Go Back   HostGator Peer Support Forums > HostGator Announcements > General Announcements

Notices

Reply
 
Thread Tools
  #201  
Old 07-13-2009, 04:59 PM
Zigling Zigling is offline
Hatchling Croc
 
Join Date: Jul 2009
Posts: 4
Default Re: All Servers - SSH Access Restricted

People will goggle and find this thread.

I went through the proper channels, already. This is where people can learn and make informed choices before they spend their cashola.

My experiences and valid complaints do not make me a spoilt child. Stop with the smack-downs. Peace to you lot because I've said what I needed to say.


/Zig
Reply With Quote
  #202  
Old 07-13-2009, 05:08 PM
SlAiD SlAiD is offline
Hatchling Croc
 
Join Date: Jun 2009
Posts: 45
Default Re: All Servers - SSH Access Restricted

@Zigling, just asking, how old are you?


SL
__________________
My Blog - ruicruz.pt
Reply With Quote
  #203  
Old 07-13-2009, 05:27 PM
Gump Gump is offline
Hatchling Croc
 
Join Date: Jun 2009
Posts: 4
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by SlAiD View Post
@Zigling, just asking, how old are you?
SlAiD, Please provide your age as well. I don't have a clue what this has to do with the discussion of SSH Access.

Just because a customer is unhappy with something doesn't mean others need to attack him to validate their own choice of vendor. Perhaps we could be a little more constructive?
Reply With Quote
  #204  
Old 07-13-2009, 05:31 PM
Target2019's Avatar
Target2019 Target2019 is offline
Junior Croc
 
Join Date: Feb 2008
Posts: 107
Default Re: All Servers - SSH Access Restricted

http://www.techworld.com/security/ne...?newsID=118941

Is this the flaw in question?
Reply With Quote
  #205  
Old 07-13-2009, 05:37 PM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,553
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by Target2019 View Post
if you mean this:
Quote:
There also seems to be some confusion between the alleged zero-day and a different vulnerability in OpenSSH, Zdrnja said. That vulnerability, which is as of yet unpatched, could allow an attacker to recover up to 32 bits of plain text from an arbitrary block of ciphertext from a connection secured using the SSH protocol in the standard configuration, according to an advisory from the UK's Center for the Protection of National Infrastructure (CPNI).
could be...
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #206  
Old 07-13-2009, 05:53 PM
jtoon86 jtoon86 is offline
Hatchling Croc
 
Join Date: Jul 2009
Posts: 7
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by Target2019 View Post
Is this the flaw in question?
Hard to say. HG beyond saying they had some "credible evidence" of a security issue (that apparently no one else has ... OpenSSH development team, Red Hat, CentOS, other hosting companies, SANS, etc) has not provided details on what exactly they are protecting their servers from.

I'm glad they provided per-IP access as that is sufficient for my needs for the HG account I currently have with the company, but the lack of communication on exactly WHAT they are protecting us from and why upgrading to the latest version mid-last week wasn't sufficient enough still leaves me scratching my head.

Right now, as a customer, I find this lack of communication and missing a deadline w/o follow-up very concerning. While this is the first issue I have come across with HG since hosting with them mid-last year, I'd feel much more comfortable with some migration plans (migrating accounts from other hosting providers to HG) if there was more disclosure about this issue.
Reply With Quote
  #207  
Old 07-13-2009, 05:56 PM
SlAiD SlAiD is offline
Hatchling Croc
 
Join Date: Jun 2009
Posts: 45
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by Gump View Post
SlAiD, Please provide your age as well. I don't have a clue what this has to do with the discussion of SSH Access.

Just because a customer is unhappy with something doesn't mean others need to attack him to validate their own choice of vendor. Perhaps we could be a little more constructive?
If the customer is unhappy he have 45 days to move.

So: If he's unhappy with the procedures of HG does not help to go here - an unofficial channel - complaining about.

The childhood previous posts let me to ask that.


Anyway, let's get to the topic...


