Cozahost hacked

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,196
Anybody else hosting their websites on cozahost?

They got hacked recently, and the hacker seems to have damaged their server OS (Windows2003). They are in the process of reinstallation etc.

Regards

Libs
 

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,196
Just subscribed to their Twitter feed. FTW.

But if you host websites and the such, then it makes more sense to use a RAID for fault tolerance? :confused: Or am I missing something completely?

Or was somebody asleep at the steering wheel?

The email we received from them tells a different story :

Hi,
At approximately 20h00 last night our main web server became unstable.
Your web sites are hosted on this server.
Attempts to recover the server failed due to severe data corruption on the system drive.
At about 03h00 hours today, the main drive was replaced. As at 05h30 the new drive format completed and the OS is being loaded. We are working on this full time.
Once the operating system is reinstalled, all the web servers, user access lists, ftp servers and accounts and so on will be re-created. Databases (ie MySQL and SQL server was not affected and is still online).
Indications are that these seemingly unrelated incidents during the last weeks are related. We are now considering the possibility of foul play and that our servers were deliberately attacked. It seems likely. Our first priority is to recover as much of our services as quickly as possible - only then will be conduct a forensic audit to investigate the possibility of criminal activity.
Given the circumstances and lead-up to this, we are very concerned that our backups of your web content was deliberately subverted - but we can only check that once the server is online again.
Deliberate damage to our backups seem likely though. Please make preparations to re-upload your web content to the server as soon as you receive confirmation from us that your access accounts and server was recovered. Our advice would be to prepare for the worst and contact your web developer (or your own backups) with the view of uploading your content in the event our recovery attempts fail.
All resources at our disposal is assigned to resolve this issue as soon as possible - we will be updating facebook.com (http://www.facebook.com/cozahost), Twitter (http://twitter.com/cozahost) and Ops (http://ops.cozahost.com) with our progress.
Note that we expect the helpdesk to be extremely busy dealing with this, so if you can avoid phoning by using the network status announcement on our phone line or (better) Facebook or Twitter to keep tabs on our progress it will be much appreciated...and allow the helpdesk agents to productively help with the recovery process.
Regards,
Waldo
 

rorz0r

Executive Member
Joined
Feb 10, 2006
Messages
7,968
At about 03h00 hours today, the main drive was replaced. As at 05h30 the new drive format completed and the OS is being loaded. We are working on this full time.

That definitely doesn't sound like they are using a SAN or even RAID... (or ghost)
 

w1z4rd

Karmic Sangoma
Joined
Jan 17, 2005
Messages
49,747
It sounds like theyre setting up their users for "sorry we didnt backup".
 

Datura

Captain Faptastic
Joined
Oct 12, 2006
Messages
47,705
Racists! Just because it's black doesn't mean you must blame it!

:mad:
 

rorz0r

Executive Member
Joined
Feb 10, 2006
Messages
7,968
If you take out the bits like "we are attending" in their twitter feed it reads like this:

*Hay guys, I bought a pc and I haz a internet connection, want me to host your websitez?
*I'm installing windows and wamp now
*Ok we're good to go, upload all your stuff
*Oh I forgot, installed filezilla ftp so now you can upload
*Some 1337 h4x0r guessed my password and got in so I've installed norton antivirus
*Everythings back online now
*Sorry guys I tripped over the power cord for the server, we're back online now but the server has some anomalies
*Onoz, C: failed so we've lost everything, I'm going to incredible connection to buy a new drive
*ok windows almost installed again, you can upload your stuff when it's done.
 

Grep

Senior Member
Joined
Nov 21, 2006
Messages
958
cant believe hosting providers aren't using VM now days. Good grief.
 
Top