topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday April 19, 2024, 8:36 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: Is your Hosting Company Secure ... Really?  (Read 6459 times)

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Is your Hosting Company Secure ... Really?
« on: March 22, 2011, 05:41 PM »
From the Department of You Gotta be Kidding Me...

While working with a client's network trying to resolve some mail flow issues...I was required to contact their web hosting company. This can be "fun" to varying degrees depending on what type of verification is used to ascertain whether or not you should be allowed to be making change requests. This is frequently called Big Fun with Social Engineering when the client can't remember or find the account info. which nobody has seen for 8+ years.

Now imagine (if-you-will) my dismay at getting absolutely no challenge what so ever. None. Nothing. Notta.  Straight to the red carpet from hello. This has now happened on two separate occasions, which were weeks apart. So it ain't like somebody was having a bad day, and let it slide... What were the changes I was requesting you ask?

1st Call:
I requested that all mailboxes be tripled in size to (and this was directly stated) allow for larger Emails (with 20+MB attachments)to be sent.

2nd Call:
I requested that all the existing MX records be removed (Um... Yeah), a new MX record be created, and that all the mail was now to be sent to an off-host IP address that I specified.

And at no time was I asked for anything (not even my name - which I didn't offer) other than what domain I would like to make changes to.

Now the web-based management interface requires, domain name, user name, and pass word ... ALL of which are case sensitive. So there seems to be some level of understanding in regard to security. It just doesn't extend (or pertain) to the folks at phone support. Try this with your hosting company sometime to see how well they fair ... You might just be mortified ... I was.

...I've advised the client to switch hosting companies ... and they are.

cranioscopical

  • Friend of the Site
  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 4,776
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #1 on: March 22, 2011, 06:19 PM »
I've advised the client to switch hosting companies ... and they are.

And thanks for all that mail… some interesting reading, eh?

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #2 on: March 23, 2011, 06:50 AM »
I've advised the client to switch hosting companies ... and they are.

And thanks for all that mail… some interesting reading, eh?
-cranioscopical (March 22, 2011, 06:19 PM)

 :huh: Ya know, I'm usually pretty good at this ... But I have no I dea what you mean by that.  :huh:

Previously they had their Exchange server suspended between the hosting company (via POP Connector) and their ISP (via SmartHost forward), on a increasingly shakey DSL connection. Now their Exchange server is fully public on a fiber connection (one of yesterday's speed tests hit 35Mb - I wonder if the wife will let me get one...).

So the mail load (for them) hasn't really changed, it's just fast & reliable now.

Renegade

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 13,288
  • Tell me something you don't know...
    • View Profile
    • Renegade Minds
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #3 on: March 23, 2011, 07:25 AM »
Oh. My. God.

That's horrible.

I'm with The Planet and Softlayer, and they're good. I've called them before and they do check to make sure that I am who I say I am.
Slow Down Music - Where I commit thought crimes...

Freedom is the right to be wrong, not the right to do wrong. - John Diefenbaker

cthorpe

  • Discount Coordinator
  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 738
  • c++thorpe
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #4 on: March 23, 2011, 07:39 AM »
I'm with a VPS.  If you were to call or email them about something like MX records, they would point you at a website that tells you how to do it and tell you to do it yourself.  I call it security through RTFM.

C

tomos

  • Charter Member
  • Joined in 2006
  • ***
  • Posts: 11,961
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #5 on: March 23, 2011, 07:46 AM »
I've advised the client to switch hosting companies ... and they are.

And thanks for all that mail… some interesting reading, eh?
-cranioscopical (March 22, 2011, 06:19 PM)

 :huh: Ya know, I'm usually pretty good at this ... But I have no I dea what you mean by that.  :huh:

=>
2nd Call:
I requested that all the existing MX records be removed (Um... Yeah), a new MX record be created, and that all the mail was now to be sent to an off-host IP address that I specified.

...you gotta be on your toes with that guy :D
Tom

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #6 on: March 23, 2011, 07:52 AM »
I'm with a VPS.  If you were to call or email them about something like MX records, they would point you at a website that tells you how to do it and tell you to do it yourself.  I call it security through RTFM.

C

 ;D ...I like that! (hehe) - However this particular hosting company doesn't give its users that option unfortunately (I checked for that first). Which is also quite sad for a $600 a year hosting account.

DNS is one of my favorite things to play with...So I tend to insist on having unrestricted access to it.

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #7 on: March 23, 2011, 07:53 AM »
I've advised the client to switch hosting companies ... and they are.

And thanks for all that mail… some interesting reading, eh?
-cranioscopical (March 22, 2011, 06:19 PM)

 :huh: Ya know, I'm usually pretty good at this ... But I have no I dea what you mean by that.  :huh:

=>
2nd Call:
I requested that all the existing MX records be removed (Um... Yeah), a new MX record be created, and that all the mail was now to be sent to an off-host IP address that I specified.

...you gotta be on your toes with that guy :D

 :wallbash: ROFL Okay, got it ... Thanks for the map!

 :D

40hz

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 11,858
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #8 on: March 23, 2011, 09:44 AM »
I'm with a VPS.  If you were to call or email them about something like MX records, they would point you at a website that tells you how to do it and tell you to do it yourself.  I call it security through RTFM.

C

*And* also covering your ass by insisting your clients make certain changes themselves.

Hmm...I think I like that idea.  8)

« Last Edit: March 23, 2011, 09:46 AM by 40hz »

rgdot

  • Supporting Member
  • Joined in 2009
  • **
  • Posts: 2,192
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #9 on: March 23, 2011, 05:23 PM »
I call it security through RTFM.

Classic stuff  ;D
As long as you are not forced to go to one of those linux support forums instead of RTFM  ;)


Josh

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Points: 45
  • Posts: 3,411
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #10 on: March 23, 2011, 05:31 PM »
I call it security through RTFM.

Classic stuff  ;D
As long as you are not forced to go to one of those linux support forums instead of RTFM  ;)



WARNING WARNING - LINUX SUPPORT INSULT DETECTED. DEPLOYING COUNTER MEASURES!

rgdot

  • Supporting Member
  • Joined in 2009
  • **
  • Posts: 2,192
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #11 on: March 24, 2011, 01:36 AM »
WARNING WARNING - LINUX SUPPORT INSULT DETECTED. DEPLOYING COUNTER MEASURES!

As of now any where I post there will be a bot reply:

RTFM


:P

cthorpe

  • Discount Coordinator
  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 738
  • c++thorpe
    • View Profile
    • Donate to Member
Re: Is your Hosting Company Secure ... Really?
« Reply #12 on: March 24, 2011, 09:44 AM »
Yeah, it's all fun and games until someone loses an eye... or in my case, his mind because one of his domains isn't working.  :wallbash: