Hackers nail unsecure websites on Afrihost server

Yes that is the gist of the article, BUT is there something missing at the Host Service Provider level that can be done Globally?

Some enforceable standards to be met and maintained before a website will be accepted for hosting? Or, does the mighty Dollar rule again?

Website development and maintenance standards should be available. Then we get to website hosting criteria that need to be met before a site will even be hosted.

Not in the field, just interested.
In all honesty if they try to enforce a global setting other than SSL on me I will get a different host.
 
Well, according to the article, Afrihost does try and make those websites aware of outdated plugins, but I'd be pretty annoyed if they tried to take control of my site (even if it's only to update plugins) as that's not what they are paid for, they are paid to host.

Precisely! There is a clear demarcation point between the two functions which should address control issues, security requirements etc. But like all interfaces, there has to be some standard that both parties need to comply to for an overall quality service.
 
Okay so we have SSL as a criteria. Anymore? What about the need for a regular audit report showing how up to date the website sw used by a site is and that plug ins have been updated? Would you object to such a requirement from a hosting service?
 
Precisely! There is a clear demarcation point between the two functions which should address control issues, security requirements etc. But like all interfaces, there has to be some standard that both parties need to comply to for an overall quality service.

As long as your security issues don't affect other sites, I don't see the issue if you want to run an outdated wordpress site that will get hacked.

Okay so we have SSL as a criteria. Anymore? What about the need for a regular audit report showing how up to date the website sw used by a site is and that plug ins have been updated? Would you object to such a requirement from a hosting service?

Don't see the point of that as you can easily check what plugins/wordpress theme/core a site is using.

Just checking MyBB for theme:
http://whatwpthemeisthat.com/
1. WP Polls
2. WP Pro Quiz
3. Simple Lightbox

and some stock images.

You can also use plugins like: Wordpress Theme and Plugin Detector (Chrome).

I am fine with mandating it if the exploit patched might lead to other sites being compromised, otherwise the hosting service should not get involved unless support is asked for and the hosting service provider offers support for WP.
 
Last edited:
As long as your security issues don't affect other sites, I don't see the issue if you want to run an outdated wordpress site that will get hacked.

But how does a Host service provider ensure that a specific sites' security issue does not spill over into sites on the same hosting platform?

The tone of the title to this article implied exactly that ( to me anyway). Then some of the statements in the article suggested the possibility as well.

I don't know the answers. Just trying to get the thinking around the topic going. What are the hackers trying to do here? Bring down the sites for evil purposes or are they drawing attention to an issue that hosting service providers should be addressing?
 
But how does a Host service provider ensure that a specific sites' security issue does not spill over into sites on the same hosting platform?

The tone of the title to this article implied exactly that ( to me anyway). Then some of the statements in the article suggested the possibility as well.

I don't know the answers. Just trying to get the thinking around the topic going. What are the hackers trying to do here? Bring down the sites for evil purposes or are they drawing attention to an issue that hosting service providers should be addressing?
I added to my post above. The hackers are having fun finding sites that do not upgrade their security, most of those who get into hosting sites know that it is not the service provider at fault and MyBB is wrong to post Afrihost's name in the title as it implies that they are partially to blame when they are not.
 
I added to my post above. The hackers are having fun finding sites that do not upgrade their security, most of those who get into hosting sites know that it is not the service provider at fault and MyBB is wrong to post Afrihost's name in the title as it implies that they are partially to blame when they are not.

I agree, quoting AH in the title is wrong and unnecessary to the gist of what the topic is about.

My issue is what should I as a company looking for someone to host my website, be looking for when comparing hosting services available? I guess my years in the business of writing specs for tenders is surfacing. Surely it is more than just price, connectivity and location?
 
Last edited:
I agree, quoting AH in the title is wrong and unnecessary to the gist of what the topic is about.

My issue is what should I as a company looking for someone to host my website, be looking for when comparing hosting services available? I guess my years in the business of writing specs for tenders is surfacing. Surely it is more than just price, connectivity and location?

