Jump to content

Recommended Posts

  • Replies 236
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Baltimore, too.

 

At first sight some index.php files have been added in various folders. Found and replaced all those on my site. Haven't noticed anything else being affected yet.

Posted

Ya, index.php in every folder. I've got about 20 domains running so it's a tedious task to just replace those files. I'm going through and restoring from backup from last night. Looks like my server was hacked about 2 hours ago based on teh time stamp.

Posted

Hello everyone,

 

I just contacted the Help desk about this and it looks like there are several of that have this problem and that they are working on this.

Posted

That's right, Steven, the servers are up, :) . No worries, the gurus were on it before I submitted a ticket. TCH will get it fixed -- they always do. :)

Posted (edited)

Nubia server affected too, submitted a support ticked earlier. Been with TCH since 2005 and don't remember seeing anything like this before, godspeed to the tech guys!

Edited by GarthVaderUK
Posted

Mine is hacked too!

does anyone have clue how long it will take to fix this?

this is my business site, and I have clients scheduled to log on later today.

making me really nervous!!!

Posted

Mine is hacked too! I'm very distressed with this as my business depends on my website! www.claudiapatatas.com is showing a hack message. I can't even log in to the cpanel, due to obvious reasons, to send a ticket. Please email me at claudiapatatas@gmail.com

 

I'm not happy with this. I appreciate that these things happen...but...

Posted

Dear TCH Family,

At around 9:30AM EST today, we identified a website defacement attack effecting a large number of our customers. We are still investigating, but it appears the attack was targeted at index.php files. We are currently looking at this to determine the extent of the defacement.

 

I will update you shortly.

 

Thank you for your patience and understanding during this very serious matter.

Posted

Nubia server affected too, submitted a support ticked earlier. Been with TCH since 2005 and don't remember seeing anything like this before, godspeed to the tech guys!

 

 

Me too. This is just mad.

Posted

Dear TCH Family,

At around 9:30AM EST today, we identified a website defacement attack effecting a large number of our customers. We are still investigating, but it appears the attack was targeted at index.php files. We are currently looking at this to determine the extent of the defacement.

 

I will update you shortly.

 

Thank you for your patience and understanding during this very serious matter.

 

 

Thank you so much.

Posted (edited)

2005 here too, Garth. Never seen anything even close to this happen here. I'm confident that Tech Support is doing their best to close any vulnerabilities and restore backups. We all need to be patient.

 

Bill, thanks for the update.

Edited by Bob Crabb
Posted

been with TCH since 2003! always been great-

this is just scary because our businesses have become so internet based

Posted

Same here; my index.php files were replaced at 6:14am. I should probably back up my files more often . . !

 

Your files are automatically backed up every 12 hours. Betcha didn't know that. If you want to do a manual restore, go here.

http://buserver4.tchmachines.com:8085/s/

 

Host Description is the name of your server. Then restore back to some time last night and you should be good. If not, go through your directory structure as sometimes they'll add an index.html as well.

Posted

Mine is hacked too! I'm very distressed with this as my business depends on my website! www.claudiapatatas.com is showing a hack message. I can't even log in to the cpanel, due to obvious reasons, to send a ticket. Please email me at claudiapatatas@gmail.com

 

I'm not happy with this. I appreciate that these things happen...but...

 

See my message above. You can restore to last night and that should fix most of the problems.

Posted

Dear TCH Family,

 

At around 9:30AM EST today, we identified a website defacement attack effecting a large number of our customers. We are still investigating, but it appears the attack was targeted at index.php files. We are currently looking at this to determine the extent of the defacement.

 

I will update you shortly.

 

Thank you for your patience and understanding during this very serious matter.

Posted

Thanks Bill!

Posted

We are working as fast as possible to get sites restored from backups. I don't know what is going on just yet, but trust me when we know we will disclose everything to the family.

Posted (edited)

My sites on columbus are fixed.