SL
__________________
My Blog - ruicruz.pt
Reply With Quote
  #208  
Old 07-13-2009, 10:25 PM
CPColin CPColin is offline
Hatchling Croc
 
Join Date: Jul 2009
Posts: 1
Default Re: All Servers - SSH Access Restricted

It's funny that HostGator is being this paranoid about this SSH vulnerability when they store our passwords as plain text, display them on various pages, and spew them in unencrypted emails all over the place.
Reply With Quote
  #209  
Old 07-13-2009, 11:39 PM
RBX0122 RBX0122 is offline
Junior Croc
 
Join Date: May 2006
Posts: 105
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by CPColin View Post
It's funny that HostGator is being this paranoid about this SSH vulnerability when they store our passwords as plain text, display them on various pages, and spew them in unencrypted emails all over the place.

Can you please explain this ?
Reply With Quote
  #210  
Old 07-14-2009, 05:34 AM
Target2019's Avatar
Target2019 Target2019 is offline
Junior Croc
 
Join Date: Feb 2008
Posts: 107
Default Re: All Servers - SSH Access Restricted

New, possible OpenSSH exploit brought to HG attention 7/5/2009 as stated in start of this thread. So I am reasonably sure the article is about the same reported flaw.

More about it here:
http://isc.sans.org/diary.html?storyid=6760

If I had 10's of thousands of customers I'd be worried, for sure. However, if offering SSH as part of my business, then would think more carefully about shutting down the service.

I haven't suffered any consequences because of this, but it will definitely stay in my mind as I consider what clients to host here.
Reply With Quote
  #211  
Old 07-14-2009, 08:38 AM
Chief Plasma Chief Plasma is offline
Hatchling Croc
 
Join Date: Feb 2007
Posts: 22
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by Zigling View Post
How about they find another way to prove it's me rather than me holding my friend's credit card information?
/Zig

A paypal email receipt does that for you. They need the transactoin ID that way. No cards involved.

Anyway, bet of luck to ya.


-cp
Reply With Quote
  #212  
Old 07-14-2009, 08:44 AM
Chief Plasma Chief Plasma is offline
Hatchling Croc
 
Join Date: Feb 2007
Posts: 22
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by boiserc View Post
Can you please explain this ?

You do not get the reminders that say your account is due with your user and pw inside. I hate that too. But that is not this threads topic.
Reply With Quote
  #213  
Old 07-14-2009, 07:54 PM
GatorDHanna's Avatar
GatorDHanna GatorDHanna is offline
HostGator Staff
 
Join Date: Sep 2008
Location: United States
Posts: 572
Default Re: All Servers - SSH Access Restricted

SSH access has been restored and should now be open and accessible to all customers (regardless of IP whitelisting status).

If you run into any problems or have any difficulties connecting, please let our support team know via email at support@hostgator.com.
__________________
Douglas
Customer Service Manager
HostGator.com LLC
1-866-96-GATOR
Reply With Quote
  #214  
Old 07-14-2009, 08:45 PM
kjvarga kjvarga is offline
Hatchling Croc
 
Join Date: Oct 2008
Posts: 4
Unhappy Re: All Servers - SSH Access Restricted

Well thank goodness for that! Unfortunately I am now getting errors from Ruby Net::SSH when I try to deploy my sites using Capistrano and it's got something to do with the recent changes.

First I was getting this encryption_client algorithm error which I have since solved:

Code:
 ** [deploy:update_code] exception while rolling back: Capistrano::ConnectionError, connection failed for: varzyfamily.com (Net::SSH::Exception: could not settle on encryption_client algorithm)
connection failed for: varzyfamily.com (Net::SSH::Exception: could not settle on encryption_client algorithm)
Some information was available from:

http://www.mail-archive.com/capistra.../msg05641.html

So I installed an updated net-ssh gem from Delano on GitHub:

Download tarball of http://github.com/delano/net-ssh/tree/master then from the download directory do the following.

