MWEB's Domain hosting - not so secure?

Priapus

Honorary Master
Joined
Jun 8, 2008
Messages
21,577
Reaction score
16,472
Location
England
Hi all,

So myself and a friend of mine have / had domains hosted with MWEB. My domain was hacked three times this month. That was after increasing security on my Wordpress site and making sure Wordpress was up to date.

Also - the site would randomly just go down. So I got over it and moved to Afrihost today.

My friend's site was also hacked. Just rather random and we both on MWEB. Maybe that has nothing to do with it?

Anyone else having these sorts of issues?
 
Dude, yes!

A client of mine has been hacked three times in the last week. I'm moving all of my Mweb clients to Hetzner.

Rubbish host, horrific service and just all round bad experience.
 
Hi all,

So myself and a friend of mine have / had domains hosted with MWEB. My domain was hacked three times this month. That was after increasing security on my Wordpress site and making sure Wordpress was up to date.

Also - the site would randomly just go down. So I got over it and moved to Afrihost today.

My friend's site was also hacked. Just rather random and we both on MWEB. Maybe that has nothing to do with it?

Anyone else having these sorts of issues?

Evening Tander

Please can you PM me the MWEB email address or username so that we can investigate this further from our side.
 
Evening Tander

Please can you PM me the MWEB email address or username so that we can investigate this further from our side.

No point, cancelation request has gone through. Got to wait the 30 Days until I can more to a better ISP.

I just find it pathetic that a company like MWEB having these sort of issues.
 
Last edited:
no there is a point. if its a config or known exploit you're running then it deserves to come out. you asked for service and they're providing it.

plus if there is a hole in their security maybe you could help them find it thus saving other people from your experience.

bitching about a company that's not willing to fix it is one thing but if you're complaining and they want to help but you're not letting them then you look like a **** not them
 
LOL yea my site was hacked by some scary Turkish Terrorist group. It wasnt a serious hack all they did was place and HTML file called Ecarter65.html. Looks like they had FTP access somehow. Had a look at the code of it and looks like nothing malicious.

FYI the group is called 1923Turk
 
Yep, the hackers exploited a security flaw in Mweb's servers. They gained root access to all websites and were able to easily cause havoc across all sites. However, unfortunately this is a big problem with a lot of SA hosting companies. I personally do not think that our security experience here in SA is that advanced at this point in time.
 
My site was hosted with Mweb, I cancelled but the domain was left running.

they have hacked that as well, now I can't even change it as I cancelled the hosting plan, lol
 
no there is a point. if its a config or known exploit you're running then it deserves to come out. you asked for service and they're providing it.

plus if there is a hole in their security maybe you could help them find it thus saving other people from your experience.

bitching about a company that's not willing to fix it is one thing but if you're complaining and they want to help but you're not letting them then you look like a **** not them

I cancelled the hosting with them and removed all files off their FTP. Thus I don't have any logs to show. I know how they got in and what they did. They got in through FTP and did what they liked. In this case it wasn't major - but annoying. So no. There isn't a point in reporting it after the fact. MWEB can look this up themselves. As Stillie pointed out - they're replacing the main html / php page with their own. Not's not as advanced as the CoJ hack...

Hoping Afrihost will be a little better.
 
My site was hosted with Mweb, I cancelled but the domain was left running.

they have hacked that as well, now I can't even change it as I cancelled the hosting plan, lol

I can only think of one client of mine that hosts at Mweb. Site's fine :D
 
Ive seen many fully up to date Wordpress websites hacked. Wordpress is just easy to hack. You have to be serious about your security or have a good backup regime.
 
Ive seen many fully up to date Wordpress websites hacked. Wordpress is just easy to hack. You have to be serious about your security or have a good backup regime.

It seems its mostly attached due to it's popularity too - like virus are to Windows machines.
 
It seems its mostly attached due to it's popularity too - like virus are to Windows machines.

I know this thread is old, but for what its worth, my clients MWEB hosting (with WordPress) was hacked too this week. MWEB support just shrug their shoulders and say I should maintain backups of the site.
(and restore it everytime it gets hacked I suppose)

I've recommended the client move off MWEB as soon as possible.
 
I know this thread is old, but for what its worth, my clients MWEB hosting (with WordPress) was hacked too this week. MWEB support just shrug their shoulders and say I should maintain backups of the site.
(and restore it everytime it gets hacked I suppose)

I've recommended the client move off MWEB as soon as possible.

So - how were they hacked?

Did the hackers get in via a wordpress vulnerability? (which by the way would happen no matter where the site was hosted)
 
I finally figured it out. They put their own functions.php in the current theme folder. That was essentially the "script" to get the db password and then overwrite the admin user with their own user. The site wouldn't load after that. Kept on getting a 404.

