We’re Back~!

It’s not a nice feeling to know that someone has access to your server. Unfortunately this is something with which Clare and I have been contending for the last few weeks.

If something is too good to be true … it probably is.


It’s not merely that I created this site for Clare; I had to find somewhere for it to live too.

Not being particularly well versed in hosting I had recourse to my friend, your friend, all of our friends:

Google logo

Before too long I’d stumbled across a company called 3iX. I couldn’t resist it; how could anyone? It offered us 20GB of storage, unlimited bandwidth, and the ability to host three sites there for the piddling sum of £1.77 per month. “Where’s the catch?”

We found out in early February that Clare’s work PC had contracted a virus from my site. Well colour me shocked! A Google search of the virus name showed that several other sites had caught the same bug … and all were hosted on 3iX.

I got in touch with their live support to discuss the issue. Rather than do anything about it, the jabroni on the end refused to help unless I had a ticket … not that the hard-of-thinking klutz would tell me what that meant or whence I might obtain one.

I eventually found out what to do and submitted the complaint. Later that day I received the following message from them:

Hello,

We have removed unwanted code from your index pages and now your site is working fine. Please check it and confirm.

Please feel free to contact us back in case of any other information.

Regards,

Simon
Host-Care Support Team.

That was jolly nice of them, especially their kind offer of inviting me to contact them. Not being terribly impressed that my supposedly secure account had had malicious code inserted I took them up on that offer. In particular, I asked them what they might do to ensure that this didn’t happen again.

I received an answer the next day. Apparently the secret to not having my account hacked by someone who breaks into their main server and thus gains access to sites hosted on it is to … change my password. Change my password. The sender of the e-mail was nice enough to paste a patronising mail about how to choose a strong password. Heaven forfend my brain be so shrivelled that I not know that opensesame is not as good as xp0Fr~~hT¬¦.

The brain train left the station without that particular employee, I fear.

Not long after my AVG pops up whilst I’m looking at Clare’s site.

Threat Detected!

In spite of the fact that I had changed the password, Clare’s site had now been infected.

I went into the files and deleted the malicious code and changed passwords again. Two hours later the index files once more featured the bad code.

Pissed off, I responded to the person who sent me the mail about how I needed to change my password to prevent this from happening again.

Thanks, but if I’d wanted a patronising note on how to choose a password, that’s what I’d have requested.

What I asked you was:

WHAT ACTIONS ARE YOU GOING TO TAKE TO ENSURE THAT THIS DOESN’T HAPPEN AGAIN? Don’t you dare attribute the blame to me for the fact that someone somewhere has got their hands on 3iX passwords. (Mine wasn’t the only site housed on 3iX that reported this on that day.)

If you are unable to answer the question yourself THEN DON’T FOB ME OFF WITH STUPID TALK ABOUT HOW TO CHOOSE A PASSWORD; put me in touch with someone who can answer my question instead.

My second question was to ask why I can’t have secure FTP. How do you, in 2008, justify the use of regular FTP?

Third point, and very important: My girlfriend’s site is on the same server, and now hers has become infected too. My site is also now infected with the same code again on the index.php file. This is true even though I changed the password.

Tell me how you propose to deal with this issue before I cease custom with you, get hosted elsewhere, and write a series of posts explaining to readers why I moved.

I expect relevant answers, so think before you respond. You are *this* close to losing a customer.

I never got a response.

A few hours later the virus had returned. I fired off another mail to 3iX:

I’ve already discussed this with you once. The former ticket was PKF-173548.

My site has been hacked and a malicious line of code placed on the index page. No-one else knows my password. If you look at my previous ticket, you’ll see that I researched the name of the virus and found a help thread in the Wordpress forums where people said it was a 3ix issue.

The code is back, even though I have changed the password. It seems that there must be something extra that rewrites the bad code after I delete it.

So: I want this problem fixed. I also want answers about how and why this is happening. I want to know why I cannot have secure ftp.

Fix this issue. After that, fix the same thing on my other site http://meddysong.com/ which is hosted on the same server.

I am very, very unhappy about this. The frontpage of your website reads “satisfaction guaranteed”. I am far from satisfied so far. I expect this issue resolved with an explanation about why my password (and others on 3ix) fell into the hands of these hackers.

I expect an answer to all of my questions. If you can’t provide one, put me in touch with someone who can.

