Site5 - Built For Designers & Developers MENU

Site5 Community Forums


Go Back   Site5 Web Hosting Forums > Site5 Official Forums > Emergency Service Notices

Emergency Service Notices Service-impacting information direct from Site5 staff.

Closed Thread
 
Thread Tools Rate Thread Display Modes
  #1  
Old July 6th, 2009, 07:08 PM
Beau Henderson's Avatar
Beau Henderson Beau Henderson is offline
Site5 Staff
 
Join Date: Jun 2005
Posts: 3,723
[Completed] SSH Disabled On All Servers Due To Possible Exploit

We are temporarily disabling access to SSH on all Site5 servers due to information we have received detailing a possible security exploit. We will update this thread with more info as it develops. We are doing this as a precaution and waiting for more information before we restore access for customers.

We sincerely apologize for any inconvenience this may cause but we do feel this action is in the best interest of all customers.

Thank you.

Last edited by Ben Welch-Bolen; July 10th, 2009 at 04:47 PM.
  #2  
Old July 7th, 2009, 03:27 PM
Ben Welch-Bolen's Avatar
Ben Welch-Bolen Ben Welch-Bolen is offline
Site5 CEO
 
Join Date: Oct 2008
Posts: 2,867
SSH is still disabled for customers, we will be posting another update in the morning to update everyone where we are at.

Update:

Also just to elaborate on why we are doing this. There is a possible exploit that would allow someone to gain complete control of a server through a vulnerability in OpenSSH. If someone were successful in doing this, they would have FULL control over the server: read your email, delete all data on the server, and so on. There is not currently a patch for this exploit which is why we are waiting word from security organizations and the creators of OpenSSH before we proceed to open SSH back up to customers. It could be this is not a real exploit but from all indications we think there is a good chance it exists. We feel that 48 hours with SSH turned off is better than customer's sites being deleted and the time it takes to restore those back from off site backups.

Please let us know if you have any questions, support is available 24/7 as always.

Thanks, Ben
__________________
Ben Welch-bolen
Site5 CEO
bwb@site5.com

Last edited by Ben Welch-Bolen; July 7th, 2009 at 04:08 PM.
  #3  
Old July 8th, 2009, 01:30 PM
Ben Welch-Bolen's Avatar
Ben Welch-Bolen Ben Welch-Bolen is offline
Site5 CEO
 
Join Date: Oct 2008
Posts: 2,867
SSH will be re-enabled shortly, we are currently applying some additional security measures and patches. We will post again when it is back up. We should be finished in the next two to three hours.

Thank you for being so patient and working with us on this one!
Thanks, Ben
__________________
Ben Welch-bolen
Site5 CEO
bwb@site5.com
  #4  
Old July 8th, 2009, 02:54 PM
Ben Welch-Bolen's Avatar
Ben Welch-Bolen Ben Welch-Bolen is offline
Site5 CEO
 
Join Date: Oct 2008
Posts: 2,867
We will post an update later this afternoon as we progress further, we are 60% done with some changes and then we will be turning SSH back on for clients.

Thanks, Ben
__________________
Ben Welch-bolen
Site5 CEO
bwb@site5.com
  #5  
Old July 8th, 2009, 04:51 PM
Graham McMillan's Avatar
Graham McMillan Graham McMillan is offline
Chief Technology Officer
 
Join Date: Mar 2007
Posts: 1,448
We have finished deploying updates to OpenSSH and we are now doing some testing to make sure everything is working properly. Once this testing is complete we will re-enable SSH for all users.
__________________
Graham McMillan
Chief Technology Officer
Site5.com
Closed Thread

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Forum Jump


All times are GMT -5. The time now is 03:55 PM.
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.