Hacked!

June 6, 2007

For those who aren’t aware Dreamhost expe­ri­enced a secu­rity breach. Accord­ing to Dreamhost, approx­i­mately 3,500 accounts were com­pro­mised, the hack­ers tak­ing note of FTP user accounts, user names and passwords.

With this data the hack­ers, using an auto­mated script of some sort, added SEO links/inframes to every instance of index.html or php.

This is the last straw. I’ve been with Dreamhost since mid-2004 and rec­om­mended them on more than one occa­sion and even went so far as defend­ing them when oth­ers com­plained about slow ser­vice or half-baked cus­tomer sup­port, the lat­ter being some­thing I never experienced.

Not any more. It’s time to look for a new home.

Over the past two hours I’ve had to comb over my files, look­ing for any­thing that could have been stolen and to my knowl­edge some files might have been removed.

Not only that, but the pass­word I used was one of the best pass­words I’ve used in a long time and now, thanks to this, I have to piece together a franken-mash of numbers.

It’s sad because while I rep­re­sent, accord­ing to DH, only .15% of the cus­tomers whose data was changed in some way, I just wish some­thing could’ve been done to pre­vent this.

Yet, who am I to say that web host­ing is safe from this kind of thing, which appar­ently it isn’t. I sup­pose I wanted to believe that they were impen­e­tra­ble, even if that was a pre­ma­ture wish.

The cul­prits added inframes and link­age point­ing to off­shore sites dis­play­ing gar­bled infor­ma­tion; SEO tac­tics indeed.

On the bright side of things, my entries are safe, every one of them accounted for since 2004. This wasn’t an issue really con­sid­er­ing I’ve kept back­ups of my DB since the begin­ning and make it habit to do it frequently.

I’m also plan­ning on mov­ing to a new CMS and will be tak­ing the entries with me to pre­serve for the future, when robots make swiss cheese sand­wiches with George For­man machines.

Does any­one out there have any sug­ges­tions for a new host? 

17 comments

Man, that would make me sick to my stom­ach. Sorry to hear about it.

I’ve been really happy with both Medi­aTem­ple (since they got most of the issues with gs worked out) and Web­fac­tion. My per­sonal sites are located on Web­fac­tion, which is great if you like a lit­tle more con­trol of your server configuration.

by David Hemphill on June 7, 2007 at 1:18 am. Reply #

Sorry to hear you got the short end of the stick with this Erik.

I checked my account this morn­ing and, as far as I could tell, there were no hack­ing attempts on my side. I did change all pass­words, how­ever. Then again, my sites are in such a lethar­gic activ­ity level than I’d rather like to see some action going on — even from hack­ers. :P

I wish I could have some handy web host­ing rec­om­men­da­tions but if my pre­vi­ous expe­ri­ence is any indi­ca­tion, all of them have a weak side to exploit. The 100% bul­let­proof web host seems more illu­sion than real­ity. I’ve been with Inter­land, (mt) and some other “lesser” hosts — and all of them sucked at tech sup­port, secu­rity breaches, or both.

I’ll be how­ever inter­ested to see what other wor­thy host­ing rec­om­men­da­tions you get for consideration.

by beto on June 7, 2007 at 1:52 am. Reply #

Man that sucks. I’m sure, since they are so pop­u­lar they have a big taget on their backs. I’d like to know if this has ever hap­pened to some of the other large host­ing com­pa­nies (MT for example).

I just moved to Dreamhost :) , but I have not noticed any changes to my pages. What exactly is a “SEO links/inframes” so I can look for that? *crosses fingers*

Sorry, no sug­ges­tions for a new host. But, I asked for some sug­ges­tions on 9rules; looks like thieir site’s down now, I’ll get you the link.

by Mike on June 7, 2007 at 8:09 am. Reply #

I’ve been very happy with Media Tem­ple though I’ve only been with them for 9 months or so. In the­ory any host could get hacked though, it’s just a mat­ter of the skill and deter­mi­na­tion of the hacker.

by Ben G. on June 7, 2007 at 11:23 am. Reply #

I really like axishost.com. The owner, Tina, has a great rep­u­ta­tion on webhostingtalk.com, and is always very help­ful when I have any kind of issue. They’re turn­ing into a large host, but main­tain­ing the small host feel when it comes to per­sonal atten­tion. The only down­side is that they don’t have sup­port via the phone, which would be nice.