I actually received an answer to this one:

Hello,

We have removed unwanted code from your index pages and now your site is working fine. Please check it and confirm.

Please feel free to contact us back in case of any other information.

Regards,

Simon
Host-Care Support Team.

Anything about that seem familiar? Scroll above; it’s the exact same response that I received the first time. That’s right; 3iX either

  1. sends you an incorrect response blaming you for their server getting hacked, since you’re obviously too stupid to think of a strong password, even this has no bearing on the fact that they were hacked, not you
  2. ignores you altogether
  3. pastes a default response because they have so much disdain for their customers that they can’t be bothered to answer questions that are put to them.

Not far off needing a megadosage of tablets to lower my blood pressure I replied:

Did you even pay the slightest attention to what I wrote? I am quite capable of removing the unwanted code myself, thanks. I want to know why I can’t have secure ftp and to whom I can complain, seeing as it’s *your* fault not mine that my site was hacked.

I suppose that you’ll ignore this message too like you’ve done my previous ones, you fucking retards.

With that, I went off to their live support:

Chat24×7: Welcome to 3iX live chat, my name is Susan, please hold for a moment, I am reviewing your question.

Chat24×7: may i know what is the issue ?

Tim Owen: Certainly.

Tim Owen: My sites (I have two on the same server)

Tim Owen: were hacked.

Tim Owen: It was the case that several 3ix passwords

Tim Owen: were obtained by a Serbian IP.

Tim Owen: The support people have removed the code

Tim Owen: but it keeps coming back, even though I’ve changed the password.

Tim Owen: So I am very, very angry.

Tim Owen: I want to know why I can’t have secure ftp

Tim Owen: and what you intend to do about this.

Tim Owen: Every time I’ve mentioned it to the support team

Tim Owen: they either ignore it

Tim Owen: of paste me a patronising mail

Tim Owen: about how to choose a good password,

Tim Owen: conveniently ignoring that it doesn’t matter how good the password is

Tim Owen: if some Serbian IP can actually see them.

Tim Owen: So, I want an apology, I want secure ftp

Tim Owen: and if I can’t have them, then I want a refund and to terminate my contract.

What is the response to this, you ask. Not what one would have expected:

Chat24×7: Network speed and technology

Chat24×7: http://www.3ix.org/data_center.php

Fortunately the respondent recovered:

Chat24×7: What is your domain/site name?

Tim Owen: http://radioclare.com

Chat24×7: Please hold for a moment

Tim Owen: and http://meddysong.com

Chat24×7: we provide secure ftp only with expert and extreme hosting packages

Chat24×7: and you are hosted with Extra hosting package

Tim Owen: oh … so you want more money to give me a service where I’m protected from hackers?

Tim Owen: You know how it says “satisfaction guaranteed” on your front page?

Tim Owen: That’s not exactly accurate.

Tim Owen: I’d suggest putting “if you take us up on our cheaper packages, we’ll allow your password to fall into the hands of hackers, and we won’t apologise or offer you standard protection like secure ftp”. That would be far more accurate.

Tim Owen: So, seeing as I can’t get an apology or protection, how about you give me a refund

Tim Owen: so that I can go to a service that actually cares about the security of their customers?

Chat24×7: To cancel your account please send an email to billing@3ix.org with the subject ‘MONEY BACK GUARANTEE – domain.com’ (specify your site name), use your registered email address to send the request and advise your cpanel username and password as verification. The cancellation and refund will be made within 48 hours.

Tim Owen: And that will be authorised?

Tim Owen: It’s just that your support people have done a wonderful job of avoiding issues like this, so I’m understandably dubious.
Chat24×7: if it is under 30 days money back guarantee than it will be authorised

Tim Owen: It’s not under 30 days

Tim Owen: Sorry, I don’t get hacked to order

Tim Owen: Maybe you’d be nice enough to let hackers see people’s passwords within the 30 days next time then.

Chat24×7: then you cannot get a refund

Tim Owen: Right

Tim Owen: So, about this “satisfaction guaranteed” thing: Can we at least both agree that that is a lie?

Chat24×7: if you want we can reset your account

Chat24×7: you can upload your data and change the password

Tim Owen: But what good is that if my account can be hacked?!

