<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Media Temple Hacked</title>
	<atom:link href="http://michaeltorbert.com/blog/media-temple-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaeltorbert.com/blog/media-temple-hacked/</link>
	<description>WordPress Virtuoso</description>
	<lastBuildDate>Sun, 08 Jan 2012 17:55:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Halil</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-61629</link>
		<dc:creator>Halil</dc:creator>
		<pubDate>Sun, 08 Jan 2012 17:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-61629</guid>
		<description>This will be somewhat like resurrecting an old post but, hence some security-conscious people seem to come here from time to time, it looked me like an OK place to mumble this.

Surprise surprise! By default, all recent versions of Plesk including 8, 9 and 10 (most probably old versions too), store all account, ftp, database and email passwords in plain in a database named &quot;psa&quot;. This is a well-known fact for years.

Shared hosting is insecure. But Plesk gives you even more options to dis-secure it: it allows to use PHP as a module with Apache, without any suexec and suPHP options.

Any shared hosting provider which properly locks up everything? I&#039;ve yet see one. This is because securing a shared server is unresourcefully time-consuming, and no shared hosting provider I know of does meaningfully more than the installation defaults.

I&#039;m not telling these to dis any server panel or any hosting provider. Since I can be considered fairly involved in this business too, I can see their positions. And yet decently secure shared hosting providers can exist. And if you know one, please tell us! But I wouldn&#039;t hold my breath, if you can measure the security of a shared provider, you are probably quite ahead of using one.

Looking for a secure shared hosting? Start training yourself on *nix file permissions, chrooting, suexec/suPHP, hidden (non-)holes (re: PHP cgi_fix_pathinfo on nginx, of which even an nginx book writer seems to be unaware of), server log parsing, fail2ban, logwatch, audits, SELinux, etc etc.

And by the time you have some grasp on these, I bet you wouldn&#039;t be looking for shared hosting any more :) This is of course, if you really mind security, unlike most of the businesses and customers out there, which you don&#039;t have to :)</description>
		<content:encoded><![CDATA[<p>This will be somewhat like resurrecting an old post but, hence some security-conscious people seem to come here from time to time, it looked me like an OK place to mumble this.</p>
<p>Surprise surprise! By default, all recent versions of Plesk including 8, 9 and 10 (most probably old versions too), store all account, ftp, database and email passwords in plain in a database named &#8220;psa&#8221;. This is a well-known fact for years.</p>
<p>Shared hosting is insecure. But Plesk gives you even more options to dis-secure it: it allows to use PHP as a module with Apache, without any suexec and suPHP options.</p>
<p>Any shared hosting provider which properly locks up everything? I&#8217;ve yet see one. This is because securing a shared server is unresourcefully time-consuming, and no shared hosting provider I know of does meaningfully more than the installation defaults.</p>
<p>I&#8217;m not telling these to dis any server panel or any hosting provider. Since I can be considered fairly involved in this business too, I can see their positions. And yet decently secure shared hosting providers can exist. And if you know one, please tell us! But I wouldn&#8217;t hold my breath, if you can measure the security of a shared provider, you are probably quite ahead of using one.</p>
<p>Looking for a secure shared hosting? Start training yourself on *nix file permissions, chrooting, suexec/suPHP, hidden (non-)holes (re: PHP cgi_fix_pathinfo on nginx, of which even an nginx book writer seems to be unaware of), server log parsing, fail2ban, logwatch, audits, SELinux, etc etc.</p>
<p>And by the time you have some grasp on these, I bet you wouldn&#8217;t be looking for shared hosting any more <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  This is of course, if you really mind security, unlike most of the businesses and customers out there, which you don&#8217;t have to <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stu</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-61461</link>
		<dc:creator>Stu</dc:creator>
		<pubDate>Thu, 05 Jan 2012 21:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-61461</guid>
		<description>I used to use MediaTemple (around the time you posted your article).  Just googled them and found your post.  Glad I left!  Thanks for sharing your experience.

Stu.</description>
		<content:encoded><![CDATA[<p>I used to use MediaTemple (around the time you posted your article).  Just googled them and found your post.  Glad I left!  Thanks for sharing your experience.</p>
<p>Stu.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SomeGuy</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-47950</link>
		<dc:creator>SomeGuy</dc:creator>
		<pubDate>Wed, 14 Sep 2011 13:28:40 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-47950</guid>
		<description>I will give Media Temple credit, there interface is good, and the products for most part are pretty good and do not need much attention.  Pretty much run on their own.  What I do have to say is the level of customer service I just experienced.  They apparently let a brute force attack hit my box  resulting in my box getting hacked, there response was &quot;shutdown&quot; my server until I reinstalled.
Which took me about 12 hours because even after the reinstall things did not work as they were supposed to.  When I called tech support they told me I was on my own, and they can only help if the box was not running. And it was running just not working right.  After calling back several times I finally got a person who was not only nice, but went out of his way to help me.  

