WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< DataPipe Sponsors NextFest Event     CrystalTech Offers ColdFusion Update >>


Web Hosts Hit by Hackers

September 27, 2006 -- (WEB HOST INDUSTRY REVIEW) -- Hackers recently exploited a flaw in the cPanel (cpanel.net) hosting control panel to gain access to four Web hosts including HostGator (hostgator.com), and take control of Windows-based machines using Internet Explorer, in an attack that lasted from late Thursday to Saturday afternoon. The hackers placed an iframe script in Web sites that directed some visitors to malicious addresses that would infect them.

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

The VML hole and other similar zero-day vulnerabilities, enable criminals to install spyware and other malware onto machines. The criminals behind the cPanel attack deployed this tactic, using a previously unknown vulnerability in cPanel to gain access to hundreds or thousands of servers that supply Web pages.

Dave Koston, an operations manager at cPanel, says the company patched the hole within an hour of it being brought to its attention. An update has since been passed along to the majority of servers that use cPanel. Koston also adds that the attackers would have needed a working account with each Web host in order to exploit the vulnerability.

HostGator owner Brent Oxley says some 200 HostGator servers were accessed, but he was unable to estimate how many of the sites were affected. He says the hackers used the cPanel vulnerability to access HostGator servers more than a month ago, and then kept a low profile before striking last week.

The iframe script redirected visitors using Internet Explorer, the only browser vulnerable to the VML flaw, while visitors using other browsers went unaffected. An estimated 20,000 sites are attempting to exploit the vulnerability, says Eric Sites, vice president of Sunbelt Software (sunbelt-software.com), the company that first discovered the flaw.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jim Lewandowski, Rackspace

Q&A: Clint Poole, Brinkster

New Features in Parallels Plesk 9

Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

More feature interviews and reports
 

Go Daddy Ads in the Grey Cup

Video Interview with Vinay Nagpal, Tata Communications

Copywriting for Direct Mail - Part 2: Big Guns

What Exactly is Semi-Dedicated Hosting?

Own your own jet

MLB.com switches to Flash; Hosting and Video Streaming Questions

More posts from our Bloggers


NameCheap Launches Twitter Promo

CBS Web Site Faces Malware Hack

VineyardHosting Limits Eternal Hosting

Email Use Increases As Economy Slows

HostNine Re-Launches New Website

SoftLayer Sponsors MSDN Conference

Hosting Sales and Promos Roundup

SoftLayer Shows Continued Growth

Microsoft Named on Spam Host List

3FN Ups Hardware Swap Capability

ZNet Brings Hyper-V VPS to India

Black Friday Causes Shutdowns


 

Marketing/Sales Trainer

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Learn more about the greening of the data center here.

> Is your company hiring? Post your job listing here!

> Get your company listed in our annual Buyer's Guide magazine issue - Deadline: Dec 31

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.