Chat24×7: if you keep changing your password frequently then this can be avoided

Tim Owen: You’re completely skirting around the issue! If things were secure

Tim Owen: I wouldn’t have to change my password at all!

Tim Owen: You people are ridiculous at putting the blame for your security lapses on to the shoulders of your customers.

Tim Owen: It’s nothing to do with me

Tim Owen: that some Serbian IP could see 3ix passwords!

Tim Owen: The responsibility for security lies at YOUR feet in this case, not mine.

I pause for five quiet minutes.

Tim Owen: So … You’ve gone quite

Tim Owen: What do I get? Refund or secure ftp?

Tim Owen: I’ve ruled out the potential of an apology; you staff seem particularly averse to acknowledging that it’s not my fault that you provide an unsecure service

Tim Owen: and will only give me something that can’t be hacked if I pay you some more money.

Tim Owen: I’m unsure whether one would label that ‘ransom’ or ‘blackmail’, but it’s not a good thing, that’s for sure.

Chat24×7: wait am enabling ssh for secure ftp connection

Chat24×7: you can now ssh with hostname as your domain name , port 3131 and cpanel username and password

Tim Owen: Thank you.

Chat24×7: Is there anything else I can help you with?

Tim Owen: No, everything is fine.

Tim Owen: Thanks you, you’ve been much more help than the people

Tim Owen: at the support group.

Unfortunately Secure FTP didn’t help, since the hackers had left in a backdoor or script to replicate the malicious code in the event that I deleted it.

In the meantime they mustn’t have appreciated my earlier line of “I suppose that you’ll ignore this message too like you’ve done my previous ones, you fucking retards”, since they sent me the following e-mail: (Right-click > View Image to see full-scale image.)

We’re looking into it

And not a few minutes later I receive their answer:

We’ve removed the unwanted code …

Yes … the same generic answer as every other fucking time!

That was it. I set about finding another host. In my rush I transferred the domain radioclare.com to other nameservers without first downloading the content that was on 3iX. Because of this, I couldn’t log back in to their hosting area. Feel my pain as I endured a conversation with 3iX’s support over 30 miserable minutes that brought a new low to the definition ‘customer disservice’:

Live-Chat: Welcome to 3iX live chat, my name is Mike, please hold for a moment, I am reviewing your question.

Live-Chat: Before the DNS has propagated you can view your site using http://serverip/~username and for cPanel you can use http://serverIP:2082

Tim Owen: It’s not allowing me to log in.

Tim Owen: My name and password were stored automatically as a cookie, so I know it’s not a mistake with the typing.

Tim Owen: So … any chance of an a response here? I need access to my hosting area. i awesome that the DNS hasn’t propogated so quickly. And if it has, could I not have direct access to my hosting area?

Tim Owen: *i assume

Tim Owen: hello?

Tim Owen: any chance of some acknowledgment?

Tim Owen: OK, you’re not paying any attentiont

Tim Owen: i’ll get the site redirected to 3iX again and

Tim Owen: retrieve the database that I need.

Tim Owen: Thanks for being so kind as to ignore me for the last 20 minutes …

Tim Owen: This is the point where you could offer me the nameservers that I’ll need to redirect to …

Tim Owen: Jesus. Is there *any* chance of acknowledgment at all?

Tim Owen: Look! Just tell me what your nameservers are, so that I can get redirected back to this site.

Tim Owen: Hold the front page: “3iX in awful service shock!”

Tim Owen: Right, I’m out of here.

Tim Owen: Thanks for nothing. Fingers crossed you’ll get fired

And that was that. Stick a fork in them, 3iX are done.

Clare and I are now hosted on A Small Orange. So far everything is perfect.

If you’ve made it this far, congratulations. Your reward is a free piece of advice: Don’t Use 3iX: They’re Fucking Shit.

Tags: , ,

6 Responses to “We’re Back~!”

  1. Radio Says:

    Oi, who said you could post on my blog :P

    Nah, it was appalling service and I’m impressed that you managed to deal with those people without exploding! Thank you very much for all your efforts to get my site back up and running again :)

    xxx

  2. Babel Says:

    Update: We’re still with A Small Orange, who continue to provide their service perfectly :)

  3. Paul Says:

    I also feel 3ix are bordering on criminals… I paid for hosting and registered a domain with them (not the one I’m using now) needless to say the whole thing was such a disaster! I could not even gain control of the domain name after I decided to dump them so I just let the whole thing lapse. I even resisted telling them what I thought of them when they had the hide to send me a renewal notice. YOU HAVE ALL BEEN WARNED… NEVER EVER USE 3ix

  4. Chris Says:

    Biggest bunch of fucking wankers ever. Avoid at all costs.