Did I mention a previous tech set my websites to use the &quot;admin&quot; account and password just to get my databases up and running because he could not get the mySQL user accounts I setup to work.  I would never use the &quot;admin&quot; account for this purpose, and yet they did.</description>
		<content:encoded><![CDATA[<p>I will give Media Temple credit, there interface is good, and the products for most part are pretty good and do not need much attention.  Pretty much run on their own.  What I do have to say is the level of customer service I just experienced.  They apparently let a brute force attack hit my box  resulting in my box getting hacked, there response was &#8220;shutdown&#8221; my server until I reinstalled.<br />
Which took me about 12 hours because even after the reinstall things did not work as they were supposed to.  When I called tech support they told me I was on my own, and they can only help if the box was not running. And it was running just not working right.  After calling back several times I finally got a person who was not only nice, but went out of his way to help me.  </p>
<p>Did I mention a previous tech set my websites to use the &#8220;admin&#8221; account and password just to get my databases up and running because he could not get the mySQL user accounts I setup to work.  I would never use the &#8220;admin&#8221; account for this purpose, and yet they did.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Performance Server Stack - Debian w/ Nginx, APC and PHP-FPM</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-41373</link>
		<dc:creator>WordPress Performance Server Stack - Debian w/ Nginx, APC and PHP-FPM</dc:creator>
		<pubDate>Sat, 23 Jul 2011 14:48:10 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-41373</guid>
		<description>[...] and Rackspace as I&#8217;ve had problems with both and they&#8217;ve had well documented &#160;security vulnerabilities&#160;in the past.Next Page: Connecting to your server the first time. Pages:  1 2 3 4 5 6 3 [...]</description>
		<content:encoded><![CDATA[<p>[...] and Rackspace as I&#8217;ve had problems with both and they&#8217;ve had well documented &nbsp;security vulnerabilities&nbsp;in the past.Next Page: Connecting to your server the first time. Pages:  1 2 3 4 5 6 3 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A Small Orange hacked &#124; Michael Torbert</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-33675</link>
		<dc:creator>A Small Orange hacked &#124; Michael Torbert</dc:creator>
		<pubDate>Mon, 16 May 2011 22:56:47 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-33675</guid>
		<description>[...] hosting company, A Small Orange, sent this email to its customers today. I&#8217;m reminded of when Media Temple was hacked recently. However, while A Small Orange still hasn&#8217;t let us know all the details, [...]</description>
		<content:encoded><![CDATA[<p>[...] hosting company, A Small Orange, sent this email to its customers today. I&#8217;m reminded of when Media Temple was hacked recently. However, while A Small Orange still hasn&#8217;t let us know all the details, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Got Hacked. Want to understand how.</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-18455</link>
		<dc:creator>Got Hacked. Want to understand how.</dc:creator>
		<pubDate>Sun, 28 Nov 2010 21:24:17 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-18455</guid>
		<description>[...] see this post from last year about the original fiasco (warning, it will piss you off). It&#8217;s gone downhill from there. I [...]</description>
		<content:encoded><![CDATA[<p>[...] see this post from last year about the original fiasco (warning, it will piss you off). It&#8217;s gone downhill from there. I [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KBSD</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-14867</link>
		<dc:creator>KBSD</dc:creator>
		<pubDate>Mon, 06 Sep 2010 15:59:43 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-14867</guid>
		<description>Following your comments, i approached MT to find out about them providing a backup service for my websites. 

Seems difficult. Or rather, they dont offer it. Do It Yourself.

Mmmh....</description>
		<content:encoded><![CDATA[<p>Following your comments, i approached MT to find out about them providing a backup service for my websites. </p>
<p>Seems difficult. Or rather, they dont offer it. Do It Yourself.</p>
<p>Mmmh&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: popo</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-14562</link>
		<dc:creator>popo</dc:creator>
		<pubDate>Mon, 30 Aug 2010 17:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-14562</guid>
		<description>And here we are again at the end of August 2010.  Three weeks ago, MediaTemple suffered an identical attack affecting thousands of users.

After spending countless hours recovering from the attack we were promised the system was now secure.

And then yesterday it happened AGAIN.

