hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Reseller Hosting : Client's account hacked! Provider says I need to pay for investigation!

Reply

Reseller Hosting Advice, experiences, and recommendations on reseller providers and discussion of other services required for web hosting reselling. If your service is unavailable, please click here.
Forum Jump

Client's account hacked! Provider says I need to pay for investigation!

Reply Post New Thread In Reseller Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-10-2012, 08:03 AM
Mikey this way! Mikey this way! is offline
Rocco Alive!
 
Join Date: Oct 2004
Location: Here @ WHT
Posts: 1,349
*

Client's account hacked! Provider says I need to pay for investigation!


Hello,

One of my clients account got hacked and spam was sent through it. Provider rightly suspended the account and brought it to my notice.

I asked how we can proceed and my reseller host says I need to either convince them (which I see not possible for various reasons/criteria mentioned) or pay up consulting fee for them to investigate and clean the account.

I will only be provided a backup to investigate

I donot possess the advanced knowledge to investigate after a certain point nor do my clients.

I've been a Hosting Provider and have worked with various hosts over the past 10 years. This is the first time I have encountered such a thing.

This thing (charging fee for investigation) I see has started very recently. Is this normal for hosts to charge such fees?

Please let me have your comments.

__________________
One Ring to rule them all, One Ring to find them, One Ring to bring them all and in the darkness bind them

Reply With Quote


Sponsored Links
  #2  
Old 03-10-2012, 08:07 AM
Wintereise Wintereise is offline
Web Hosting Master
 
Join Date: Dec 2010
Location: Good Question
Posts: 565
Uh, I don't see why not. If it's an unmanaged service, they've every right to demand payment for doing what essentially counts as 'management'

Reply With Quote
  #3  
Old 03-10-2012, 08:08 AM
linux_geek linux_geek is offline
Newbie
 
Join Date: Mar 2012
Posts: 22
What kind of hack is it?

Reply With Quote
Sponsored Links
  #4  
Old 03-10-2012, 10:17 AM
RRWH RRWH is offline
Web Hosting Master
 
Join Date: Mar 2005
Location: Australia
Posts: 1,186
What does their TOS say? Did you agree to this when you signed up?

It is not unreasonable as long as it is covered under their TOS.

__________________
No advertising here.... Move along.

CPanel Shared and Reseller Hosting, OpenVZ VPS Hosting


Reply With Quote
  #5  
Old 03-10-2012, 11:10 AM
Xarwin Xarwin is offline
Newbie
 
Join Date: Mar 2012
Posts: 25
^ What RRWH said.
Check with what you agreed.

Reply With Quote
  #6  
Old 03-10-2012, 03:32 PM
SajanP SajanP is offline
WHT Content Curator
 
Join Date: Mar 2007
Location: USA
Posts: 4,686
It certainly is normal for a hosting provider to charge for necessary tasks that must be done which are outside the scope of of normal service. Finding, investigating, suspending, and cleaning an account would fall into that.

__________________
Sajan Parikh
Feel free to get in touch with me if I can be of assistance with anything.
PHP Development | Server Management | Linux Administration | Web Consulting
p: (563) 726-0371 e: email@sajanp.com | t: @sajanNOPPIX | w: http://sajanp.com

Reply With Quote
  #7  
Old 03-10-2012, 04:04 PM
astutiumRob astutiumRob is offline
Will Host for Food
 
Join Date: Jul 2002
Location: London, United Kingdom
Posts: 3,679
Quote:
Originally Posted by Mikey this way! View Post
I donot possess the advanced knowledge to investigate after a certain point nor do my clients.
So you have to pay for someone who does have that knowledge.

You can put fuel in your car, you can wash your car, you can drive your car, but if you dont know how to investiagte where that gawd-awful-smell is coming from 5 minutes into your journey, you pay someone to investigate at a garage !