  5. zambrean Says:

    well.. 2 days ago when i was try to enter in my site i was see this:

    Forbidden You don’t have permission to access / on this server. And
    oher words more.. Something about apache.. i don`t remember what…
    port 80.. etc..

    I was go and connect my self on 3ix chat and I was speak with the Agent. She was doing i don`t know what and i was able to see this.

    http://800pixeli.wordpress.com/files/2009/09/xxxed1.jpg
    I was tell to the Agent that where i was put “Here must be the picture”, is missing the picture.

    She was left me alone. She was close the chat. I was connect again. Another Agent. Tell him again all the story.

    Later, I was connect with my FTP on my site and i was see that inside
    of public_html is missing the folder called “images”. I was understand
    that someone, was deleted all my pictures. Thats why the site shows
    just thumbnails pictures, and the 900 pixeli picture, not. So, I was
    go again to the 3ix live chat, and this time I was speak with “Eric”.
    She was restored my site i guess and everything was fine.

    But with the FTP i was go inside of this folder images. I was see that
    inside i have a new one, called CityBanckOfAmerica.com.
    I was tell this to Eric. Because never in my life i was uploaded this
    folder in my site. It was not mine!!! Someone was put this inside of
    my public_html. Maybe, the same person was changed my database 2 weeks
    ago. I don`t know. Because I don`t understand how this thinks are
    working.

    Eric was deleted this folder and she was see that the folder from
    public_htrml, called “images” haves chmod 777 permission activate. And
    she was explain me that I don`t need to make this folder writable!
    Eric was change the permission to 0755 for images and thumbnails
    directory. Maybe this is the way used by the “strange person” to put
    inside of this folder, another one called CityBanckOfAmerica.com.

    On this afternoon (18.09.2009) I connect myself in to admin.
    http://www.zambrean.com/admin/ and on General Info i was read this:

    http://800pixeli.wordpress.com/files/2009/09/zambrean-com_error.jpg

    So, if the Image Directory is not writable, i`m not able to upload any images. If I make 777, someone is try to.. hack me? i guess that City Banck Of
    America is a Bank, no? What was doind this “site” inside of my site?
    And who was make my site “Forbidden You don’t have permission to
    access / on this server”. ???

    Finaly, today 19.09.2009, after one year, 3ix was reset my account losing all my work. I was begining install again the Pixelpost. But after some minutes i was see this:

    http://800pixeli.wordpress.com/files/2009/09/shit.jpg

    I was connect again to ask if they can give me the word, that if i will instal again all, i will not loose again everithing.

    And this is what was happening: Is a copy – paste from the chat:

    All operators are currently assisting others. Thanks for your patience. An operator will be with you shortly.

    Chat InformationYou are now connected.

    24×7Live: Welcome to 3iX live chat, my name is James, please hold for a moment, I am reviewing your question.

    24×7Live: Welcome to 3iX live chat, my name is Susan, please hold for a moment, I am reviewing your question.

    Me cambia cada dos por tres de Agent. Asi que siempre tengo que empezar de nuevo y decir que es lo que quiero. Y como no es en español.. pues cuesta.

    zambrean: hello

    zambrean: i read on internet that 3ix is

    zambrean: 3ix is the worst hosting company I ever used. They kept disconnecting my sites because of ‘high server load’ and they did nothing to isolate the cause. They just kept on suspending my account, and when I asked about their explanation, they just said ‘your site is causing high server load’. I asked them to fix and apparently, after a week of series of chat support to them, they can’t fix their own freaking server.

    zambrean: is that true?

    24×7Live: Ok

    24×7Live: We are terminating your hosting account from server

    24×7Live: You can host it elsewhere

    ……………………………..

    Nothing more.

    What to do?

  6. Babel Says:

    ¿Qué si puede hacer? Siempre es lo mismo con 3iX. Lo siento, que te hagan así.

    I’m glad that you’re not with them anymore. They’re absolutely terrible!

Leave a Reply