WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< NaviSite Offers SaaS Sandbox Service     Renasoft Offers Portable Web Server >>


HostGator Recovers From cPanel Flaw

By Justin Lee, theWHIR.com

September 29, 2006 -- (WEB HOST INDUSTRY REVIEW) -- A confluence of vulnerabilities - one in the hosting control panel cPanel, and one in Microsoft's Internet Explorer browser - created a large-scale security breach at several hosting firms last week, and may prompt Microsoft to patch the its browser ahead of the scheduled October 10 update.

   
Why use a vendor when you can choose a partner? DataPipe delivers highly customized solutions to meet your unique IT needs. World-class data centers in the U.S., London & China. DataPipe - Personal Touch, Global Reach.

Last weekend, hackers exploited a flaw in cPanel (cpanel.net), among the most popular Web hosting control panels, gain access to the networks of seven Web hosts. The attackers took control of hundreds, possibly thousands, of Windows-based machines using Internet Explorer. 

Hackers injected iframe exploits into PHP pages located on the Web hosts' servers, redirecting some visitors to sites off the hosts' networks. The IE bug is related to the way the browser processes Web-based graphics code written in the Vector Markup Language, enabling hackers to install spyware and malware onto the computers of Internet Explorer users.

Bocan Raton, Florida-based HostGator (hostgator.com) was the first Web host to discover the attack, which lasted from late Thursday to Saturday afternoon. However, HostGator founder and president Brent Oxley says the hackers used the cPanel vulnerability to access HostGator servers more than a month ago, keeping a low profile before striking late last week.

According to Eric Sites, vice president of Sunbelt Software (sunbelt-software.com), there are some 20,000 sites that are currently attempting to exploit the vulnerability. The security software developer initially discovered hackers were using the VML flaw on pornographic Web sites.

Dave Koston, an operations manager at cPanel, says the company patched the hole within an hour of it being brought to its attention. An update was then passed along to the majority of servers that use the control panel software.

HostGator says it worked with other parties to develop an additional version of the patch and ensure that the problem was fully resolved. 

"Provided your server is secure via all other common methods and properly administrated," says Oxley, "with this patch applied on a cPanel server, the issue should not present itself at this time."

Oxley says no matter how stringent a Web hosting company's security practices, it is extremely difficult to defend against attacks that target a flaw in third-party software.

"There's really not much you can do since its cPanel and it's out of our control," says Oxley. "They have the source, which means they're the only one that can secure it. There are exploits everyday; I'm sure there are going to be many other exploits to be discovered."

After HostGator discovered the cPanel exploit, it contacted a few of its major competitors to see if they were also affected by the flaw. After discovering other cPanel hosting companies had similar experiences, HostGator advised them on how to remedy the problem.

On September 24, Network Redux sent a formal request on behalf of HostGator and five other Web hosts including BlueHost, Rails Playground, Clear-Data Internet Services, Myriad Network and HostingZoom, asking cPanel engage security consultants for a full security audit of the cPanel and WHM codebase.

The Web hosts urged cPanel to provide "assurance from a third party entity [that its] codebase provides a secure operating environment" for its users. The request also called for cPanel to provide "fixes to all discovered security issues, and full disclosure be provided to cPanel partners and distributors," all within an appropriate time period for updates.

Oxley says HostGator alerted the FBI and other law enforcement agencies to the situation, but "have not seen any interest from them."

And while HostGator has stemmed the spread of what could have become a very serious problem, similar attacks are likely to occur in the future. Oxley says that dealing with such security issues is an inevitable downside of the industry.

"Is this going to be the last exploit that we're ever going to see? Probably not, but we've done everything we can on our side to have a secure setup," says Oxley. "In the end, no one's 100 percent secure when it comes to Web servers, and anyone who says they are is lying and has no idea what they're doing."

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jonathan Bryce, Mosso

Q&A: Nick Nelson, UK-2/Dotable

1&1 Opens Lenexa Data Center

Noise Filter: Ky. Domain Seizure

NaviSite Launches Dedicated Hosting

Q&A: Michael van Dijken, Microsoft

Q&A: Jim Fagan, Rackspace Asia

More feature interviews and reports
 

Hosting Transformation Summit 2008 - Video Feedback

Someone Else Tours IBM's Second-Life Green Data Center

The Market Dropped - Plummeted - Tanked - Skidded - Those Hosting Stocks

Hosting Transformation Summit 2008 - Video Interview Dan Ephraim, Tier 1 Research

Copywriting - Persuade Your Reader with Benefits

Archimedes Principle - Money For Your Data Center

More posts from our Bloggers


McAfee Adds Product Management VP

NaviSite Offers Alert Logic Solutions

Registrar Gandi Adds Web Hosting

CA Updates Automation Manager

iWeb Restructures Management

KEMP Takes Load Balancing To School

IBM to Open Scotland Colo Facility

ICAP To Expand London Connections

IBM Offers Cloud-Based Software

Aplus.Net Names New CFO

Virtualization to Drive SaaS: Survey

CWIE Buys Embattled Alpha Red


 

Office Administrator

Senior Windows System Engineer

Programmer Analyst

Group Marketing Manager

Network Operations Engineer

Technical Customer Care Representative

National Account Manager

Customer Service Representative

Legal Assistant (Part-Time)

Project Manager

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Website Source: Powerful Website hosting starting at $6.85

> Rackspace: What Do You Get With Your Hosting Provider?

> PEER 1: World-class managed hosting. ValuePro Plan just $299.

> Click here for special deals and offers from WHIR sponsors!

> Click here to learn more about going green with your data center

> Is your company hiring? Post your job listing here!

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.