Go Back   HostGator Peer Support Forums > HostGator Announcements > Network Status

Notices

Reply
 
Thread Tools
  #1  
Old 01-24-2005, 02:12 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Santy worm affecting all cpanel hosts

http://forums.cpanel.net/showthread.php?t=34846
http://www.phpbb.com/phpBB/viewtopic.php?t=258892

This internet attack is flooding out apache on many servers and causing problems everywhere on the internet. Bad day for the internet very bad day for us.

Things will get better as ISP's setup filters.
__________________
Gators love marshmallows.
Reply With Quote
  #2  
Old 01-24-2005, 02:37 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Santy worm affecting all cpanel hosts

The worm is written to a file "m1ho2of" on the victim. After the transfer is complete, the worm will use the exploit once again to execute the code using the system default Perl interpreter.

Santy contains also a generation counter that is increased every time the worm is executed, i.e. once per infected host. If the number of generations is higher than three (3), it will execute its payload. The payload attempts to replace all files with the following extensions ".htm", ".php", ".asp", ".shtm", ".jsp" and ".phtm". The result is the these files are replaced with a HTML page that contains the following text:
__________________
Gators love marshmallows.
Reply With Quote
  #3  
Old 01-24-2005, 02:43 PM
Dawn Dawn is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 38
Default Re: Santy worm affecting all cpanel hosts

I realize that there is no need to submit a support ticket even though my site is down, but I have no clue what all you have just said means. Will my site still be intact when this is over? I don't run any message board on it.


Thanks
Dawn
Reply With Quote
  #4  
Old 01-24-2005, 02:51 PM
netuser netuser is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 12
Default Re: Santy worm affecting all cpanel hosts

Is there something being done? Or do we just wait until this is blown over somehow?
Reply With Quote
  #5  
Old 01-24-2005, 02:54 PM
abstraktMedia's Avatar
abstraktMedia abstraktMedia is offline
Junior Croc
 
Join Date: Aug 2003
Location: Ljubljana
Posts: 120
Default Re: Santy worm affecting all cpanel hosts

Yeah...we still don't know what this means?is our data going to be fine or will everything be lost...I have one phpBB but I patched it to a latest version just because of Santy a month ago...
__________________

- advanced programming and design
- database development - MySQL, MSSQL ...
- hosting - PHP, MySQL, CGI, PERL ...
- domains - 30 different TLDs
Reply With Quote
  #6  
Old 01-24-2005, 03:02 PM
britbob britbob is offline
Swamp Croc
 
Join Date: Oct 2004
Posts: 270
Default Re: Santy worm affecting all cpanel hosts

Could this be why Jetta has been slow today? Seems to take some time to open a page, then other times it`s much better.

Is this effecting only phpBB? Some detail in `english` please Brent
__________________
Bob.

Reply With Quote
  #7  
Old 01-24-2005, 03:11 PM
jscherbel jscherbel is offline
Hatchling Croc
 
Join Date: Jun 2004
Location: Salt Lake City, UT
Posts: 3
Default Re: Santy worm affecting all cpanel hosts

To my knowledge, this virus attacks phpBB message boards on a version other than 2.0.11 -- I'm open to being told otherwise.

I know that my site as well as most of my client's sites have upgraded to 2.0.11 yet my account is currently suspended? There goes my customers/users as they get a "suspended" message on my site!

I hope Brent and co. figure things out soon. Good luck!
Reply With Quote
  #8  
Old 01-24-2005, 03:17 PM
Jme574 Jme574 is offline
Junior Croc
 
Join Date: Dec 2004
Posts: 178
Default Re: Santy worm affecting all cpanel hosts

I still have accounts with 2 other hosing companies as i have not fully transfered all my accounts to my resellers account here with hostgator. both of the other companies are having the same exact problem as we are having here.


just thought that everyone would like to know that so they understand that this is not just a host gator problem. With alot of luck and super support hopefully everything will get back on track soon.
Reply With Quote
  #9  
Old 01-24-2005, 03:54 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Santy worm affecting all cpanel hosts

That is correct it is an Internet problem that pretty much can only wait to be blown over. It is the ISP's job to set up filters to block out the damage from the worm router side.

All the servers are fine they are simply being overloaded by fake traffic that cannot be blocked. You cannot block the entire Internet....

So both the servers are affected and the Internet is slower from everything being overwhelmed.

It has died down significantly already. This morning when I woke every server was having problems as far as downtime. A few servers had to be rebooted and took over 20 minutes to come back online because of the flooding going on.

Think of the Internet as a 6 Lane Hwy a chemical truck flipped over and has leakage. You now have one Highway Lane left open things are not going to move fast and all you can do is wait for them to clean it up.
__________________
Gators love marshmallows.
Reply With Quote
  #10  
Old 01-24-2005, 04:04 PM
Dawn Dawn is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 38
Default Re: Santy worm affecting all cpanel hosts

Thank You for explaining
Reply With Quote
  #11  
Old 01-24-2005, 05:10 PM
jscherbel jscherbel is offline
Hatchling Croc
 
Join Date: Jun 2004
Location: Salt Lake City, UT
Posts: 3
Default Re: Santy worm affecting all cpanel hosts

When will you begin replying to "sales" emails regarding my suspended account - which I have to assume is related to this thread as I had no balance due yesterday?
Reply With Quote
  #12  
Old 01-24-2005, 05:29 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Santy worm affecting all cpanel hosts

"This appears to be a new variant of the recent phpbb exploit and tipping point is currently working on a updated vaccine to identify and block this exploit. This should hopefully be put in place shortly. Thanks. "

The data center is waiting on a filter the World’s Most Powerful Intrusion Prevention System. (TippingPoint’s UnityOne)
__________________
Gators love marshmallows.
Reply With Quote
  #13  
Old 01-24-2005, 06:05 PM
programmer programmer is offline
Junior Croc
 
Join Date: Dec 2004
Posts: 171
Default Re: Santy worm affecting all cpanel hosts

Great; hopefully this is taken care of soon.

