Web Host Chat - The UK hosting forum
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Game Servers
Go Back   Web Host Chat > News, Reviews and useful guides > Discuss a hosting company
Reply
 
LinkBack (4) Thread Tools
Old 22nd October 2008   4 links from elsewhere to this Post. Click to view. #1 (permalink)
Found the Computer
 
Join Date: May 2008
Posts: 29
norbie is on a distinguished road
Servage - Awful Security

Here is a support ticket I just submitted on my Servage account:

Quote:
Originally Posted by 2008-10-21 22:19
Customer

Subject: Major Security Issue

Hi,

I just went to open phpmyadmin to look at some data in one of my mysql databases and I was presented with this:

http://img.photobucket.com/albums/v4...phpmyadmin.jpg
http://img.photobucket.com/albums/v4...hpmyadmin2.jpg

As you can see, this gives me full access to other customers' databases.

I am also unable to access my own databases.

Please can you explain why there is a massive security flaw here? I seriously hope that my data is more secure than these other poor sods.
Quote:
Originally Posted by 2008-10-22 00:30
Support - Mark
Hello Andrew,

Thank you for submitting ticket.

Please provide us the exact database name for which you are facing problem. In order to further investigate and assist you in a better way.

Kind Regards
Mark, Support
Servage Hosting
*Sigh*.
Attached Images
File Type: jpg phpmyadmin2.jpg (148.1 KB, 40 views)
File Type: jpg phpmyadmin.jpg (93.2 KB, 33 views)
norbie is offline   Reply With Quote
Old 22nd October 2008   #2 (permalink)
 
Join Date: Aug 2005
Posts: 561
Schumie is on a distinguished road
LOL... out of interest, can you actually see the data in the DB's, or just the database names in the drop down list?

IIRC with phpMyAdmin, this is one of the configurable things to show all databases or not off the top of my head (or it used to be ~5 years ago... a lot has changed since then I know!)
Schumie is offline   Reply With Quote
Old 22nd October 2008   #3 (permalink)
 
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
freethought is on a distinguished road
at least you need to authenticate to get PHPMyAdmin - I just tried the URL to be cheeky but it wouldn't let me in without logging in
Now THAT would be one hell of a security flaw!
__________________
Freethought Internet Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
freethought is online now   Reply With Quote
Old 22nd October 2008   #4 (permalink)
Found the Computer
 
Join Date: May 2008
Posts: 29
norbie is on a distinguished road
Quote:
Originally Posted by Schumie View Post
LOL... out of interest, can you actually see the data in the DB's, or just the database names in the drop down list?

IIRC with phpMyAdmin, this is one of the configurable things to show all databases or not off the top of my head (or it used to be ~5 years ago... a lot has changed since then I know!)
Yes I can see all the data, and change it if I wanted to (See the second screenshot).

This has happened once before - for some reason the authentication allows me to see other people's databases (which of course I shouldn't be able to do).

It's quite annoying really as I can't see my databases (And I wonder who can!)

Quote:
Originally Posted by freethought View Post
at least you need to authenticate to get PHPMyAdmin - I just tried the URL to be cheeky but it wouldn't let me in without logging in
Now THAT would be one hell of a security flaw!
Haha, yes that would be even more amazing.
norbie is offline   Reply With Quote
Old 22nd October 2008   #5 (permalink)
 
Join Date: Jun 2003
Posts: 1,891
JamesSykes is on a distinguished road
Would it be illegal to sign up to servage and wipe everyone's databases?
__________________
Mooharr
E-Mail Hosting Services

These are not my views and i cannot be held accountable for anything he says.
JamesSykes is offline   Reply With Quote
Old 22nd October 2008   #6 (permalink)
 
Join Date: Jun 2003
Posts: 1,891
JamesSykes is on a distinguished road
OH THIS IS PURE COMEDY :

Customer Survey


"At this exact moment we host 179994 websites."
__________________
Mooharr
E-Mail Hosting Services

These are not my views and i cannot be held accountable for anything he says.
JamesSykes is offline   Reply With Quote
Old 22nd October 2008   #7 (permalink)
Platinum Bad Boy
 
[inx]Olly's Avatar
 
Join Date: Dec 2003
Location: Formally the dc floor, now an office near you
Age: 27
Posts: 3,098
[inx]Olly is on a distinguished road
I might be wrong, but that kind of reply tends to be from an Indian / outsourced support person.

If it's not, and it was one of my staff, I'd be firing a rocket up their arse!!
__________________
Oliver Warburton
Managing Director, INX-Network Ltd.
The UK's leading GSP :)
Company # 05100055. VAT # 875 6215 00.
INX-Gaming - (url-removed: need 20 posts). Europe's fastest growing CSS, CZERO, CS gaming league
These are not the views of a company director. These are strictly my personal views.
[inx]Olly is offline   Reply With Quote
Old 22nd October 2008   #8 (permalink)
 
Join Date: Jan 2008
Posts: 637
FH - Tim is on a distinguished road
Indeed they haven't actually read the guys ticket, there do seem to be a fair few issues with servage on this sort of thing, I am sure I read some threads about it on wht.
__________________
Tim -Fly High Ltd - UK Shared Hosting - Private Label Resellers - Managed & Self managed Dedicated Servers
█ Custom Nameservers - Domain Resellers - WHMCS - UK Servers
Follow me on twitter even get exclusive specials/sales !