__________________
Rob Golding Astutium Ltd - UK based ICANN Accredited Domain Registrar - proud to accept BitCoins
Buying Web Hosts and Domain Registrars Today @ hostacquisitions.co.uk
UK Web Hosting | UK VPS | UK Dedicated Servers | ADSL/FTTC | Backup/DR | Cloud
UK Colocation | Reseller Accounts | IPv6 Transit | Secondary MX | DNS | WHMCS Modules

Reply With Quote
  #8  
Old 03-10-2012, 08:35 PM
Eggyak Eggyak is offline
Temporarily Suspended
 
Join Date: Mar 2012
Posts: 102
Ive never really understood why hosting companies become hosting companies if they don't know how to manage a hosting company... even worse.. admit it in public.

Get harder passwords, and scan your site on a regular basis! it helps.

Reply With Quote
  #9  
Old 03-10-2012, 08:54 PM
Stuart_c Stuart_c is offline
Junior Guru Wannabe
 
Join Date: Feb 2012
Posts: 86
Quote:
Originally Posted by Mikey this way! View Post
Hello,

One of my clients account got hacked and spam was sent through it. Provider rightly suspended the account and brought it to my notice.

I asked how we can proceed and my reseller host says I need to either convince them (which I see not possible for various reasons/criteria mentioned) or pay up consulting fee for them to investigate and clean the account.

I will only be provided a backup to investigate

I donot possess the advanced knowledge to investigate after a certain point nor do my clients.

I've been a Hosting Provider and have worked with various hosts over the past 10 years. This is the first time I have encountered such a thing.

This thing (charging fee for investigation) I see has started very recently. Is this normal for hosts to charge such fees?

Please let me have your comments.
lol! y should ur host help u with a hacked site for free? did they advertise that they will help clean up the mess if u got poor security?

for them to even offer u the option is a good thing. Some will just tell u to do it urself!

how much did they want to charge for investigation?

Quote:
Originally Posted by Eggyak View Post
Ive never really understood why hosting companies become hosting companies if they don't know how to manage a hosting company... even worse.. admit it in public.

Get harder passwords, and scan your site on a regular basis! it helps.
haha! true. u should always do ur research because people that suffer are ur customers and they dont deserve poor service

Reply With Quote
  #10  
Old 03-10-2012, 10:00 PM
Yujin Yujin is offline
Always Ask...Don't Pretend!
 
Join Date: Aug 2010
Location: CPU
Posts: 2,065
Charging because the website was hacked?

Do you really need to investigate this? Or you can asked them to restore the most recent backup and update the script?

If this is a reseller account, your provider do not investigate the issue. It is your job or the website owners job to ensure that your script are updated and secure. The best and quickest way is ask your provider to restore the website and asked your client to fix the script.

__________________
Ask for Server IP & Nameservers IP to check if your reseller provider truly provides 100% white-label.


Reply With Quote
  #11  
Old 03-11-2012, 03:50 AM
CrocWeb CrocWeb is online now
Corporate Member
 
Join Date: Aug 2009
Location: Canada
Posts: 1,219
They should unsuspend the account and allow you time to clean/secure it yourself. Change all passwords. Then Ensure all scripts/plugins/addons are up to date. If the host offers ClamAV or similar, run it and make sure the account is clean. There could still be malicious code within files, if possible reupload them.

If you or your host takes daily backups, restoring from it would also be a good choice. Once restored, be sure to change passwords and update scripts.

__________________
CrocWeb :: Fastest, Reliable & Affordable Canadian Hosting
cPanel - LiteSpeed - MySQL on SSD - RVSiteBuilder Pro - CloudFlare - Softaculous - and much more!
www.crocweb.com :: Now hosting over 50,000 domains!

Reply With Quote
  #12  
Old 03-11-2012, 06:37 AM
FernGullyGraphics FernGullyGraphics is offline
Dependable Web Services
 
Join Date: Jun 2010
Location: Modesto, Ca. - USA
Posts: 4,933
Quote:
Originally Posted by Mikey this way! View Post
Hello,

One of my clients account got hacked and spam was sent through it. Provider rightly suspended the account and brought it to my notice.

I asked how we can proceed and my reseller host says I need to either convince them (which I see not possible for various reasons/criteria mentioned) or pay up consulting fee for them to investigate and clean the account.

I will only be provided a backup to investigate

I donot possess the advanced knowledge to investigate after a certain point nor do my clients.