I've noticed a bigger load on jetta, but nothing major. Right now it is 2.2, but earlier it was 5.4. All is working ok though. Does this have anything to do with that I wonder?
Reply With Quote
  #14  
Old 01-24-2005, 07:20 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Santy worm affecting all cpanel hosts

yes all the servers have extreme loads from this.
__________________
Gators love marshmallows.
Reply With Quote
  #15  
Old 01-24-2005, 09:09 PM
egoHavoc egoHavoc is offline
Hatchling Croc
 
Join Date: Apr 2004
Posts: 8
Default Re: Santy worm affecting all cpanel hosts

Thank you for the FYI guys.. your always doing a great job (:
Reply With Quote
  #16  
Old 01-24-2005, 10:06 PM
GatorBrent's Avatar
GatorBrent GatorBrent is offline
HostGator Staff
 
Join Date: Oct 2002
Location: houston, texas
Posts: 2,977
Default Re: Santy worm affecting all cpanel hosts

Things are extremely calm at the moment. We have servers with a single site on them that went off-line because of this. The bulk of it should be over, but I guess we'll see tomorrow when Internet traffic is at its peak. I believe it should be okay =)
__________________
Gators love marshmallows.
Reply With Quote
  #17  
Old 01-24-2005, 11:08 PM
mikegi mikegi is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 9
Default Re: Santy worm affecting all cpanel hosts

Quote:
Originally Posted by GatorBrent
Things are extremely calm at the moment. We have servers with a single site on them that went off-line because of this. The bulk of it should be over, but I guess we'll see tomorrow when Internet traffic is at its peak. I believe it should be okay =)
Thanks for getting this fixed. I'm thinking that Gitmo is too good for the perp(s) who did this...
Reply With Quote
  #18  
Old 01-25-2005, 01:44 AM
abstraktMedia's Avatar
abstraktMedia abstraktMedia is offline
Junior Croc
 
Join Date: Aug 2003
Location: Ljubljana
Posts: 120
Default Re: Santy worm affecting all cpanel hosts

Yeah Brent...thanx for keeping us updated...you guys are doing a great job...as always...that's why me and my bussiness are with you for almost a year and a half...ok chat support could be better but ther's always something that could be better...also thanx on behalf of my customers...
__________________

- advanced programming and design
- database development - MySQL, MSSQL ...
- hosting - PHP, MySQL, CGI, PERL ...
- domains - 30 different TLDs
Reply With Quote
  #19  
Old 01-25-2005, 12:06 PM
Amish's Avatar
Amish Amish is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 47
Default Re: Santy worm affecting all cpanel hosts

The past 4 months or so, have seen a lot of downtime and outages, and whatnot. I jumped to HG because my prior webhost was a pile of horsecrap... Now HG is looking to almost be the same. My website is one of the very few things I still like about the internet, and it sucks when I can't even get to it.
__________________
Reply With Quote
  #20  
Old 01-25-2005, 02:36 PM
netuser netuser is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 12
Question Re: Santy worm affecting all cpanel hosts

Yesterday night and this morning, my site loaded up fast. But since then, the site has been pretty slow again. Are the attacks still going on?
Reply With Quote
  #21  
Old 01-25-2005, 02:43 PM
Dawn Dawn is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 38
Default Re: Santy worm affecting all cpanel hosts

My site is slow off and on too, and FTP is a nightmare...
Reply With Quote
  #22  
Old 01-25-2005, 03:05 PM
ginger ginger is offline
Hatchling Croc
 
Join Date: Jan 2004
Posts: 9
Default Re: Santy worm affecting all cpanel hosts

My sites are working, however my outgoing SMTP is not...is this the same problem, or should I submit a ticket?
Reply With Quote
  #23  
Old 01-25-2005, 03:11 PM
Dawn Dawn is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 38
Default Re: Santy worm affecting all cpanel hosts

my site just stopped loading again, and so has my CPanel...
Reply With Quote
  #24  
Old 01-25-2005, 03:13 PM
dan dan is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 1
Default Re: Santy worm affecting all cpanel hosts

Is there anyway to get things like this, where perfomance on our sites is likely to be affected, via an email announcement? I'd venture most of us don't check the forum until we have a problem, where we are already muttering things like 'that @#$@#@# hostgator' under our breath.

If I would have had an email stating this problem was occuring, I would have been muttering 'that #$%$@$ worm, thanks hostgator'.

I would welcome the opportunity to get these 'warnings' in a more proactive manner. Putting it on the forum is good, getting to me is better.

Dan
Reply With Quote
  #25  
Old 01-25-2005, 04:10 PM
netuser netuser is offline
Hatchling Croc
 
Join Date: Sep 2004
Posts: 12
Negative Re: Santy worm affecting all cpanel hosts

I totally agree that keeping customers in the loop is the best way to keep their business. OK, it is not customer service 101, but it is a well-known way for customer satisfaction. If it is not your fault and you are working on the issue, we will understand. Just let us know. It is very frustrating to be kept in the dark. Should we wonder if the problem would be solved in the next minute or never? Are there other hosting companies that are not having this problem?
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

All times are GMT -6. The time now is 01:41 AM.

 
Forum SEO by Zoints