1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Hostgator Hosting Account Hacked!!

Discussion in 'Security' started by NaughtyNeo, Mar 5, 2008.

  1. #1
    Today I noticed significantly low traffic and revenue for some of my main sites. At first I thought it was act of google god. So I checked the SERPS, but everything was fine. When I checked my sites, many of my sites were redirecting to searchportal.information.com ! :eek: I almost had a heart attack thinking that someone got hold of my domains from the registrar and is redirecting. But when I checked my account at enom, all the domains are safe and is pointing towards the correct name servers at hostgator.
    When I checked my hosting account at hostgator I found most of my add-on domains were missing. That is when it struck me. Some cheater who is using the same shared hosting account at hostgator logged into my account and deleted all those domains from my account. He then added those domains to his account. Since the domains were pointing to the same nameservers, it was just a matter of adding an index page for each domain with searchportal.information.com opened in frames. ( See my site, http://www.domainnameswebhost.net/ ) Damn cheater!!! :mad:

    I have contacted the live support guy at hostgator at around 4:30pm (US time). His first reaction was that the domain got expired. But later he understood that the domain is registered in my name till 2010 and there are several domains. He then asked me to send an email to support. Opened a support ticket and sent an email by 5:00pm. At 7:00 pm the linux system admin from hostgator support team moved the ticket to their security section. As I am posting this thread I am still waiting to hear back from them.
    I will update this thread how their support team handle this issue. :rolleyes:

    I think this is a serious security issue. If they don’t terminate the account of the cheater, then anyone who is sharing the same server can get into trouble. :(
     
    NaughtyNeo, Mar 5, 2008 IP
  2. cooldude7273

    cooldude7273 Active Member

    Messages:
    185
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #2
    Yeah, BUT. Was the hacking of your account your fault any?

    One of my sites was once hacked and completely defaced. Sure, I'd love to blame the hacker, because, well, he hacked me, but I was also to blame as there was a vulnerability in one of my scripts that let him walk right in. If I had kept my scripts up to date, it wouldn't have happened.

    Do you know of anything like this in your case? Is your password a common one perhaps? Any old vulnerable scripts?
     
    cooldude7273, Mar 5, 2008 IP
  3. northwest

    northwest Peon

    Messages:
    277
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Thanks for putting this info out. I need to watch my domains now... Hope they delete the cheater's account.

    Good luck...
     
    northwest, Mar 5, 2008 IP
  4. NaughtyNeo

    NaughtyNeo Peon

    Messages:
    829
    Likes Received:
    41
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Thanks for the reply.
    Other than wordpress I only have one script used on this hosting account. That is snews on a subdomain. But that shouldn't be the problem since even if he is able to hack the domain, he shouldn't able to enter into my cpanel. When I logged into my capenl I found that the last login was from a different ip than mine.
    Also I have a seperate password and login for my hosting and cpanel which I do not use anywhere else.
     
    NaughtyNeo, Mar 5, 2008 IP
  5. NaughtyNeo

    NaughtyNeo Peon

    Messages:
    829
    Likes Received:
    41
    Best Answers:
    0
    Trophy Points:
    0
    #5
    NaughtyNeo, Mar 5, 2008 IP
  6. primeryder

    primeryder Well-Known Member

    Messages:
    1,658
    Likes Received:
    40
    Best Answers:
    0
    Trophy Points:
    158
    #6
    Never heard of that happeneing before...a true cautionary tale. But the cheater will lose his account just for a couple of days of traffic. What a waste.
     
    primeryder, Mar 5, 2008 IP
  7. NaughtyNeo

    NaughtyNeo Peon

    Messages:
    829
    Likes Received:
    41
    Best Answers:
    0
    Trophy Points:
    0
    #7
    By the folks,
    Hostgator support team fixed the issue after almost 12 hours. They haven't told me what exactly went wrong. But I am glad that my sites are back and running. :)
     
    NaughtyNeo, Mar 6, 2008 IP
  8. eoveru

    eoveru Banned

    Messages:
    60
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    I have seen this issue popping up with hostgator several times in the past 24 hours. Could be a problem with someone getting into hostgators system unauthorized.
     
    eoveru, Mar 6, 2008 IP
  9. jsb

    jsb Guest

    Messages:
    100
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #9
    It would be helpful if they let you know how it happened, unless of course it was a security flaw on their end, in which case they would want to keep that to themselves :).

