hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : When a dedicated server gets compromised ....
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

When a dedicated server gets compromised ....

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 10-24-2007, 09:52 PM
GaryPilot GaryPilot is offline
Newbie
 
Join Date: Oct 2007
Posts: 21

When a dedicated server gets compromised ....


I have a dedicated/managed server at a host at $299 per month and the /tmp directory got compromised by a spammer. They sent out spam and so far 4 spam monitoring sites have black listed my IP.

The question is should this have been caught by the hosting company ? Should this have even happened?

Reply With Quote


Sponsored Links
  #2  
Old 10-24-2007, 10:03 PM
KarlZimmer KarlZimmer is online now
THE Web Hosting Master
 
Join Date: Jan 2003
Location: Chicago, IL
Posts: 6,538
Quote:
Originally Posted by GaryPilot View Post
I have a dedicated/managed server at a host at $299 per month and the /tmp directory got compromised by a spammer. They sent out spam and so far 4 spam monitoring sites have black listed my IP.

The question is should this have been caught by the hosting company ? Should this have even happened?
Do they state that that is covered in their managed services?

__________________
Karl Zimmerman - Steadfast Networks: Dedicated Servers and Premium Colocation
karl @ steadfast.net - AIM: KarlAZimmerman - Sales/Support: 312-602-2689
2 Data Centers and 20,000+ sqft. in Chicago (350 E Cermak) + Manhattan Data Center
Cloud Hosting, Managed Dedicated Servers, Chicago Colocation, and New York Colocation

Reply With Quote
  #3  
Old 10-24-2007, 10:29 PM
Techark Techark is offline
Web Hosting Master
 
Join Date: Apr 2002
Location: Australia or US depends
Posts: 5,723
Depends how long was it compromised?
No one can catch 100% of /tmp exploits the instant they happen.
If it was there for a week or so then yeah they should have caught it, it is was there a day then no not always will it be caught right away.

More important thing you should be asking is did they help you ID the cause how /tmp got compromised and help close the hole up or at least tell you what needed to be upgraded or removed to avoid it happening again.

No hosting company can stop you or your users from uploading or running outdated code on your web sites. The blame for how the files got there most likely rest with what ever user it was that failed to update their software.

Or you can ask them to tighten the screws so tight on the server security it becomes almost useless for regular hosting.

__________________
Techark Web Hosting
Cloud Servers and Managed Dedicated Servers with Live Proactive Monitoring
My Blog of Random Thoughts

Reply With Quote
Sponsored Links
  #4  
Old 10-24-2007, 11:03 PM
creaws creaws is offline
WHT Addict
 
Join Date: May 2007
Posts: 129
Someone must have found the spammer out, suspend the account and then let the client know, thatīs the normal procedure.

__________________
http://creawebsolutions.com
Server Management & Web Security.


Reply With Quote
  #5  
Old 10-24-2007, 11:13 PM
Jay Suds Jay Suds is offline
Web Hosting Master
 
Join Date: Jun 2001
Location: Denver, CO
Posts: 3,210
As with most other questions on here, "it depends". What exactly is included in the managed services they provide? Managed means many different things to many different people / companies. Some people consider a managed service to simply be unlimited support of all technical issues, with everything handled in a reactive manner. Others consider fully managed to be proactive handling updates, patching, monitoring, backups, response to downed services. And there's a lot that fall in between the first example and the second. We primarily do fully managed for Windows customers, and while it's actually quite rare for a whole box to get exploited, we do make it our mission to figure out what happened, and make sure it doesn't happen again.

__________________
Jay Sudowski // Handy Networks LLC // Co-Founder & CTO
AS30475 - Level(3), HE, Telia, XO and Cogent. Noction optimized network.
Offering Self Managed and Fully Managed Linux and Windows Dedicated Solutions from our Private Denver Data Center.
Current specials here. Check them out.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Researchers Urge System Admins to Check for New Apache Web Server Backdoor Malware Web Hosting News 2013-05-01 11:35:53
SSHD Rootkit in the Wild Blog 2013-02-22 16:44:08
Web Host Milesweb Launches Dedicated Server Hosting in India Web Hosting News 2012-12-31 10:53:51
Canadian Web Host BlackSun Launches Customized Dedicated Servers Web Hosting News 2012-05-28 14:35:45
Web Host 1&1 Enhances Dedicated Server Line with 32 Core, 64 GB RAM Server Web Hosting News 2011-12-20 15:30:05


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?