I've been a Hosting Provider and have worked with various hosts over the past 10 years. This is the first time I have encountered such a thing.

This thing (charging fee for investigation) I see has started very recently. Is this normal for hosts to charge such fees?

Please let me have your comments.
Unfortunately this is starting to become a bigger and bigger issue, the number cause I have found for sites being hacked is people going out and downloading free themes from untrusted places and using them for their websites. Often times free themes are either poorly written or contain malicious code from the start.

The second most common reason for a site being hacked (at least in my experience) are webmasters accessing website credentials via FTP from unsecure computers (hackers will hack the computer and harvest web hosting credentials from your computer).

To get to the bottom of this I would A.) find out what type of website your client was running (Wordpress, joomla..ect) and find out if they recently installed a free theme? B.) Make sure the users computer is secure and that they have a active/up to date firewall/virus protection installed on the computer they are using to FTP or access the account from.

Hope that helps!

__________________
Fernando Diaz Alfaro - Owner of FernGullyGraphics - Since 2001
Shared and Reseller Web Hosting Services - Web Design - Domain Names
Cloud Linux - Varnish Cache - WHM/Cpanel - CloudFlare - Softaculous - RVSiteBuilder Pro
Learn more about our services at www.FernGullyGraphics.com

Reply With Quote
  #13  
Old 03-11-2012, 07:39 AM
RC-Martin RC-Martin is online now
Web Hosting Master
 
Join Date: Dec 2009
Location: Greece
Posts: 784
Quote:
Originally Posted by Mikey this way! View Post
Hello,

One of my clients account got hacked and spam was sent through it. Provider rightly suspended the account and brought it to my notice.

I asked how we can proceed and my reseller host says I need to either convince them (which I see not possible for various reasons/criteria mentioned) or pay up consulting fee for them to investigate and clean the account.

I will only be provided a backup to investigate

I donot possess the advanced knowledge to investigate after a certain point nor do my clients.

I've been a Hosting Provider and have worked with various hosts over the past 10 years. This is the first time I have encountered such a thing.

This thing (charging fee for investigation) I see has started very recently. Is this normal for hosts to charge such fees?

Please let me have your comments.
How much did they ask to get the job done? I find it logical to ask for a fee to do this,but it all depends on the price they asked.

Reply With Quote
  #14  
Old 03-12-2012, 01:02 PM
Mikey this way! Mikey this way! is offline
Rocco Alive!
 
Join Date: Oct 2004
Location: Here @ WHT
Posts: 1,349
Lol! I see a lot of responses which include saying why am I in the hosting business . The reason I asked coz my current provider never did this and this is the first time they have asked. I see that they do have a point in charging me fee which I initially thought was not justified.

Hence, I request the mods to close this thread...

__________________
One Ring to rule them all, One Ring to find them, One Ring to bring them all and in the darkness bind them

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
Reseller hosting provider suspended a client's account Jatinder Reseller Hosting 16 01-26-2012 02:29 PM
Client won't pay or cancel their account yghosting Running a Web Hosting Business 15 02-22-2007 09:37 PM
Help: Client got hacked... ORiN Running a Web Hosting Business 4 10-29-2004 09:26 AM
One Client Site Hacked belindaj Hosting Security and Technology 9 07-05-2004 11:55 PM
Client's Site Has Been Hacked!! Mans Hosting Security and Technology 11 09-15-2003 08:01 AM

Related posts from TheWhir.com
Title Type Date Posted
SwaggSec Hackers Release 900 Admin Credentials from China Telecom Attack Web Hosting News 2012-06-04 15:24:03
Survey Finds 40 Percent of Site Owners Change Opinion of Web Host After Hack Web Hosting News 2012-02-24 10:41:36
Dutch Telecommunications Firm KPN Stops Issuing SSL Certificates After Hack Detected Web Hosting News 2011-11-07 15:29:02
1.3 Million User IDs and Passwords Stolen in Washington Post Jobs Site Hack Web Hosting News 2011-07-07 14:41:28
Hackers Crack Fox News Twitter, Post False Report of Obama's Death Web Hosting News 2011-07-05 14:08:59


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?