Code:
gem sources -a http://gems.github.com
gem install mislav-hanna
gem install echoe
gem build net-ssh.gemspec
gem install net-ssh-2.0.12.gem
Sweet! All done. But now I'm getting this CipherError about the key length being too short. Damn! I think I'm getting closer tho. I am using RSA keys to connect to HG (of default lenght, not sure exactly).

Code:
 ** [deploy:update_code] exception while rolling back: Capistrano::ConnectionError, connection failed for: varzyfamily.com (OpenSSL::CipherError: key length too short)
connection failed for: varzyfamily.com (OpenSSL::CipherError: key length too short)
Any ideas? Do I just need to generate a different (DSA) key? longer key?
Reply With Quote
  #215  
Old 07-14-2009, 09:21 PM
kjvarga kjvarga is offline
Hatchling Croc
 
Join Date: Oct 2008
Posts: 4
Default Re: All Servers - SSH Access Restricted

Got this reply from HG:

This is caused by the cipher that Capistrano is using - in short before Capistrano can talk to our servers, it performs a "handshake" with the server so the server and Capistrano know how to communicate with each other. We made several changes to eliminate the use of weak and easily exploitable (english: bad) ciphers and it appears that Capistrano is unable to agree with our server on which cipher to use.

Our servers are currently set to only allow these ciphers:
aes128-ctr,aes256-ctr,arcfour256,arcfour

You may need to contact the developer of Capistrano at http://www.capify.org/index.php/Capistrano with the above informatin on what ciphers we need it to support as I am not familiar with that program.
Reply With Quote
  #216  
Old 07-14-2009, 11:30 PM
rstanley rstanley is offline
Hatchling Croc
 
Join Date: Jul 2009
Posts: 3
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by GatorDHanna View Post
SSH access has been restored and should now be open and accessible to all customers (regardless of IP whitelisting status).

If you run into any problems or have any difficulties connecting, please let our support team know via email at support@hostgator.com.
Now perhaps you can update the "Announcements" on the Control Panel so that people can see it, and receive the notice by email, if they have signed up for that option! After all, that's what it is there for! This has not been updated since "Thu, 09 Jul 2009 13:52:09 CDT"
Reply With Quote
  #217  
Old 07-15-2009, 01:31 AM
Jean-Luc Jean-Luc is offline
Hatchling Croc
 
Join Date: Jul 2008
Posts: 44
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by kjvarga View Post
Got this reply from HG:

Our servers are currently set to only allow these ciphers:
aes128-ctr,aes256-ctr,arcfour256,arcfour
This explains why I get "Couldn't agree a client-to-server cypher (available aes128-ctr,aes256-ctr,arcfour256,arcfour)" when I try to connect with PuTTY.

How can I add support for "aes128-ctr,aes256-ctr,arcfour256,arcfour" in PuTTY ?

Jean-Luc

Last edited by Jean-Luc; 07-15-2009 at 01:34 AM.
Reply With Quote
  #218  
Old 07-15-2009, 03:30 AM
GatorZKarr's Avatar
GatorZKarr GatorZKarr is offline
HostGator Staff
 
Join Date: Jul 2008
Posts: 211
Default Re: All Servers - SSH Access Restricted

Jean-Luc, that error has been documented with putty 0.55 and our updated version of SSH. If you use the latest version (0.60) you should be able to connect without any issue.

http://support.hostgator.com/article...-cipher-errors
Reply With Quote
  #219  
Old 07-15-2009, 03:40 AM
Jean-Luc Jean-Luc is offline
Hatchling Croc
 
Join Date: Jul 2008
Posts: 44
Default Re: All Servers - SSH Access Restricted

I am now connected with 0.60. Thanks.