MediaTemple is an unmitigated DISASTER.  Be extremely careful using them for hosting.  Their systems are simply not secure.  They are completely clueless about security.</description>
		<content:encoded><![CDATA[<p>And here we are again at the end of August 2010.  Three weeks ago, MediaTemple suffered an identical attack affecting thousands of users.</p>
<p>After spending countless hours recovering from the attack we were promised the system was now secure.</p>
<p>And then yesterday it happened AGAIN.</p>
<p>MediaTemple is an unmitigated DISASTER.  Be extremely careful using them for hosting.  Their systems are simply not secure.  They are completely clueless about security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: News fix</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-13954</link>
		<dc:creator>News fix</dc:creator>
		<pubDate>Fri, 06 Aug 2010 17:24:31 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-13954</guid>
		<description>One of my clients is on media temple and today the 5th of august we got attacked. we couldnt understand the issue and in order to minimize impact on  our business, we had to change hostings.</description>
		<content:encoded><![CDATA[<p>One of my clients is on media temple and today the 5th of august we got attacked. we couldnt understand the issue and in order to minimize impact on  our business, we had to change hostings.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Ong</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-12089</link>
		<dc:creator>Patrick Ong</dc:creator>
		<pubDate>Sat, 12 Jun 2010 14:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-12089</guid>
		<description>woah...wondering if my DB on Media Temple has been hacked...

for some reason, for the past 2 days, my email has gone bonkers...I cannot access it, password not accepted via my Mail software and even webmail is not allowing me access...

scary...but I do agree that they are very good in terms of support...</description>
		<content:encoded><![CDATA[<p>woah&#8230;wondering if my DB on Media Temple has been hacked&#8230;</p>
<p>for some reason, for the past 2 days, my email has gone bonkers&#8230;I cannot access it, password not accepted via my Mail software and even webmail is not allowing me access&#8230;</p>
<p>scary&#8230;but I do agree that they are very good in terms of support&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alberto Hernandez</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10403</link>
		<dc:creator>Alberto Hernandez</dc:creator>
		<pubDate>Wed, 21 Apr 2010 15:05:27 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10403</guid>
		<description>I have the same fill, but they compromise 120 clients web sites, I have to change all my clients out side, because if I upgrade to other kind of server they cant migrate 3400 emails acounts and 280 websites included wordpress and joomla CMS websites, I have to change one by one in less a weak, because the problem in my country (MEXICO) dosnt have a real infraestructure and any provider to make a real webhost. In this time I have just 2 server in MT but they make the charges for entry year, soo I just end the terms and migrate this clients too.

The response for the MT staff was add in my acount 2 free moths or services like a 120 usd.</description>
		<content:encoded><![CDATA[<p>I have the same fill, but they compromise 120 clients web sites, I have to change all my clients out side, because if I upgrade to other kind of server they cant migrate 3400 emails acounts and 280 websites included wordpress and joomla CMS websites, I have to change one by one in less a weak, because the problem in my country (MEXICO) dosnt have a real infraestructure and any provider to make a real webhost. In this time I have just 2 server in MT but they make the charges for entry year, soo I just end the terms and migrate this clients too.</p>
<p>The response for the MT staff was add in my acount 2 free moths or services like a 120 usd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andres</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10399</link>
		<dc:creator>Andres</dc:creator>
		<pubDate>Wed, 21 Apr 2010 13:49:29 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10399</guid>
		<description>@DDD I completely agree with the latency. I love MediaTemple&#039;s interface but their service, even at cluster 6, was insanely slow. I just canceled :-(</description>
		<content:encoded><![CDATA[<p>@DDD I completely agree with the latency. I love MediaTemple&#8217;s interface but their service, even at cluster 6, was insanely slow. I just canceled <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DDD</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10384</link>
		<dc:creator>DDD</dc:creator>
		<pubDate>Wed, 21 Apr 2010 06:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10384</guid>
		<description>Unless you are on a newer or as yet not overcrowded cluster, check your http and database latency. It&#039;s insanely bad. SQL container helps.</description>
		<content:encoded><![CDATA[<p>Unless you are on a newer or as yet not overcrowded cluster, check your http and database latency. It&#8217;s insanely bad. SQL container helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Changing Technology = Problems</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10377</link>
		<dc:creator>Changing Technology = Problems</dc:creator>
		<pubDate>Wed, 21 Apr 2010 02:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10377</guid>
		<description>I don&#039;t gauge a web hosting company by their lack of problems, but the way and the speed at which they deal with problems. Media Temple has continued to show forward thinking, regular equipment upgrades, and they do a good job communicating with their customers. Plus, their technical support is excellent.

