Live data from Hacker News

We tested popular web hosting companies and all were easily hacked

websiteplanet.com

31–40 of 52 posts

Re: We tested popular web hosting companies and all were easily hacked

#31

I wish they had kept going till they found a web hosting firm that didn't have these issues. Can anyone -- not affiliated with such a firm -- recommend one? If you are affiliated with such a firm, and you respond anyway, please explain what you do differently.

I use Netlify for my websites, they're excellent.

Re: We tested popular web hosting companies and all were easily hacked

#32
post #28
post #22

Are the old hosting companies of the past still sharing the same disk with other users? I remember going cd .. and seeing a bunch of folders in /home from other users. If any one of those users used a chmod incorrectly I would be able to access their shit. It is not super likely for most files but well known files can be a problem. Beyond that, trusted CGI-BIN processes could probably be used to get around security c…

Standard containerization technology (e.g. docker) isn’t designed to sandbox untrusted code.

Do tell what is designed to sandbox untrusted code

Re: We tested popular web hosting companies and all were easily hacked

#33
post #28

Earlier quoted context omitted.

Standard containerization technology (e.g. docker) isn’t designed to sandbox untrusted code.

Do tell what is designed to sandbox untrusted code

Xen Hypervisor can do that https://xenproject.org/developers/teams/xen-hypervisor/

Re: We tested popular web hosting companies and all were easily hacked

#34

3 of the 5 companies they tested are really the same company. "Endurance, who runs Bluehost, iPage, and HostGator:"

Can attest, having worked at the Bluehost brand as a tier 2 chat support (before they shut down everything and offshored all support to the Indian CEO's family's Indian call center).

The company is a fucking nightmare. ALL EIG brands should be avoided like the plague including Constant Contact, site5, bluehost, hostgator, fastdomains, justhost, hostmonster, ipage, NetFirms, UnifiedLayer, IpowerWeb, PowWeb, ResellerClub, HostNine, HostCentric, Domain.com, Dotster, Verio, AppMachine, Arvixe...etc...

They have horrible security. Hacked sites were the norm not the exception. The techs we had were decent, but when things started off-shoring the off-shore tech's were complete idiots who couldn't figure out how to add space to a VPS...That was in 2015, I'm sure now it's way worse. I left in 2014/2015 to do development full-time, my wife worked there till they shut down their Orem, UT operations.

We had friends who they actually got to move to AZ to work w/ hostgator during the transition, and then fired 3 months later after they didn't need them anymore and AFTER they'd already bought a house in AZ... real pieces of shit there...

The CEO even said 3 weeks before everyone got the notification they were being canned "Don't worry your jobs are all safe, nobody's getting laid off" ...lmao

Re: We tested popular web hosting companies and all were easily hacked

#35

Earlier quoted context omitted.

I emailed Bluehost, this is the response I got. Hello Joshua, Thank you for reaching out to Bluehost via our press@ email address; as a brief introduction, I am writing you from Endurance International Group, parent company to Bluehost and several other web hosting services. In regards to your questions for how to best protect your website, one of the best things you can do to invest in your business is to acquire we…

"You got hacked because you didn't give us enough money"... these guys should get into the Ransomware business.

As I mentioned in another thread, I used to work for EIG... and 'one does not simply reply to a CSR request without first offering an upsell...' was a meme that was posted quite often.

Re: We tested popular web hosting companies and all were easily hacked

#36
Lots of people seem to have anticipated these results! So, is it OK now that for low-volume static sites I've just thrown everything on S3? How about adding in lambda and SQS for low-volume almost-static sites? Is it still terrible that I've wasted cents per month on these services?

Re: We tested popular web hosting companies and all were easily hacked

#38

3 of the 5 companies they tested are really the same company. "Endurance, who runs Bluehost, iPage, and HostGator:"

Can attest, having worked at the Bluehost brand as a tier 2 chat support (before they shut down everything and offshored all support to the Indian CEO's family's Indian call center). The company is a fucking nightmare. ALL EIG brands should be avoided like the plague including Constant Contact, site5, bluehost, hostgator, fastdomains, justhost, hostmonster, ipage, NetFirms, UnifiedLayer, IpowerWeb, PowWeb, ResellerCl…

Luckily most of those domain names already scream "do not trust this hosting service"

Re: We tested popular web hosting companies and all were easily hacked

#40
post #38

Earlier quoted context omitted.

Can attest, having worked at the Bluehost brand as a tier 2 chat support (before they shut down everything and offshored all support to the Indian CEO's family's Indian call center). The company is a fucking nightmare. ALL EIG brands should be avoided like the plague including Constant Contact, site5, bluehost, hostgator, fastdomains, justhost, hostmonster, ipage, NetFirms, UnifiedLayer, IpowerWeb, PowWeb, ResellerCl…

Luckily most of those domain names already scream "do not trust this hosting service"

Unluckily, in the majority of small and mid-sized businesses, non-technical people like sales and middle managers are responsible for making technical decisions, like picking a hosting provider.

Witness all of the otherwise upright companies that have domains through GoDaddy.

Post reply on HN