My Dreamhost panel got hacked with my 30+ clients website

Discussion in 'Security' started by tipsguru, Aug 10, 2008.

  1. #1
    Guyz.... I'm in big big trouble, don't know what to do...
    i got this mail from dreamhost few hours ago

    Your DreamHost account contact email preferences were just changed via:
    https://panel.dreamhost.com/id/?tab=contact

    The old account contact email address(es):


    The new account contact email address(es):


    The time of the change:
    2008-08-10 15:57:54 (Pacific Time)

    (This account manages the following domains:
    *all of my hosted domain names* )

    IF YOU DIDN'T MAKE THIS CHANGE, PLEASE LET SUPPORT KNOW IMMEDIATELY
    by going to https://panel.dreamhost.com/?tree=support.msg

    Or, if you can't log in there , you can contact support at:
    https://www.dreamhost.com/contact.cgi

    Your contact email addresses are crucial to the security of your account!

    If you DID make this change, you can ignore this message.

    Thanks,
    The Happy DreamHost Account-Email-Change-Double-Checking Team!


    I've mailed them, but no reply yet. but the most dangerous thing is all of my hosted sites are not opening, and all files has been delated! Before inactivating my accounts the hacker deleted all of my files.

    What to do now? I'm gonna die...
     
    tipsguru, Aug 10, 2008 IP
  2. nimhost

    nimhost Active Member

    Messages:
    235
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    58
    #2
    have you scanning your computer ?
    maybe your computer get trojan, spyware, keylogger on it because i don't think dreamhost will publish their client username and password info :)
     
    nimhost, Aug 15, 2008 IP
  3. Louis11

    Louis11 Active Member

    Messages:
    783
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    70
    #3
    Uhm . . . Yea i'm gonna bet that Dreamhost doesn't release usernames and passwords :rolleyes: And if they do I would switch immediately! :p

    On a more serious note, the attack may have come from a form of malware, but more likely resulted in a server compromise or web application attack.

    You've done the right thing by contacting the host immediately. However when you get your site(s) back up make sure you patch all of the software you are using.

    You mentioned hosting several client websites: are you on an unmanaged dedicated server? If so, what have you done for security?

    Hope you have a backup plan in place!
     
    Louis11, Aug 19, 2008 IP