I have been with them since 2005 and have dozens of subdomains hosted with them and none of my servers have been compromised or hacked to my knowledge. You won&#039;t find a perfect web host, but Media Temple has a good track record, and we are pleased to do business with them.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t gauge a web hosting company by their lack of problems, but the way and the speed at which they deal with problems. Media Temple has continued to show forward thinking, regular equipment upgrades, and they do a good job communicating with their customers. Plus, their technical support is excellent.</p>
<p>I have been with them since 2005 and have dozens of subdomains hosted with them and none of my servers have been compromised or hacked to my knowledge. You won&#8217;t find a perfect web host, but Media Temple has a good track record, and we are pleased to do business with them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linda Sherman</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10364</link>
		<dc:creator>Linda Sherman</dc:creator>
		<pubDate>Tue, 20 Apr 2010 20:30:35 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10364</guid>
		<description>I am currently dealing with this with a large hosting company. I do not want to go through this again. I have registered a couple of domains with Media Temple but haven&#039;t launched yet. Is there ANY Shared Hosting system that is SAFE?

Laughing Squid for RackSpace?

I came to Media Temple because of their great reputation but after getting their letter about the password change was very unsettling.

Linda</description>
		<content:encoded><![CDATA[<p>I am currently dealing with this with a large hosting company. I do not want to go through this again. I have registered a couple of domains with Media Temple but haven&#8217;t launched yet. Is there ANY Shared Hosting system that is SAFE?</p>
<p>Laughing Squid for RackSpace?</p>
<p>I came to Media Temple because of their great reputation but after getting their letter about the password change was very unsettling.</p>
<p>Linda</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10162</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Sun, 11 Apr 2010 00:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10162</guid>
		<description>Media Temple is still dealing with the fallout from this big security breach. They&#039;ve been changing out passwords, including database credentials, on the many accounts affected by this incident.</description>
		<content:encoded><![CDATA[<p>Media Temple is still dealing with the fallout from this big security breach. They&#8217;ve been changing out passwords, including database credentials, on the many accounts affected by this incident.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cullen</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10121</link>
		<dc:creator>Cullen</dc:creator>
		<pubDate>Thu, 08 Apr 2010 19:24:05 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10121</guid>
		<description>I&#039;ve been nothing but impressed with Media Temple.  For the last 6 years they have done what they said they would do and more.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been nothing but impressed with Media Temple.  For the last 6 years they have done what they said they would do and more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Askar Sabiq</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-10029</link>
		<dc:creator>Askar Sabiq</dc:creator>
		<pubDate>Sun, 04 Apr 2010 04:05:37 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-10029</guid>
		<description>nevermind, big hosting in the planet got hacked :) so &quot;no one 100% secure&quot; statement is right :D anyway, great blog!</description>
		<content:encoded><![CDATA[<p>nevermind, big hosting in the planet got hacked <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  so &#8220;no one 100% secure&#8221; statement is right <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  anyway, great blog!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: QWD</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-9759</link>
		<dc:creator>QWD</dc:creator>
		<pubDate>Tue, 23 Mar 2010 08:03:15 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-9759</guid>
		<description>I have read about this hack on numerous boards ...  I also have had a server compromised by the same hack. Here is what I know is true, first off we are not with the aforementioned hosting companies, and yes they had several servers compromised. It was not only blogs, but actually php based coded apps and sites. The hacks occured in the same time frame as those mentioned here. One of our clients had a virus on a office computer, and the hacks occured on the sites in his ftp client. The code injected into our sites was the same as was seen in ours and others ...   etc   ...</description>
		<content:encoded><![CDATA[<p>I have read about this hack on numerous boards &#8230;  I also have had a server compromised by the same hack. Here is what I know is true, first off we are not with the aforementioned hosting companies, and yes they had several servers compromised. It was not only blogs, but actually php based coded apps and sites. The hacks occured in the same time frame as those mentioned here. One of our clients had a virus on a office computer, and the hacks occured on the sites in his ftp client. The code injected into our sites was the same as was seen in ours and others &#8230;   etc   &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bruce</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-9323</link>
		<dc:creator>bruce</dc:creator>
		<pubDate>Thu, 11 Mar 2010 06:55:45 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-9323</guid>
		<description>I&#039;ve had the same code injection attack occur on two of my websites. Both use shared hosting but both are with different companies. It seems like it is quite common with shared hosting.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve had the same code injection attack occur on two of my websites. Both use shared hosting but both are with different companies. It seems like it is quite common with shared hosting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vladimir</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-9273</link>
		<dc:creator>Vladimir</dc:creator>
		<pubDate>Tue, 09 Mar 2010 23:40:23 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-9273</guid>
		<description>@Viktor:

