Dynadot โ€” .com Transfer

Suggestions please?

Spacemail by SpaceshipSpacemail by Spaceship
Watch

ZuraX

Established Member
Impact
42
Right now I got a dedicated server as follows.

2.4 Ghz Celeron,
1024 Ram,
80 GB HDD,
1000GB Transfer,
8 IPs (5 useable),
cPanel / WHM / Fantastico
Full management by SeeksAdmin and Rack911
Advanced policy firewall, APF
Brute force detection, BFD
CHkrootkit
Logwatch
$140/mo

Thing is ONE customers account got hacked and someone was putting up fake paypal, ebay, and yahoo accounts. The customer deleted the files when he seen them and changed his pass often. Yet the files kept coming back. he finally emailed me about it and I had a look and changed the pass and deleted the files. I watched the account for 3 days and the files never came back.

He emailed me on 11/12. On 11/18 at around 4:30pm the server went down. I contacted the support people and was told it was taken down because of that guys account. Seems the files came back and the hacker was spamming for the pages he added. I explained everything to the support people and was told my server would be back online and I would have to delete the account. Why didnt they just email me about this? I waited a bit then emailed asking why it wasnt back up to be told that the abuse staff wasnt in to turn it back on.

Today I emailed to ask what was going on and was told it would be up shortly. That was at 3pm. Here it is midnight and the server is still offline and my last three supoort requests have not been answered. If the server isnt put up soon I am going to lose all of my customers. I have already lost one besides the one that got hacked. My customers payments help me pay the server bill. If I lose too many I will not be able to afford the server bill next month.

So my question is, what would you do?

Anyone know a good dedicated server place that offers all that I now get for the same price or lower? I thought about just telling all my customers I am sorry but they need to find a new host and finding a good reseller account for my sites but I run a banner exchange and a PPC Search site that may not work right on a reseller/shared server. :(

Suggestions?
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
AfternicAfternic
It's the 22nd now. If your server hasn't been reactivated by now then you will probably already have lost most of your hosting customers anyway. You probably won't find a reseller account that will accept a ppc and a bannerexchange inexspensively because of the high amount of traffic these type of sites usually tend to generate.
Wishing all the best!
 
0
•••
that sounds like a servermatrix or theplanet server? similar specs?

have you disabled root logins at all via ssh?
and is jail shell enabled?
and php home dir protection enabled?

it might be a case that the hacker is getting on via root or another user then placing the filesi n another user account?
 
0
•••
Only one account can access root via su -
Only 4 people have SSH access. Me, my brother, a guy I have known for years, and the host.
The server is back up as of yesterday afternoon and the account has been deleted.
 
0
•••
ZuraX said:
Only one account can access root via su -
Only 4 people have SSH access. Me, my brother, a guy I have known for years, and the host.
The server is back up as of yesterday afternoon and the account has been deleted.

do you all login with root? or another account with similar perms?

might be an idea to disable root logins and create a wheel group user and give them access to ssh and jail shell any others

just an idea glad you got it sorted
 
0
•••
Thats how its setup....
 
0
•••
ZuraX said:
Only one account can access root via su -
Only 4 people have SSH access. Me, my brother, a guy I have known for years, and the host.
The server is back up as of yesterday afternoon and the account has been deleted.

Do those 4 people have root access or only yourself?
I think you should check why the illegitimate files are back ~ Otherwise, leasing a new one would not help much ~
 
0
•••
No only me and the server place have root. There was a file I found that auto installed the illegal files. The server place never did tell me if it was a complaint from before or after I removed the files.. So its hard to say if they came back after I found the "install" file.
 
0
•••
try ev1servers.com.
 
0
•••
No thanks. I have heard toooo many bad things about them.
 
0
•••
try yrhost.com they have some cheap dedicated servers
 
0
•••
Zurax, I would suggest VersaWeb.net, I am trying them out now and the prices are as good or BETTER then ServerMatrix.com. I am moving some of my servers their and will get a resellers discount (Or so I was told), so I may be able to offer you banging deal on a secure, managed server :) PM me if your interested.
 
0
•••
Try Hostforweb[com] They have some nice Ded servers - Which are reliable.

Best of Luck!
 
0
•••
CatchedCatched
Escrow.com
Spaceship
Rexus Domain
CryptoExchange.com
Domain Recover
CatchDoms
DomDB
NameFit
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back