 

Bill, thanks to you and your excellent staff for the quick response.

Edited by Bob Crabb
Posted

we're back!!! thanks TCH!

now, for the future, how can I find out the name of my server?

 

Diane, log into your cPanel, and you will see the server name.

Posted

Your files are automatically backed up every 12 hours. Betcha didn't know that. If you want to do a manual restore, go here.

http://buserver4.tch...nes.com:8085/s/

 

Host Description is the name of your server. Then restore back to some time last night and you should be good. If not, go through your directory structure as sometimes they'll add an index.html as well.

I did NOT know that; thank you! My site is back up but I'm filing all of this away for future reference. Now to figure out which server I'm on . . .

 

Thanks!

Posted

we're back!!! thanks TCH!

now, for the future, how can I find out the name of my server?

 

Log into Cpanel.

On the left side, it says Expand Stats. Click that, and you will see a section called Server Name.

Posted

I did NOT know that; thank you! My site is back up but I'm filing all of this away for future reference. Now to figure out which server I'm on . . .

 

Thanks!

Ah, I'm on unni. Thanks for the quick response, TCH!

Posted

Ok guys, we are going to be using a canned reply to all our tech support tickets. Here it is: (just a fyi)

 

Hello,

 

Thank you for contacting us concerning your web site. Please head over to our forums for an up to the minute status on this issue.

 

We have our entire staff working on this issue and rest assured that we are working non-stop to correct this issue.

 

You can view the update here:

 

http://www.totalchoicehosting.com/forums/index.php?showtopic=42941&pid=250121&st=0entry250121

 

Thank you for your support and understanding.

 

The TotalChoice Hosting Gurus....

Posted

Vortex too. Site is ncs-tech.org. Unless my site is actually hacked and not part of this flurry.

 

Restored my first CP backup, it failed to fix the problems. Trying another.

 

Help ticket submitted as well.

Posted

The techs are working as fast as they can. Please give them time.

 

On a couple of my personal sites I removed the index.html file from the root folder and replaced my index.php file with a current one and it fixed them.

Posted

My site went down, too, at about the same time. It's on the Atlanta server. I looked at the main index file and it looked normal. I got a screen shot of the hacker's boast and sent it with my request for assistance ticket...

Posted

I've been with TCH since the early 2000's and I have no doubts everything will be back in order as quickly as possible.

 

And just like that, my website appears to be back up!

Posted

We have a restore script running across all effected servers. This is simply restoring index.php files from cPanel backups.

 

This will take a bit of time, and we will of course update this thread as we move along.

Posted

We have a restore script running across all effected servers. This is simply restoring index.php files from cPanel backups.

 

This will take a bit of time, and we will of course update this thread as we move along.

Posted

Just an update, I am on bespin server, my index.php was hacked at arround 6AM EST-time, if my FTP software is reporting the time correctly.

I have just did a restore my side a few moment ago, and now all is well.

 

What is intretsing is that I notice the error_log file, reported a lot of errors on "duplicated_ip". and that dated back the 25, possibly older. Hope this helps

 

I would like to say a special thanks to TCH for the quick update, and being transparent with us! :(

Posted

new issue- we're not getting any emails to/from the server- is this related?

 

I'm assuming it's related; I'm having the same issue. Hopefully it will be fixed once all the restores/adjustments are made by TCH.

Posted (edited)

I'm also impressed that despite the chaos, Tech Support still managed to respond to my ticket and direct me to this thread within 45 minutes!

Edited by Mang Photo
Posted

I'm also impressed that despite the chaos, Tech Support still managed to respond to my ticket and direct me to this thread within 45 minutes!

definitely impressive :-) way to go TCH!

Posted

new issue- we're not getting any emails to/from the server- is this related?

 

We are having the same issue on kashyk

 

No emails being received and when I try and send from an account it gives us an SMTP error.

Posted

How do we sign in? My totalchoicehosting username and password do not work.