Fortunately the rest of the database was still in tact. So deleting the functions.php and changing the admin user back via the users table would probably have done the trick. To be safe, i just reinstalled the latest version of WP and changed the default admin user and created a strong password.
 
Last edited:
So not sure which vulnerabilty they used to plant a file in my folder structure. Does anybody know if its a hosting vulnerability or if its a wordpress specific vulnerability?
 
I am posting this in the hope its helpful to anyone out there. Its a bit of as rant at first, but at the end will post the *helpfull* stuff, promise.

My business website has been hacked 5 TIMES in the last 2 months. I have been dealing with MWEB Support EVERY day since then, I even had words with their support manager, Ettiene, to try to make him understand that call centres WILL NEVER WORK and that my problem is simply not being addressed..He promised to red ball it, but 3 weeks later...... same problems exist.



Words will fail to make any of you understand my level of frustration with this utterly useless service provider.

Dealing with mweb support normally goes a little something like this :

1. You dial the number and listen to their advertising spam for 8 to 12 minutes
2.then you get to choose what department you want to go through. (I am doing this right now as I type this)
3. Eventually, after another 5-10 minutes, your call is answered (just answered after 9 minutes and 39 seconds)
4. Then you have to tell them the WHOLE story, what has been done to date, and what you would like them to do.
5. You then get put on hold (another 5 minutes)
6. He then tells you that the hosting guys will investigate and get back to you.
7. 2 days later, you repeat the whole process
8. In the meantime you send them email after email, and support ticket after support ticket gets generated, only to disappear into cybernothing. (ooh Im hold for the 4th time this call again) (21 minutes
9. Eventually, after yelling at Ettiene for long enough you MAY get through to someone, who has ZERO experience, and will try to troubleshoot your problem and they will tell you its nothing to do with them something you did wrong, and you have to re-create your website from scratch AGAIN.

MWEB support HAS to be most inept, unhelpful IT support structure around. Especially if your problem is HOSTING related. there is simply no way anyone will put you through to the backend hosing support or developers. Forget it. Instead you have to entertain the notions of a knowledge base reading noob while your blood pressure is starting to redline, because youve just been told for the umpteenth time "Oh it must be because your wordpress plugins are out of Date." GRRRRRRR

Anyway, finally Spoke to Michele (Support Teamleader)(32 minutes 24 seconds later) who just informed me that they are very aware of my problem (Then why is nobody calling me , or at least emailing me, or SOMETHING), and also that they know about the hacking problem as 2 support staff have told me before.

(After being handed over to another Support tech, and another 15 minutes explaining EVERYTHING I have done. AGAIN, I am now told that their engineers will investingate and will get back to me, just not today, as they all go home at 4. Wow havent heard that one before... Meanwhile im here looking like a poephol in the eyes of my customers. Wait a minute, surely a restore takes only a few minutes?????. mmm).

I have now resigned myself to move this domain to Afrihost or similar hosting provider, with the hopes that that HSP has tighter security. Its a shame, because if I HAVE to complement these boobs, the ADSL line I have had with them has been rock solid, with the consistently lowest ping on the BF servers of ANY other player. (8 or 9ms EVERY time).

Ok So in the interest that someone may gain something from it, here is a shortened version of what has happened.

Website Hacked1 :

Admin password changed
index.php changed to display hacked image
Cpanel and FTP password changed
DNS Record changed for the domain
Other "infected files"
·random.php (root directory of the WordPress installation)
·ppchecker (email addresses and email sender, this was uploaded to his \wp-content\uploads\2015\02 directory)




Response :

Moved to Cpanel2 server - got hacked
WP installation updated
All plugins updated
all passwords changed
HACKED AGAIN (3 Times)
Moved again to CPanel4 server
Complete new WP installation, spent 2 weeks re-creating website FROM SCRATCH
16 character WP Login
8 character VERY cryptic Cplanel password
"very Strong" Database password
Bulleproof Security the ONLY plugin used - no others.

Latest Hack :
Cpanel / FTP password changed
MySQL tables wiped
Files deleted from Theme folder
Blank WP installation overwrites my old files
Website name and description changed to "Hacked by *insert rectums name here*"
All posts and pages deleted from blog, so blank page displays
Website redirect inserted, one that could only be removed with Mweb's backend processes. (????)

Pipe up if any of this seems familiar.

Wessie
 
You cant really complain about call centers when you buy cheap hosting. You get what you pay for. If you want Premium service I would recommend paying premium prices with the right type of hosting company.

Just a thing about wordpress websites that get repeatedly hacked. Are you using a cracked or warez theme? If your site is getting hacked with only one plugin that would be the first place I check. Im not sure if MWEB run CageFS so I dont know how secure their file system is.
 
Possibly these hacks are either an inside job or someone inside is facilitating these hacks. The larger IT setups often don't change their passwords when someone who had access to them leaves. They also fail to remove the account of those who have left.
 
Top
Sign up to the MyBroadband newsletter
X