Support/SLA, to connectivity add redundancy,
Not sure if location is that important, you can use a CDN if you have a lot of content you need to move. I don't host a lot of sites though. It would be nice if MyBB could input on this, would be an interesting article especially if it was in a form of review among local providers.

It always depends on use-case and budget.
 
I agree, quoting AH in the title is wrong and unnecessary to the gist of what the topic is about.

My issue is what should I as a company looking for someone to host my website, be looking for when comparing hosting services available? I guess my years in the business of writing specs for tenders is surfacing. Surely it is more than just price, connectivity and location?

I would say it's mainly about the hosting environment that you need. It also depends if you want a physical server or a cloud server. :)
 
But how does a Host service provider ensure that a specific sites' security issue does not spill over into sites on the same hosting platform?

The tone of the title to this article implied exactly that ( to me anyway). Then some of the statements in the article suggested the possibility as well.

I don't know the answers. Just trying to get the thinking around the topic going. What are the hackers trying to do here? Bring down the sites for evil purposes or are they drawing attention to an issue that hosting service providers should be addressing?
Containers. Virtualization the sites are all on little containers and don't affect each other.
 
Here is an email Web Space Bar sent to clients on the 20th Feb 2017 regarding maintenance. Read the bold part.

Good evening

If you are receiving this email, you are on a server that is scheduled for migration.

This weekend everyone on darkmoon.webspacebar.co.za will upgrade to a larger server.

The reason we are migrating everyone is due to a new server being built with more resources and great new software, this new server, will have the following features:

* running the latest version of WHM & Cpanel
* raid 1+0 on SSD drives for the best speed
* this new server has 128gig ram, up from 32 gig on the current server,
* this new server has 12 CPU cores, up from 8 Cores on the current server,
* this new server will run patchman, see http://patchman.co , thats right, we are paying for a lisence to help folks running wordpress & joomla to ensure vunerabilities are detected and mitigated while users are notified (patchman is tested on the current server and its working great)
* this new server will run imunify360, see https://imunify360.com
* outbound mail relay remains to go via mailchannels which is out outbound spam filter, since we started using this we have never had a single IP get blacklisted due to someone trying to send spam from our enterprise, which is great for business as your mail sent to a customer will never be rejected due to a inbound ip being on a blacklist.

I trust everyone will love the experience on the new hardware.

So to sum it all up, newer, stronger, faster, better, and the price to our customers still remains the same.

Migration will begin at 18:00 on Friday 24 February , and should conclude by Sunday.

As always we are at your service, if you have any questions please don't hesitate to let us know.

Wishing you all a great evening and a fantastic week ahead.

Kind Regards
Team Web Space Bar
 
Here is an email Web Space Bar sent to clients on the 20th Feb 2017 regarding maintenance. Read the bold part.

Thanks for sharing that. :)

I'll pass that onto our Server Admins, I'm sure they are already know Patchman.co but maybe it's something we can look at. :)
 
It's irresponsible for any hosting company nowadays to offer hosting without automating patches to such common software as WordPress.

Let's also not forget that Afrihost is incapable of properly configuring MX records for their clients. I don't need to say more than this: https://mybroadband.co.za/vb/showth...accepting-mail-properly-for-more-than-a-month (yes, they still have not fixed a year old issue)

Sorry Afrihost, you don't have a sterling record when it comes to hosting services using technology of the 21st century...
 
It's irresponsible for any hosting company nowadays to offer hosting without automating patches to such common software as WordPress.

Let's also not forget that Afrihost is incapable of properly configuring MX records for their clients. I don't need to say more than this: https://mybroadband.co.za/vb/showth...accepting-mail-properly-for-more-than-a-month (yes, they still have not fixed a year old issue)

Sorry Afrihost, you don't have a sterling record when it comes to hosting services using technology of the 21st century...

What if a plugin is discontinued or has a buggy update? We'll always do the best that we can for our Clients, but when it comes to website content and making changes to it - which updated plugins potentially can, especially when it comes to changes to themes - we have to be very careful not to disrupt the Clients content.

Our Team did deal with your MX record query in detail, if you continue to have any queries relating to that you're more than welcome to reply to the ticket and I'll follow-up on it for you. :)
 
I was not knocking Afrihost.
I mentioned AfriGenie, to say I feel their pain, because users or their website supporters should patch WP and run a decent security module.

And no. Afrihost (or any host for that matter) would be opening a nasty can of worms if they auto update every users' WP and modules. Half of the rubbish people run have not been updated on over 3 years. Madness!
 
It's irresponsible for any hosting company nowadays to offer hosting without automating patches to such common software as WordPress.

Let's also not forget that Afrihost is incapable of properly configuring MX records for their clients. I don't need to say more than this: https://mybroadband.co.za/vb/showth...accepting-mail-properly-for-more-than-a-month (yes, they still have not fixed a year old issue)

Sorry Afrihost, you don't have a sterling record when it comes to hosting services using technology of the 21st century...

Wordpress has built-in auto update for plugin/core, they don't need to use a system to automate it.
 
Our Team did deal with your MX record query in detail, if you continue to have any queries relating to that you're more than welcome to reply to the ticket and I'll follow-up on it for you. :)

Very ingenious answer which is not true. Refer to ticket KDQ-689-72684 from June 2016 - the issue was never resolved and my last email never received the courtesy of a reply:
<snip>My point is that on any given day Afrihost (via pseudo.ucebox.co.za) reports the highest (upwards of 4000) transient errors with your MTAs refusing a connection. If your MTA is rate-limiting, my expectation would be to receive a 421 instead of just terminating the connection.

I also think that your MX records in your hosted environment are misconfigured - as an example, recipient host: [redacted].co.za: The preferred MX record points to pseudo.ucebox.co.za, of which ALL IPs refuse connection).

Although the number of errors reduced since I raised the issue beginning in May, I do still believe that MX configuration within your environment is incorrect (refer to Pastebin link for domains affected yesterday - http://pastebin.com/mF5228PT)

Since you refused to ever properly fix the problems, we transiently fail about 40,000 transactional mails to customers hosting their domains with you (about 800) - case in point for April:
[root@mailserver pmta]
[root@mailserver pmta]# date
Wed Apr 19 21:36:10 SAST 2017

# grep -i "(no answer from host),,pseudo.ucebox.co.za " acct-2017-04-*-0000.csv | wc -l
37660

It is therefore also quite a moot point to try and enlighten you on how to properly host commodity applications such as Wordpress or Joomla. Even your marketing material (and I think you remember how that worked out with ISPA) stats "Your website will be securely hosted on the latest hardware at state-of-the-art data centres." and "Security. There are hackers out there who enjoy causing havoc. A web hosting company will generally have experience in ensuring their client's websites are as secure as possible."

There are many hosting providers out there (WPEngine.com for example) which can completely secure your WordPress installation. As a hosting company it is surely not that difficult to deploy a security scanner such as Sucuri or WPScan and then mitigate such vulnerabilities through regular scans. Wordpress installations specifically are predictably structured (plugin directory anyone) that you can very easily bulk-scan your virtual hosts on a regular basis. Any decent hosting provider will also have the capability to automatically patch WordPress core without impacting your client.

It is really a cheap shot to make your hosting customers responsible for "not updating plugins" when you as a hosting provider took 5 weeks to contain the attacks. You were also not pro-actively aware of the attacks, but had to be told by your hosting clients and from the feedback I received you were initially not very concerned about it until a large number of sites on the one IP got defaced.

I am done commenting on this topic, but felt it is worthwhile for others to put it into perspective: It is very easy for a hosting provider to scan hosted domains for WordPress vulnerabilities. It is reckless for a hosting provider to have clients being attacked for 4-5 weeks.
 
