WordPress Virus and Serv Hosting

skynarc

Active Member
Joined
Aug 15, 2006
Messages
72
Reaction score
0
Hi,

My site has been hacked about 4 times with Serv Hosting and by now I thought I have taken every single security measure known to man. Yes, I know WordPress has it's issues. In fact, WordPress at it's core as I have come to understand is pretty rock solid and it is the Plugins most of the time that have the vulnerabilities.

Of course, with that in mind I make sure my sites are up to date, my plugins are from reliable sources and up to date and that I have followed as many security measures as I can.

Serv Hosting has been known to change their users passwords numerous times and from articles I have read as far back as 2008, they are a hackers paradise. So I am moving.

The last hack warned that I should change my FTP password immediately (red flag; their FTP has been breached again) and then begin the process of sorting out the virus. I left it for a few days because I got too busy and the site had not been defaced...yet. The only thing I did on Friday was to change my FTP password.

Yesterday, Sunday, I open my site and sure enough, the site is defaced with the following screen. It would seem from this screenshot, that the hackers would have full access to my site and the only reason nothing else happened was because I had changed my password.

I have spoken to Hetzner and they've said that without being in that environment, they cannot prove that Serv Hosting has not done enough to secure their servers. As you can imagine, when the majority of your sites are hacked, you do not want to spend hours and hours fixing issues if the ISP is at fault. I have gone as far as to find out if there is an Ombudsman for ISP's in SA to which I have found out that unless they belong to ISPA, which is voluntary, there is not much else anyone can do. So, you are liable for your own damages.

Please take a look at the screenshot. If anything, I hope the ISPs will take note of it and flag is in their systems for something to look out for.



Thanks
 
Last edited:
Ive had the same issues with Serve hosting on my Joomla! websites. They keep being infected on and on and this is just the core Joomla installation with no additional plugins. Their support centre's customer service leaves a lot to be desired, just last week when one of their servers was down, they informed me after calling them that I shd keep checking. On askin if they can mail me when their service comes back i was told thats not possible because they dont know which clients are on that server Serve Hosting sUcKs !!!
 
find out which ftp server software they using. Some are more secure than others. Most common way is to sniff for passwords. Good FTP servers can deal with this. Bad ones cant.

There is always the weakest link regardless of how secure the ftp is, and that is human beings. If they havent setup their clients accounts and directory access properly, this can cause havoc.

Hackers who are able to change your site must have access to your directories. If they havent hacked your account, maybe they hacked someone elses. FTP accounts for other users should not have access to your directories. And you should not have access to other directories. Check how far you can browse with your account. Chances are, someone else can then also browse to yours, if you can browse theirs. If its a unix site, check the permissions of the files. No reason why the files should be writeable by others. I know squat about windows, but I'm sure there must be similar features :D
 
Hi,
Being hacked like this is not a great advert for any hosting organisation. If the hosting organisation is not taking your query seriously then I suggest that it is time to get hosted somewhere else.

regards

Tim
 
I've got countless Wordpress installs hosted on Hetzner. Only ever had one "breach", and it was related to a vulnerability in Wordpress, which was coincidentally patched the next day.
 
Similar thing happened with my websites on Serv. They said it in such a way that MY passwords were not secure enough...but in the end I think it was some other vulnerability. Anyways...my websites were also defaced.
 
I just spotted this post again and thought I would give some feedback.

I've been with Hetzner for months now and not once (touch wood) has a single WordPress site been hacked whilst with them.

Makes me question if Serv (or any ISP) should be held accountable for the countless production hours lost due to their failure to properly install security correctly on their servers.
 
I just spotted this post again and thought I would give some feedback.

I've been with Hetzner for months now and not once (touch wood) has a single WordPress site been hacked whilst with them.

Makes me question if Serv (or any ISP) should be held accountable for the countless production hours lost due to their failure to properly install security correctly on their servers.

No.

You took the risk of being cheap and going on shared hosting. You also accepted the TOS & AUP. So no, you cant hold them accountable.
 
No.

You took the risk of being cheap and going on shared hosting. You also accepted the TOS & AUP. So no, you cant hold them accountable.

Not when they kept telling me that their servers are secure but that I am taking a risk using WordPress as a CMS.
 
Top
Sign up to the MyBroadband newsletter
X