6 ms·
Could you give an example of when a customer would need that? I'm missing something.
by bpchaps 8y ago
Could you give an example of when a customer would need that? I'm missing something.
- gscott 8y agoA lot of SQL injections are malicious ad scripts that will be named the same on each hack. It would be pretty easy to remove something like that as it passes back through Godaddy's router. I would hope they notify the website owner because otherwise you wouldn't know that you have a problem.
- guessmyname 8y agoIf a customer’s website is being hosted in a shared account, the infection will quickly spread across the other websites in the same server unless the hosting provider takes the matter in their own hands. Years ago, it was common to simply suspend the infected website until the webmaster finished the cleanup by themselves. Nowadays, instead of suspending a website for a minor infection, some hosting providers simply clean the malicious code automatically, or offer a premium cleanup service if the infection is more complex.
- thaumaturgy 8y ago> If a customer’s website is being hosted in a shared account, the infection will quickly spread across the other websites in the same server unless the hosting provider takes the matter in their own hands. Not at any professional hosting service. It's not hard to secure the environment so that it'll take a classier attack than guessing somebody's WP login to get access to any other sites on the host. The actual problem for hosting services is that compromised sites can be used to annoy visitors or other hosting services. edit: okay, I don't care about the points, but I'm getting really curious why people disagree with this.
- ggggtez 8y agoMost hosting providers don't want to host malware, as it's against their terms. Instead of banning an account, trying to identify affected customers proactively sounds reasonable. Injecting your own code in their site does not.
- thaumaturgy 8y agoI can't tell if you're trying to respond to me, or just making a public service announcement. In any case, yes, I agree.
- perennate 8y agoI agree. If it's possible for the infection to "spread across the other websites in the same server", then that implies that clients can access and modify each other's files, which is not the case with any shared hosting provider I've heard of. What is more plausible is malicious server-side code eating up server resources, and that load impacting the websites of other customers, but that has its own solutions which are different from automated detection of malicious JavaScript code.
- thaumaturgy 8y agoMost of the compromises I've dealt with over the years fall into just a handful of categories: 1. Data theft. So, ripping off a database or intercepting credentials while people log in. 2. Embed a link into page output which will try to download something from somewhere somehow. It might be phishing, or (usually) it's some kind of JS trying to infect the user with malware. Lazy attacks work by just popping up a convincing-enough warning message with a link that lets the user download the malware themselves, and it's effective enough. 3. Credit card theft. Using a third party service with iframes makes this harder, but not impossible. 4. Dropping some kind of web-based shell, like C99. #1 doesn't get anybody to care. If that's all that ever happened, I'm pretty sure shared hosting providers would still be saying, "sucks to be you." #3 causes headaches for the site owner and makes them care, but still not the hosting provider. #2 got the hosting providers' attention once Google launched Safe Browsing. Suddenly this put some of the responsibility for maintaining a safe network back onto the hosting providers. Their first solution was to just shut down sites discovered to have malicious code, but that really irritated the customers. So gradually hosting providers started trying to be a little more helpful. #4 is a big headache for hosting providers, because those things don't get picked up automatically by Google, and the shells can be used to irritate other hosting providers, who will definitely start lodging complaints with whoever's upstream of the hosting provider. Not on this list is, "try to infect other sites on the same server", because shared hosting environments have had easy access to a variety of tools for a long time now that prevents that. In a LAMP environment, that used to include SuexecUserGroup; more modern LAMP environments now use php-fpm and have PHP processes running from distinct unprivileged user accounts. There's also the usual php.ini values, like open_basedir, which limit access to the filesystem or to other PHP functions (allow_url_fopen). I won't say it's impossible for an infected site to attack another site on the same server in a shared hosting context, but you'll need a get-out-of-jail card and those are harder to come by. No professional shared host would allow one site to access or modify another site on the same server.
- scarface74 8y agoI honestly never knew that shared hosting was a thing that companies sold. I was under the (false) assumption that every user’s website was in their own little VM, not they were sharing a web server.
- TylerE 8y agoUp until as recently as maybe 6 or 7 years ago it was about the only option if you didn't want to pay for a full dedicated server. Running a full VM, especially on the tools back then, took a ton of resources. Even server class machines only had 4 or 8GB of RAM typically.
- scarface74 8y agoDon’t get me wrong, I’m not new to the field and in hindsight it makes perfect sense, but back then, I worked for corporations that hosted their own servers and never needed to host a site for a personal/small company. By the time I got to the point where I would think about doing something on my own, VPS hosting was so cheap, I wouldn’t have thought about anything besides a VPS like Linode.
- daeken 8y agoNone of this is true. VPSes have existed since the early 2000s and have been in common use since the mid 2000s; Linode was founded in 2003, for instance. Shared hosting was popular because it cost pennies, whereas VPSes would run you $30+/mo, which of course is more like $5+/mo now.
- scarface74 8y agoJust for a reference: https://blog.linode.com/2003/11/04/new-linode-96-plan/ https://blog.linode.com/2003/11/04/new-linode-96-plan/ 96M RAM 3GB Disk Space 38GB xfer $29.95
- TJSomething 8y agoLinode's kind of expensive. I've been using VPSDime [1] for a few years, since they give us 6 GB of RAM for $7 a month. For smaller stuff, I've been happy with RamNode [2], which is $3.50 a month for 1 GB of RAM. And you can usually find good deals on Low End Box [3]. Of course, at those price points, everything is OpenVZ, which is kind of annoying. [1] https://vpsdime.com/ https://vpsdime.com/ [2] https://www.ramnode.com/vps.php https://www.ramnode.com/vps.php [3] https://lowendbox.com/ https://lowendbox.com/
- joecool1029 8y agoIt's honestly a smart thing for shared hosting providers to offer. Some years ago my co took over a bunch of legacy sites from another developer that were not tightly maintained Wordpress. We hosted the sites at the time at Rackspace Cloud Sites. The main reason we chose their antiquated hosting tier was that Rackspace support would handle infection cleanup when it happened. It would take us time to assess everything and do up contracts for bring-up with these sites. Everything from old revslider and timthumb to more exotic infections. Once you got a file injection or reverse shell on a host, it would spread fast to everything on the server. Only way reliably back was catching when it came in and rolling it back to before then upgrading the vulnerable components.
- JohnFen 8y ago> It's honestly a smart thing for shared hosting providers to offer Offering it as an opt-in service, yes. Doing it to websites that have not agreed to to it, no.
- rawoke083600 8y ago"If a customer’s website is being hosted in a shared account, the infection will quickly spread across the other websites" Hmm Shouldn't my hosting provider provide better isolation and separation from the bad accounts?
- JohnFen 8y ago> Years ago, it was common to simply suspend the infected website until the webmaster finished the cleanup by themselves. Which is still how it should be done.
- jedieaston 8y agoIf someone takes control of their website and puts malicious stuff on there, GoDaddy being able to ask the customer “Hey, did you mean to do that?” and helping them roll it back is handy.
- JChase2 8y agoWordpress plugins get injected with crap all the time, same with joomla, pretty much any site running a super old php version with their CMS, etc.