Jean-Luc
__________________
200ok.eu Broken Link Checker finds 404 errors, error pages with 200 ok status, missing images, protocol errors, password protected pages, bad domain names, redirect loops, parking pages,...
Reply With Quote
  #220  
Old 07-15-2009, 11:09 AM
bhoult bhoult is offline
Hatchling Croc
 
Join Date: Jan 2009
Posts: 1
Default Re: All Servers - SSH Access Restricted

Did you ever figure out how to get capistrano working?... I am having the same issue.
Reply With Quote
  #221  
Old 07-15-2009, 11:15 AM
citawds's Avatar
citawds citawds is offline
Swamp Croc
 
Join Date: Oct 2008
Location: Colorado
Posts: 210
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by GatorZKarr View Post
Jean-Luc, that error has been documented with putty 0.55 and our updated version of SSH. If you use the latest version (0.60) you should be able to connect without any issue.

http://support.hostgator.com/article...-cipher-errors
Ah that clears it up. I also ran into the same error message but then I fired up Secure Copy which connected without issues leading me to think I had an issue with my copy of putty, I just deleted and downloaded another copy which would be the latest which of course works, I never investigated further thinking I had some how borked putty ;-)

I will say that when I fired off an email to hostgator support asking to have my IP white-listed this was done within less then 5 minutes no other issues better to be safe then sorry thanks support!

Steve
Reply With Quote
  #222  
Old 07-15-2009, 11:25 AM
quint's Avatar
quint quint is offline
Hatchling Croc
 
Join Date: Sep 2006
Posts: 28
Default Re: All Servers - SSH Access Restricted

SFTP is working fine again
Reply With Quote
  #223  
Old 07-15-2009, 11:33 AM
GatorDHanna's Avatar
GatorDHanna GatorDHanna is offline
HostGator Staff
 
Join Date: Sep 2008
Location: United States
Posts: 572
Default Re: All Servers - SSH Access Restricted

Quote:
Originally Posted by rstanley View Post
Now perhaps you can update the "Announcements" on the Control Panel so that people can see it, and receive the notice by email, if they have signed up for that option! After all, that's what it is there for! This has not been updated since "Thu, 09 Jul 2009 13:52:09 CDT"
This has been done. Thanks!
__________________
Douglas
Customer Service Manager
HostGator.com LLC
1-866-96-GATOR
Reply With Quote
  #224  
Old 07-15-2009, 07:48 PM
kjvarga kjvarga is offline
Hatchling Croc
 
Join Date: Oct 2008
Posts: 4
Default Re: All Servers - SSH Access Restricted

No, I don't have solution to the Capistrano problem. I'm going to have to try to take a look at it over the next couple days. If anyone solves it, please be sure to post the solution to this thread.
Reply With Quote
  #225  
Old 07-17-2009, 03:30 AM
kjvarga kjvarga is offline
Hatchling Croc
 
Join Date: Oct 2008
Posts: 4
Default Re: All Servers - SSH Access Restricted

Holy smokes, I've fixed the Capistrano problem! I feel like a god! I feel invincible! I feel...dizzy.

It turns out it's a problem with Ruby's Net::SSH and OpenSSL implementations, and possibly also with your OpenSSL C libraries :/

However, I've created a work around for Net::SSH which should cover any bugs in the underlying OpenSSL. The problem is with the ARCFOUR256 cipher and OpenSSL's RC4 cipher handling. OpenSSL thinks the key should be 16 bytes long so Net::SSH goes and creates one of 16 bytes. But then OpenSSH says that "the key is too short".

So I've forced Net::SSH to generate adequately long keys for ARCFOUR256 and ARCFOUR512 (I added that for kicks) ciphers and now OpenSSL doesn't complain.

You can read more about it and get an updated ruby Gem from http://github.com/kjvarga/net-ssh/tree/master.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
access restricted page Beatmeoutofme Pre-Sales Questions 1 09-08-2008 04:06 PM
Linux servers or Windows servers? Sphinx Shared Hosting Support 2 06-17-2008 12:55 PM
Restricted Upload via FTP?? Pazeh Shared Hosting Support 6 01-10-2008 08:03 AM
creating a quota/password restricted ftp account YellowFish Shared Hosting Support 1 05-30-2003 12:14 PM

All times are GMT -5. The time now is 01:31 AM.