My Dedicated Server

Discussion in 'Site & Server Administration' started by EGS, Sep 17, 2006.

  1. #1
    My dedicated server was suspended recently for phishing and spam, as my host claims. However, I have not used my dedicated server at all for email or communication - just for web space and hosting my websites.

    My server's been down for over 24 hours and I am furious. They are recommending that I pay over $450 in fees for this when I have done nothing. Keep in mind that I'm basically poor and can barely afford my dedicated server per month.

    What should I do? I'm really pissed because I didn't do anything...they say they got complaints from my server for phishing and spam emails when I have given nobody my server's password or access to it, nor do I even have a lot of sites hosted on it.

    I don't see what happened. The only way I can contact their abuse dept. is through email, too, which pisses me off. I can call for all other help except that. Worse thing is that I was billed a few days ago, and basically I'm not getting what I paid for.

    I didn't do anything, but I don't know how to prove it! :(
     
    EGS, Sep 17, 2006 IP
  2. Icheb

    Icheb Peon

    Messages:
    1,092
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    0
    #2
    You don't have to prove anything. Unless they have hard evidence that you did something wrong you should quickly go to a lawyer and have him contact them.
     
    Icheb, Sep 17, 2006 IP
  3. The Webmaster

    The Webmaster IdeasOfOne

    Messages:
    9,516
    Likes Received:
    718
    Best Answers:
    0
    Trophy Points:
    360
    #3
    You dont have to prove any damn thing..

    Ask them to prove that you used your server for phishing and spamming...
    And get your lawer ready and send them a pre judiciary notice...
     
    The Webmaster, Sep 17, 2006 IP
  4. EGS

    EGS Notable Member

    Messages:
    6,078
    Likes Received:
    438
    Best Answers:
    0
    Trophy Points:
    290
    #4
    Well apparently there was a lot of PayPal phishing emails being sent out from my server, so someone obviously was able to connect to my server's mail server and send out phishing emails from that.

    I think its pretty ridiculous though that my server wasn't secure enough to reject these connections and in the long run I'm taking the heat for someone else's work..
     
    EGS, Sep 17, 2006 IP
  5. happymondays

    happymondays Well-Known Member

    Messages:
    515
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    108
    #5
    What is your hosting company?
    I mean I have a lot of stories with hosting companies, including (worse on)theplanet where replacing a 2 weeks old but faulty HD took them 2 business days (200 sites down...) but this what you have here is really something.
     
    happymondays, Sep 17, 2006 IP
  6. EGS

    EGS Notable Member

    Messages:
    6,078
    Likes Received:
    438
    Best Answers:
    0
    Trophy Points:
    290
    #6
    They're trying to charge me a LOT of money for this when I didn't even do anything and honestly I can't even afford it...anyone have any recommendations? I can't afford a lawyer. =\
     
    EGS, Sep 18, 2006 IP
  7. Scriptona

    Scriptona Notable Member

    Messages:
    4,957
    Likes Received:
    265
    Best Answers:
    0
    Trophy Points:
    280
    #7
    who said u have to get a lawyer ?

    just tell them this

    " either you prove that my server was used for spamming or my lawyer will be happy to handle that case specially when i promise him of 50% of the compensation i'll get from you "

    this should work like a charm for those bastards trying to dig in the webmasters pockets to live
     
    Scriptona, Sep 18, 2006 IP
  8. wormy

    wormy Active Member

    Messages:
    1,112
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    80
    #8
    I had the same problem with my web host. I had a dedicated server too and they shut me down within 6 hours. How did I get out of it? I made a big fuss and created trouble tickets and double checked my security and finally convinced them to let me have it back. But there is one thing you need to realize(which I suspected in my case too) and that thing is...you have been hacked! :eek:
     
    wormy, Sep 19, 2006 IP
  9. Nintendo

    Nintendo ♬ King of da Wackos ♬

    Messages:
    12,890
    Likes Received:
    1,064
    Best Answers:
    0
    Trophy Points:
    430
    #9
    ev1servers.com is the best in the west.

    Oh, as a wise man once asked...'Wh[o] is your hosting company?'
     