Very ingenious answer which is not true. Refer to ticket KDQ-689-72684 from June 2016 - the issue was never resolved and my last email never received the courtesy of a reply:


Since you refused to ever properly fix the problems, we transiently fail about 40,000 transactional mails to customers hosting their domains with you (about 800) - case in point for April:


It is therefore also quite a moot point to try and enlighten you on how to properly host commodity applications such as Wordpress or Joomla. Even your marketing material (and I think you remember how that worked out with ISPA) stats "Your website will be securely hosted on the latest hardware at state-of-the-art data centres." and "Security. There are hackers out there who enjoy causing havoc. A web hosting company will generally have experience in ensuring their client's websites are as secure as possible."

There are many hosting providers out there (WPEngine.com for example) which can completely secure your WordPress installation. As a hosting company it is surely not that difficult to deploy a security scanner such as Sucuri or WPScan and then mitigate such vulnerabilities through regular scans. Wordpress installations specifically are predictably structured (plugin directory anyone) that you can very easily bulk-scan your virtual hosts on a regular basis. Any decent hosting provider will also have the capability to automatically patch WordPress core without impacting your client.

It is really a cheap shot to make your hosting customers responsible for "not updating plugins" when you as a hosting provider took 5 weeks to contain the attacks. You were also not pro-actively aware of the attacks, but had to be told by your hosting clients and from the feedback I received you were initially not very concerned about it until a large number of sites on the one IP got defaced.

I am done commenting on this topic, but felt it is worthwhile for others to put it into perspective: It is very easy for a hosting provider to scan hosted domains for WordPress vulnerabilities. It is reckless for a hosting provider to have clients being attacked for 4-5 weeks.

@rpm can you get a follow-up with the ones whose site was defaced to confirm/deny the above?
 
@rpm can you get a follow-up with the ones whose site was defaced to confirm/deny the above?

The point I tried to make and neither Afrihost or MyBB has covered (and this would apply to almost all of the local cheap hosting providers such as AH) is that none have the basic operational procedures in place.

This becomes very evident that sites can get defaced and remain like this for days and weeks and attacks continue for up to 5 weeks (granted against different websites, but still targeting Afrihost infrastructure). It is therefore a very cheap shot to blame clients for the defacement, especially under the circumstance, that AH markets their hosting as "easy". Let's distinguish that most of us have more experience than AH engineers themselves, but most of their customers rely on that CPanel "Install Wordpress button" and assume that AH will make sure that everything else is safe.

It would be wishful thinking that ISPs such as Afrihost have security precautions consistent with ISO/IEC 27002 in place or pass a SAS 70 Type II examination but honestly they would not even pass the most basic PCI level compliance (although not required any IT company should follow it as it covers best practises).

I doubt that most hosting providers such as Afrihost have the capability of regular vulnerability scanning of all infrastructure, servers, databases and applications and mitigation in place. They would also lack independent regular penetration testing. Hardly anyone encrypts backup media (or isolates client backup-media).

Based on the fact that infrastructure was attacked for 5 weeks, it is highly unlikely that AH has intrusion detection or intrusion prevention systems in place. Yes, people say that the client environments are "jailed / isolated" and it is the client's responsibility to protect their sites (in the same line of thought, if you have a house in an estate with estate security and the estate security lets anyone into the estate and you get robbed, who would be accountable?).

What the article did not cover is the fact that Afrihost is actually not aware of how the sites were defaced. It is highly unlikely that a good 80 websites share the same outdated plugin. It rather sounds that a WordPress CPanel core installation was outdated allowing the specific attack vector.

With any opensource software such as WordPress and 3rd party contributed plugins it must be 100% expected that malicious code can enter a system. A decent hosting provider would have system scanners in place which search for vulnerable plugins and would automatically disable them. It would be in the interest of a hosting provider to have a mechanism to disallow certain plugins for performance reasons. Just have a look at WPEngine to get a view on why certain plugins are disallowed: https://wpengine.com/support/disallowed-plugins/

Providing hosting services and being good at it is never easy and requires consistent attention - something AH has seemingly not given to their clients for a good 5 weeks.
 
Top
Sign up to the MyBroadband newsletter
X