status 12 12-09-2003 02:32 PM
07/13/2003: cpanel2.nocspeed.com Bladesnitz Network / Server Status 14 07-14-2003 04:37 PM
07/14/2003 Cpanel2.nocspeed.com hostnet Network / Server Status 1 07-14-2003 01:13 PM
07/10/2003: cpanel2.nocspeed.com Bladesnitz Network / Server Status 0 07-10-2003 09:28 PM
06/18/2003 cpanel2.nocspeed.com MichaelB Network / Server Status 2 06-20-2003 05:23 PM


All times are GMT -5. The time now is 06:03 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.47864 seconds with 14 queries
[Output: 61.23 Kb. compressed to 56.67 Kb. by saving 4.56 Kb. (7.44%)]