 

Make sure you select the Cpanel login from the drop down and enter your server name as well. It should work.

Posted

sites on Ft Worth are working now. Thanks again to TCH for the quick resolution of such a large scale problem on a holiday weekend.

Posted

Thank you TCH... I have been a customer with you since 2004 and I am very pleased with how quickly you guys are working to fix the problems. My site is back up!

THANK YOU!!

Posted

These people obviously don't have a clue who they are dealing with. Thanks, Bill and all the gurus, for your watchful care and dedication to keep us all safe.

Posted

No resolution for me, had to fix this myself manually....

 

Can you tell us how you were hacked and what you will do to prevent this in future?

 

Are my CC details and other identity details safe with you if this idiot can get at all your servers like this.

Posted

Email issues should be now corrected. However, we are still motorizing email server status and will correct any issues that may arise.

Posted

Do we need to reset our CPanel passwords? Or were they not compromised?

 

It never hurts to rotate passwords, however passwords were not compromised.

Posted

Is anyone still seeing their sites defaced?

 

I am not however my site is still not restored. I am waiting patiently i'm on the Utapau Server. I just assume it takes time as you work through the servers.

Posted

Thanks, Bill & Team.

 

All my reseller accounts are now no longer defaced and working as expected.

 

A great response to what appears to be an almighty (in terms of number of sites) defacing. The response I received from the support team was swift too under such circumstances.

 

Thanks to all involved.

Posted

Same problem here on the Phoenix server.

 

Fortunately, just a few accounts seem to be affected on my reseller account.

 

I restored them with my own back-ups and seems to be okay now, and I don't see any databases were affected but should I trust them still?

 

Can you tell us how you were hacked and what you will do to prevent this in future?

Yes, I would like to know this, too. Restoring is one thing, but how did this happen to so many different servers?

Posted

All is well here. Thanks again. Y'all probably still have a lot of work to do in analyzing what happened, and monitoring, but I hope that the TCH staff can get away form the computers for a while and enjoy the Memorial Day weekend.

 

Thanks, and happy Memorial Day!!

Posted

Can i get an update on Utapau Server........ I just assume they will use the backup from last night and life will be back to normal soon? Is this the correct thinking?

Posted

All of my sites on montreal still seem to be defaced.

 

Can i get an update on Utapau Server........ I just assume they will use the backup from last night and life will be back to normal soon? Is this the correct thinking?

 

Please check now and let us know if you still have issues.

Posted

Major kudos to you guys for getting things back up and running again so quickly! This is just another example of the great service I've come to expect from TCH over the years I've been a customer.

 

It's probably a bit early to ask this but do you have any idea how this guy gained entry to so many systems? It would be nice to think that whatever back door he used was closed tight so that this kind of thing becomes a great deal less likely in the future.

Posted

Thanks guys. It looks like I lost 6 hours of emals. No problem, I can recover.

 

My real question is what did this person acheive? Did he just show his prowess by screwing us all? Did he collect some sort of info? What?

Posted

Several of my sites on montreal are just showing file listings. Looks like the index.html page was deleted, but not replaced. Sites that use index.php seem to be working. Should I update my ticket with the specific list of sites that are still affected? (I'd rather not post them here.)

Posted

pkronhert,

 

I would wait a bit more if possible, as I guess the techs still have a lot to do with this issue.

However, you could reopen the ticket, but expect some waiting to hear from the techs.

Posted (edited)

I had 6 of my sites hacked and fixed them myself with re-uploading index.php and removing index.html. So far no more sites hacked or re-hacked.

 

I notice various folder names have today's date, which worried me but I do not see anything inside them modified (so far).

 

I see this hack is not new: http://randombits.wo...nda.com/node/20

 

I should note I am on Portland (208.76.80.121)

Edited by rick02840
Guest
This topic is now closed to further replies.

×
×
  • Create New...