    Nintendo, Sep 19, 2006 IP
  10. mihd

    mihd Peon

    Messages:
    136
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #10
    quite simple dont host in US! way to expensive, there are some excellent providers in europe

    if they claim your server was sending spam it prob was, if its an unmanaged server it up to you to secure it, linux believe it or not is not that secure out of the box :0

    but still i wouldnt pay 400$ fine, that sort of money will get you 4x 100mbit unmetered pentium4's in germany :)
     
    mihd, Sep 19, 2006 IP
  11. MattUK

    MattUK Notable Member

    Messages:
    6,950
    Likes Received:
    377
    Best Answers:
    0
    Trophy Points:
    275
    #11
    Did you have any scripts installed that can send out emails? I had a similar problem with a PHPBB install last year.
     
    MattUK, Sep 19, 2006 IP
  12. onedollar

    onedollar SEO Consultant for Hire

    Messages:
    3,481
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    0
    #12
    as MattUK says, most likely due to some security hole in some script you've got installed
     
    onedollar, Sep 19, 2006 IP
  13. EGS

    EGS Notable Member

    Messages:
    6,078
    Likes Received:
    438
    Best Answers:
    0
    Trophy Points:
    290
    #13
    I'm looking at that possibility, but I don't see any scripts installed on my server that aren't secure that can do that function. :x
     
    EGS, Sep 19, 2006 IP
  14. MattUK

    MattUK Notable Member

    Messages:
    6,950
    Likes Received:
    377
    Best Answers:
    0
    Trophy Points:
    275
    #14
    None of them have sendmail functionality?
     
    MattUK, Sep 19, 2006 IP
  15. daredashi

    daredashi Well-Known Member

    Messages:
    667
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #15
    are you running your own sites or also renting server for other sites ?
    if you are renting out then check their domains.

    check your mail server logs for "nobody" originated mails. check you mail server for open mail relay.

    ask your web host to pass on phissing email header to findout mail originator IP / location and other things

    its probability that your server is compramised. check logs for IP access other than yours. if you don't find any logs for login of you ip then check for log permissions. check package MD5 sums (i am assumming you have *nix server)

    install root kit (http://www.chkrootkit.org/) and check services ehich are causing more resource usage than normal or spawnning even not called.

    why you are not disclossing web host name ??:rolleyes:
     
    daredashi, Sep 19, 2006 IP
  16. sarathy

    sarathy Peon

    Messages:
    1,613
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #16
    i had same problem with hostgator and was suspended. After some mails to the abuse dept, they replied that an article script that i used in one of the domains was used to send over 2 lakh spam mails by a spammer.
    They quickly resolved the issue and my sites were live again.,
     
    sarathy, Sep 19, 2006 IP
  17. falcondriver

    falcondriver Well-Known Member

    Messages:
    963
    Likes Received:
    47
    Best Answers:
    0
    Trophy Points:
    145
    #17
    thats because they have no speed limits at the data highway in germany!

    scnr :)
     
    falcondriver, Sep 19, 2006 IP
  18. EGS

    EGS Notable Member

    Messages:
    6,078
    Likes Received:
    438
    Best Answers:
    0
    Trophy Points:
    290
    #18
    Well believe me I am checking them and making sure all of them are up to date but right now I'm having FTP problems so this is just great...my server may still be vulnerable and I'm not trying to get my server suspended again for something someone else has done.
     
    EGS, Sep 19, 2006 IP
  19. Mong

    Mong ↓↘→ horsePower

    Messages:
    4,789
    Likes Received:
    734
    Best Answers:
    0
    Trophy Points:
    235
    #19
    Its allegations on you and in result you have lost many hours.
    Its really sad.

    Allegations of spam are understandable because some scripts can be exploited to spam freely but i don't know that scripts can be exploited for phising. :(

    Confirm what exactly has happened to them ..
    There must be some unsafe scripts on your websites.
     
    Mong, Sep 19, 2006 IP
  20. Mong

    Mong ↓↘→ horsePower

    Messages:
    4,789
    Likes Received:
    734
    Best Answers:
    0
    Trophy Points:
    235
    #20
    Temporarily host somewhere else.. because it can take time to resolve with current host.
     
    Mong, Sep 19, 2006 IP