Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Wed Feb 26, 2014, 05:20 PM Feb 2014

Got an email from my hosting company about security....

I'll reproduce it below and omit the name of the company:

Over the past few weeks we have seen a rise in email abuse across our server farm. The majority of this abuse is attributed to weak and insecure passwords on client’s cPanel and email accounts. The other small portion of the email abuse comes from accounts that have been exploited thru old and outdated 3rd party scripts such as WordPress and Joomla.

As you are aware your website is part of the Global Internet Community. With this come’s great responsibilities and duties that every web site administrator must follow. It is crucial that you maintain strong passwords and that you rotate your passwords for both your cPanel and email user accounts. We suggest this is done at least every six months. Use passwords with at least 8 characters, both upper and lower case and a few special characters.

It also very important that you maintain your site files. Simply because you correctly installed WordPress two months ago does not mean that it is secure today. Third party scripts, including plugins and software must be updated and maintained on a regular basis. It is critical for us all to maintain our sites, this will allow us all to host on safe and secure servers.


Is this sort of email pretty common these days ? It's the first one I've ever gotten from them in 8 years. Thanks.

Steve
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Got an email from my hosting company about security.... (Original Post) steve2470 Feb 2014 OP
I cannot say whether it is common or not. ManiacJoe Feb 2014 #1
yes it is appropriate steve2470 Feb 2014 #2
The battle goes on. TygrBright Feb 2014 #3
I think they post security things on their website steve2470 Feb 2014 #4
I manage a couple plesk and cpanel servers...there some new massive exploits out Drew Richards Mar 2014 #5
a million probes a day ???? steve2470 Mar 2014 #6
I work for a very large isp/voip provider with data centers all over the US and virgin islands. Drew Richards Mar 2014 #7

TygrBright

(20,755 posts)
3. The battle goes on.
Wed Feb 26, 2014, 06:51 PM
Feb 2014

Crackers and spam merchants have become increasingly sophisticated at finding ways to exploit the smallest vulnerabilities to bust open whole nodes' worth of data and hijack vast arrays of computing power.

I'm just surprised you haven't heard from your host in 8 years. I get regular updates from my host on recommended security procedures, and what they are doing to make their servers more secure.

agreeably,
Bright

steve2470

(37,457 posts)
4. I think they post security things on their website
Wed Feb 26, 2014, 07:14 PM
Feb 2014

This email was directly from the CEO of my company. I guess things finally got so bad that he felt he had to email all of us.

Drew Richards

(1,558 posts)
5. I manage a couple plesk and cpanel servers...there some new massive exploits out
Sat Mar 22, 2014, 02:20 AM
Mar 2014

Especially against wordpress and old unupdated java scripts. Everyone is is sending out notifications...

Our new rec is is minimum passwords of 10 characters upper lower symbol and no english words. Different pws for cpanel and sftp access and update your scripts and use correct permissions or we loc your site till its secure...

Currently we are hit by over a million probes a day from china taiwan and amsterdam. Guys we are in a cyber war and no one in gov is really doing anything about it.

I would block all international access to the sites cpanel and sftp my voice switches ect... but management says no...

IP tables and fail2ban work good but id rather just block the whole damn class A's...

All I can say is back up your stuff NOW before you get hacked and wiped out.

Latest Discussions»Help & Search»Computer Help and Support»Got an email from my host...