But they have excel­lent prices, fast sup­port via tick­ets, and near flaw­less uptime. I’d highly rec­om­mend you look into them.

by Chris Huff on June 7, 2007 at 11:47 am. Reply #

How about Medi­atem­ple?

by Nicolas on June 7, 2007 at 1:22 pm. Reply #

It hap­pened to me too. Twice. But I’ve also heard that this has hap­pened to a num­ber of other web host­ing com­pa­nies before. Thus far, I have been very happy with the ser­vice that DreamHost offers and I intend to give them the ben­e­fit of the doubt. It seems that their pro­pri­etary con­trol panel is partly to blame, and they have taken steps to make sure this does not hap­pen again. Our par­tic­u­lar accounts were selected for hack­ing because of our pop­u­lar­ity, so I sup­pose we should be flat­tered as well as angry.

Ulti­mately though, I blame the scum­bags who actu­ally did the deed. It is easy to chas­tise DreamHost for sloppy secu­rity, but how many busi­nesses and indi­vid­u­als can claim that their sys­tem is 100% impreg­nable? Some­how, these crea­tures always find a way through the most dra­con­ian of secu­rity mea­sures and spread their evil wares.

by Simon Jessey on June 7, 2007 at 2:06 pm. Reply #

I have a hos­ing com­pany :D , http://brainhub.net if you wanna have a look. If you’re look­ing for some­thing more like a vps sys­tem, I rec­om­mend my pre­vi­ous host, http://cheapvps.co.uk. :D
Of course, ASO are awe­some too ^^

by Political Monster on June 7, 2007 at 2:34 pm. Reply #

Mike: Well, up until this point I was pretty much con­tent with their service.

Oh and I meant “iframes”, not inframes. The hack­ers slipped in an iframe which pointed to a gar­bled, over­seas web site. That and they messed with the .htac­cess file with brute force to redi­rect var­i­ous links to SEO sites.

Ben , Chris and Nico­las: Thanks for the rec­om­men­da­tions. I’m open to them right now and have a list com­piled for alter­na­tives when I decide to move to a new home.

These things hap­pen, I under­stand that, but it’s just a pain in the neck. I’ve been research­ing new hosts for a few months now so this is just an extra push I suppose.

Simon: You’re cer­tainly more for­giv­ing than I am, and you’ve been hacked twice!

Some­how, these crea­tures always find a way through the most dra­con­ian of secu­rity mea­sures and spread their evil wares.

Right on!

by kartooner on June 7, 2007 at 10:12 pm. Reply #

Sorry to hear about that Erik. I’ve been with Lunarpages since 2004, and out­side of that one time when they took my site down because I was using my con­tact form to spam the entire intraweb, they’ve been pretty good.

New CMS? Tell me more.

by Greg on June 8, 2007 at 1:16 am. Reply #

I’ve decided to host with Medi­aTem­ple. They appear to be a solid oper­a­tion and their con­trol panel is a site to behold.

If all goes as planned, I shouldn’t be down for too long, but it all depends on how smooth the process will be.

Thanks again every­one for your thoughts and suggestions.

by kartooner on June 8, 2007 at 3:58 pm. Reply #

The new CMS will more than likely be Textpat­tern, but I’ve got my eye on Expres­sion Engine as well, so it’ll be a toss up, that’s for sure.

Should I just flip a coin?

by kartooner on June 8, 2007 at 4:00 pm. Reply #

I’d go for Expres­sion Engine. More ver­sa­tile and a nicer designed sys­tem too.

by James AkaXakA on June 10, 2007 at 8:40 am. Reply #

Well, I’ve moved over to Medi­aTem­ple but I still need to fix a few things.

by kartooner on June 11, 2007 at 9:34 pm. Reply #

Web Designer, Devel­oper, Flash Desiger, PHP, Graphic Designer

by Rajan on June 14, 2007 at 12:20 pm. Reply #

I’ve been with Medi­aTem­ple for a few years now and they’ve never dis­ap­pointed me. I think you’ll do fine with them.

by Leon on June 22, 2007 at 12:38 pm. Reply #

I heard about this breech. Scary stuff! If it hap­pened to me, I would be in a lot of trouble!!!

Who are you using now? I am using start­logic dot com, but I am look­ing to move very soon.

by Dui on February 23, 2008 at 3:42 am. Reply #

Leave your comment

Required.

Required. Not published.

If you have one.