All views expressed in my posts are my own and not those of Fly High Ltd
Company # 05967991
FH - Tim is online now   Reply With Quote
Old 22nd October 2008   #9 (permalink)
 
Join Date: Mar 2008
Posts: 227
ThomasC is on a distinguished road
Quote:
Originally Posted by JamesSykes View Post
"At this exact moment we host 179994 websites."
I also noticed that but I found it more interesting to read all about "ServageOS"
ThomasC is offline   Reply With Quote
Old 22nd October 2008   #10 (permalink)
 
BurtyB's Avatar
 
Join Date: Apr 2004
Location: Newark, UK
Posts: 864
BurtyB is an unknown quantity at this point
Quote:
Originally Posted by JamesSykes View Post
"At this exact moment we host 179994 websites."
I guess that's about right looking at the domains they have on their DNS servers.

ChrisB.
__________________
Chris Burton Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
* OthelloHosts.net Linux and Windows High-Availability Professional Email / Web / Secure Hosting
* OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
Views expressed in this post are my own and not Othello Technology Systems Ltd.
BurtyB is offline   Reply With Quote
Old 22nd October 2008   #11 (permalink)
 
JamieBeeston's Avatar
 
Join Date: Aug 2005
Posts: 4,192
JamieBeeston is on a distinguished road
DNS serve != Host
__________________
Register1.net
.eu £7.95
.com .net .org .uk £5.48
Premium UK Virtual Hosting from £16 a year
Quad Core 2.83Ghz 1GB 2TB 250GB Xeon Servers from £49
Company reg: 04186664 VAT reg: GB 815 5899 88
[Any views expressed on this forum are my own, and may not represent the views of any organisation that I own or am connected with.]
JamieBeeston is online now   Reply With Quote
Old 22nd October 2008   #12 (permalink)
The lights are on
 
Join Date: May 2008
Posts: 60
ms2134 is on a distinguished road
Quote:
Originally Posted by JamesSykes View Post
Would it be illegal to sign up to servage and wipe everyone's databases?

, The screen shot's ... !!! DAMM!..

It is yet another issue that has been brought to attention. I wonder what other issues they may have at their end...

As with, what i have quoted...

It may be illegal, but sure would be funny to make a complete backup, then clear them all and go to Severage, and ask them if they would like to purchase them back or go to the Media and show them up...

~ Mike
__________________
Corporate Internet Solutions
Registered reseller for Liquidnet (Registration No. 4654498)
ms2134 is offline   Reply With Quote
Old 23rd October 2008   #13 (permalink)
Found the Computer
 
Join Date: May 2008
Posts: 29
norbie is on a distinguished road
Quote:
Originally Posted by 2008-10-23 12:09
Customer
Did you even read my ticket?

Did you see the subject which read - MAJOR SECURITY ISSUE?

You are an extremely disappointing host. I cannot believe how bad you have become.
Quote:
Originally Posted by 2008-10-23 12:14
Support - John
Hello Andrew,

I have checked access to the databases' phpMyAdmin from your control panel by could not replicate the issue as shown in the jpg file.

Suggest you clear your browser's cache and check again.

Thanks.

Kind Regards
John, Support
Servage Hosting
The problem appears to be fixed now, but it will happen again as they didn't actually resolve anything - it resolved itself.

They just don't seem to understand how serious it was. Imagine if it was an e-commerce site database or something.
norbie is offline   Reply With Quote
Old 23rd October 2008   #14 (permalink)
Found the Computer
 
Join Date: May 2008
Posts: 29
norbie is on a distinguished road
Ignore that. I get another database server with full access to someone else's database now.
Attached Images
File Type: jpg phpmyadmin3.jpg (75.0 KB, 19 views)
File Type: jpg phpmyadmin4.jpg (182.7 KB, 25 views)
norbie is offline   Reply With Quote
Old 23rd October 2008   #15 (permalink)
 
AdamC's Avatar
 
Join Date: Jun 2005
Location: Dorset, UK
Age: 22
Posts: 1,003
AdamC is on a distinguished road
I hope you already in the process of moving hosts then. I'd suggest the requests forum on here is the best place to start if you haven't already.
__________________
Adam Cooke
aTech Media - UK Ruby on Rails development specialists
Radar -A Xen virtual machine deployment & management engine
Codebase - a full source control hosting solution

Company Registration Number: 5523199 VAT Registration Number: GB 868 861 560
All views expressed in my posts are my own and not those of aTech Media Limited.
AdamC is offline   Reply With Quote
Reply


LinkBacks (?)
LinkBack to this Thread: http://www.webhostchat.co.uk/discuss-hosting-company/14757-servage-awful-security.html
Posted By For Type Date
The Webshite is broken because Servage.net are a bunch of useless cunts. This thread Refback 25th December 2008 07:08 PM
The Webshite is broken because Servage.net are a bunch of useless cunts. This thread Refback 19th December 2008 09:35 AM
The Webshite is broken because Servage.net are a bunch of useless cunts. This thread Refback 1st December 2008 07:31 PM
Servage - Awful Security | Weird Hosting This thread Refback 29th November 2008 12:22 PM

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
What server security do you have and run bwbd Dedicated Servers, VPS and Colocation 27 13th September 2006 01:48 PM
[NEWS] Info Security Product Guide Selects Comodo For 2006 ?Hot Company ... - Help Net Security [NEWS] Hosting and Tech News 0 2nd February 2006 12:06 AM
Servage cah Discuss a hosting company 6 17th January 2006 07:07 PM
Servage cah Internet Service Providers 1 17th January 2006 03:24 PM
Awful jokes and puns ... othellotech General Chit Chat & Discussion 0 28th December 2002 12:57 AM

User Information
»REGISTER NOW!
Discuss a hosting company Want to find out peoples opinions and experiences of a hosting company.


Quick forum search
 

Special Hosting Offers

Hot Stuff


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0