&gt; especially since rainbow tables for hashes were invented

Using a salt when hashing the password renders rainbow tables useless ;-)</description>
		<content:encoded><![CDATA[<p>@Viktor:</p>
<p>&gt; especially since rainbow tables for hashes were invented</p>
<p>Using a salt when hashing the password renders rainbow tables useless <img src='http://michaeltorbert.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-9126</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Fri, 05 Mar 2010 08:07:55 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-9126</guid>
		<description>I had the same expirience with some hosting companies. Now I have my own server and we moved to Linux at the workstations after problems like this. Windows runs only in the Virtual Box to test the IE. Some virus use the open FTP connection at the computer, so if you have a virus at a developer machine you get a big problem. But the same is if the webserver is hacked and they get root permission. Then have all customers at this server a big problem. And the most hosting companies don&#039;t use a virus scanner at a webserver. And if a virus or a stupid staff of the hosting company changed the permission at your hosting, you can&#039;t see the files with the virus or can&#039;t delete or change it. I had two hosting companies with the problem with the permission and they ignored my requests.
For all that use standard software like phpmyadmin. Please never use the normal path or easy paswords. At every webserver you can see in the logs a lot of requests to /phpmyadmin /phpMyAdmin and so on. The same is with Webmailer. So you can reduce the risk with change the path name.</description>
		<content:encoded><![CDATA[<p>I had the same expirience with some hosting companies. Now I have my own server and we moved to Linux at the workstations after problems like this. Windows runs only in the Virtual Box to test the IE. Some virus use the open FTP connection at the computer, so if you have a virus at a developer machine you get a big problem. But the same is if the webserver is hacked and they get root permission. Then have all customers at this server a big problem. And the most hosting companies don&#8217;t use a virus scanner at a webserver. And if a virus or a stupid staff of the hosting company changed the permission at your hosting, you can&#8217;t see the files with the virus or can&#8217;t delete or change it. I had two hosting companies with the problem with the permission and they ignored my requests.<br />
For all that use standard software like phpmyadmin. Please never use the normal path or easy paswords. At every webserver you can see in the logs a lot of requests to /phpmyadmin /phpMyAdmin and so on. The same is with Webmailer. So you can reduce the risk with change the path name.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-8914</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Sun, 28 Feb 2010 15:24:58 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-8914</guid>
		<description>We host on liquidnet ie ResellersPanel and MANY MANY sites were hacked the same time Your hosting got nailed. Except ResellersPanel is in full denial mode blamming each customer for 100s of lost or hacked websites.

They are out right rude to the point of making threats if anyone tells the public.

Good Luck with yours, we&#039;ll be moving ours.</description>
		<content:encoded><![CDATA[<p>We host on liquidnet ie ResellersPanel and MANY MANY sites were hacked the same time Your hosting got nailed. Except ResellersPanel is in full denial mode blamming each customer for 100s of lost or hacked websites.</p>
<p>They are out right rude to the point of making threats if anyone tells the public.</p>
<p>Good Luck with yours, we&#8217;ll be moving ours.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Florian</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-8794</link>
		<dc:creator>Florian</dc:creator>
		<pubDate>Thu, 25 Feb 2010 10:29:22 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-8794</guid>
		<description>It&#039;s shocking to hear that passwords are stored as plain text, security is never perfect, but leaving the front door open and expecting noone to simply walk in is very unprofessional in my opinion.</description>
		<content:encoded><![CDATA[<p>It&#8217;s shocking to hear that passwords are stored as plain text, security is never perfect, but leaving the front door open and expecting noone to simply walk in is very unprofessional in my opinion.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Server move complete &#8211; Linode rules! &#124; mou.me.uk</title>
		<link>http://michaeltorbert.com/blog/media-temple-hacked/comment-page-2/#comment-8487</link>
		<dc:creator>Server move complete &#8211; Linode rules! &#124; mou.me.uk</dc:creator>
		<pubDate>Tue, 23 Feb 2010 12:58:30 +0000</pubDate>
		<guid isPermaLink="false">http://michaeltorbert.com/?p=612#comment-8487</guid>
		<description>[...] for nearly 2 years, and I decided enough was enough. Slow load times, dodgy password policies and a rather high profile server wide hack was enough to convince me that it was time to put my new found sysadmin skills to use and move all [...]</description>
		<content:encoded><![CDATA[<p>[...] for nearly 2 years, and I decided enough was enough. Slow load times, dodgy password policies and a rather high profile server wide hack was enough to convince me that it was time to put my new found sysadmin skills to use and move all [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