    I'm sure other hosts get hacked too, this is just the 2nd Hostgator one I have read about this week though.
     
    jsb, Mar 6, 2008 IP
  10. NaughtyNeo

    NaughtyNeo Peon

    Messages:
    829
    Likes Received:
    41
    Best Answers:
    0
    Trophy Points:
    0
    #10
    The support guy from hostgator told me it is probably a cpanel bug which caused the domains disapper from the add-on domain list. And he syas the domains were still there and working. It is just that it disappered from add-on domains list.

    But I don't think that is the case, because 18 of my domains were showing a webpage with searchportal.information.com opened in frame. Also, my top traffic domain is a blog which was removed from the blog list at fantastico.

    It could be a cpanel security issue or hostgator themselves is redirecting all the pages to searchportal.information.com on domains which are not properly set-up. But since I don't know the exact reason, I won't blame the hostgator guys completely. May be it's cpanel issue like this one: http://forums.digitalpoint.com/showthread.php?t=740313
     
    NaughtyNeo, Mar 6, 2008 IP
  11. NoobieDoobieDo

    NoobieDoobieDo Peon

    Messages:
    1,456
    Likes Received:
    53
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I also use Hostgator and have found their email support team to be very slow. One time I waited 3 hours to get my cpanel pw reset. Eventually I just got a live chat agent to do it. Other than that HG has been great.
     
    NoobieDoobieDo, Mar 20, 2008 IP
  12. COBSolutions

    COBSolutions Well-Known Member

    Messages:
    2,379
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    190
    #12
    I also host atleast 10 domains with hostgator, yet to find any issues, the live chat is used by me frequently to sort out the issues and they are quite quick-have never used any other support systems though
     
    COBSolutions, Mar 22, 2008 IP
  13. mattmoo

    mattmoo Peon

    Messages:
    29
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    yes, this has just happened to me today on 2 domains hosted within an aluminum account with hostgator.

    i am trying to get onto hostgator about it now, but their website is timing out! if they give me an helpful advice i will post it here.

    matt
     
    mattmoo, May 12, 2008 IP
  14. Joomla Dude

    Joomla Dude Banned

    Messages:
    592
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #14
    OMG,this sounds bad.
    I have been with Hostagator,but i nevre faced any sort of problems using it. Actually,i also use the Live Support in their homepage frequently and so i get all of my doubts cleared by that..
    Better to take help from them always,if you have any sort of suspense in your account ...
     
    Joomla Dude, May 12, 2008 IP
  15. amoona

    amoona Peon

    Messages:
    56
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    You do the correct thing man! The guy who did these tricks is really stupid!
     
    amoona, May 26, 2008 IP
  16. hostgator

    hostgator Peon

    Messages:
    73
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #16
    This definitely isn't a hacking. The url it was going to is the url we have setup on our servers so that if a domain doesn't exist we collect the traffic and send it there. Any money made off this page is then donated to charity.


    Do you have a ticket number I can look at?
     
    hostgator, May 26, 2008 IP
  17. hostgator

    hostgator Peon

    Messages:
    73
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #17
    The netcraft url is from a cpanel exploit that affected thousands of hosts and took place over a year ago. (definitely not the issue)
     
    hostgator, May 26, 2008 IP
  18. geckojohn

    geckojohn Peon

    Messages:
    1,037
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #18
    How does everyone else like hostgator?
     
    geckojohn, May 26, 2008 IP
  19. andyoudontstop

    andyoudontstop Peon

    Messages:
    42
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #19
    HostGator tends to be one of the better providers out there for their price bracket.
     
    andyoudontstop, Jun 16, 2008 IP
  20. AfterHim.com

    AfterHim.com Peon

    Messages:
    1,923
    Likes Received:
    51
    Best Answers:
    0
    Trophy Points:
    0
    #20
    I love hostgator...I have two accounts and about 80 domains hosted with them....I have hacking problems all the time as well. The hacker uploads files via FTP...always stuff about khmercoder.
     
    AfterHim.com, Jul 6, 2008 IP