I'm an owner and manager of a server running about a year ago, and everything was fine till three months ago.
Many VBulletin forums hacked from one hacer.
i hired a technical to re-setup security of the server
upgrading for ( OS , php , apache ) done. and other setting...
after that he said every thing is ok now.
3 weeks later , hack back again from another hacker on 3 VBulletin forums
put in your concideration all hacked forums are secured enough and using 3.6.8 patch level 2.
what possible reasons assist the hacker to reach config file?
is this a gab from the server or VB version?
OS : Fedore 5 .. upgraded from Fedora 4
php Version : 5.2.4
Apache Version : 1.3.39
PERL version 5.8.8
I recently ran into an easy with my host where there server crashed and left us in the cold for days without knowing what the problem was or when the site would be up again. Further more, the admin controls went from Plesk to something they created themselves where you actually canīt do anything with.
As a logic result of this, I want to switch hosting as fast possible.
My question is, can I easily switch from one host to another even if we already payed for hosting untill august next year? Or there any issues involved with switching host, like with domain names,...?
I run a small vb forum that is quickly expanding beyond the shared hosting plan we currently have with GoDaddy. So far we have been looking at VPS as a solution that would allow us to grow as we grow.
I hope I'm allowed to ask this, but I am looking for examples of vb forums that have about 100 concurrently logged in members and examples of vb forums with 200 members concurrently logged in and are running on either KnownHost or WiredTree (or an alternative service).
Please provide a link to your forum, the name of the host, and the VPS package you currently have. Finally, please let me know if you are utilizing Litespeed.
I'm hoping this will become a great resource for growing community owners looking to take the next step.
Over the past 4 years I have had 5 different hosting companies. I run a small forum (400 to 1k page vies per day) and is a nuke forum. It usually runs flawlessly on the new host for 7 to 9 months and then the db bogs down and I switch to a new host and install the complete db again to the days postings and it runs gr8 yet again.
Im no expert but Im no newb either. I have worked for 2 hosting companies (Hostgator & Applied Innovations) and I have my Bachelors in IT. I know enough to be dangerous! Is there anyone who can tell me if there is a host that I can put my little forums on that doesnt charge an arm and a leg and is reliable enough to stay with.
I have seen all the reviews all over the place, but from working at hostgator I know they have their level 2 support people logging in to these types of forums as different people and posting great reviews every day, I dont think they have stopped doing that.
Is there any one who has been with their hosting co for years and have a site like mine that can say that they recommend it?
Alot of VB forums have hacking every day In fact All hackers couldn't hack databases or files
They only edit one template in style like header or forumhome So Uploading style again resolve the problem But How can I disallow them to to edit templates
I am running Apache 2.2 on CentOS. I really want to install mod_security to lock things down. But I saw where there were some issues with mod_security and forums. I plan on having a forum live on my site shortly. I found this bit of info:
If you install mod security on the server, some forums will not work properly as this will compare each pattern which is posted against the rule set and will block it if found matching.
Is anyone using mod_security with a forum currently?
I want to know that my main site smsbucket.com and smsbucket.com/forums are both hosted on same server.
But in future when my forum will grow I will need to switch host because my current hosting provider doesn't provide big disk space so in future can I just host /forums on different server? and keep smsbucket.com on my current server?
some of my user , have problem by sending activate email , from their forums and sites such as Vbulletin and phpnuke
this issue happen since i checked (Prevent the user "nobody" from sending out mail to remote addresses) box in Tweak setting , for preventing Spammers.
Suexec was enabled in my server , but i dont enable PhpSuexec in apache build .
-----Original Message----- From: Mail Delivery System [mailto:Mailer-Daemon@swh1.sellwebhost.com] Sent: December 29, 2007 6:05 AM To: nobody@swh1.sellwebhost.com Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed:
alakeneex@mail.ru SMTP error from remote mail server after RCPT TO:<alakeneex@mail.ru>: host mxs.mail.ru [194.67.23.20]: 550 Access from ip address 72.55.156.210 blocked. Visit http://win.mail.ru/cgi-bin/support_bl?ip=72.55.156.210
------ This is a copy of the message, including all the headers. ------
Return-path: <nobody@swh1.sellwebhost.com> Received: from nobody by swh1.sellwebhost.com with local (Exim 4.68) (envelope-from <nobody@swh1.sellwebhost.com>) id 1J8ZV7-0001oN-QQ for alakeneex@mail.ru; Sat, 29 Dec 2007 06:05:09 -0500 To: alakeneex@mail.ru Subject: Welcome to hidden.com Forums Reply-to: jim@hidden.com From: jim@hidden.com Message-ID: <4448804740c38716c8c65ef3203108b3@hidden.com> MIME-Version: 1.0 Content-type: text/plain; charset=iso-8859-1 Content-transfer-encoding: 8bit Date: Sat, 29 Dec 2007 06:05:09 -0500 X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: PHP X-MimeOLE: Produced By phpBB2
Welcome to hidden.com Forums
Please keep this email for your records. Your account information is as follows:
Please do not forget your password as it has been encrypted in our database and we cannot retrieve it for you. However, should you forget your password you can request a new one which will be activated in the same way as this account.
This is only one exemple from one forum but many of our users use forums as well and we receive dozens of similar mails.. Is there a way to stop this or to make the mail rebound to the user instead to nobody?
Staminus Communications has been hosting a botnet forum, which distributes bots, worms, trojans, illegal clickers, and tons more, 95% of the site is illegal, and is forbidden by Staminus's provider yet they could care less as long as they get there money, I sent an abuse letter August 17th 2009, they even admitted things were illegal on the site, I pointed out several like the Google Adsense clicker bot which is highly illegal and which is nothing close to the other content hosted and/or linked to.
They are hosting unkn0wn.ws they refuse to remove the site or make them remove the illegal content which is most of the forum, which now forces me to send a letter to there provider and the cybercrime which I am now doing.
Now I guess they do not care about what they host, only if the person pays, so I guess I'm just going to expose it here for everyone to notice, because it's just going to get there data center raided over time by hosting illegal content and not removing it.
Let's see what you guys think, or what the admins have to say when they read this post.
What do you guys think when a provider does nothing about illegal content do you think it's the employee's that are at fault or the customer?
I have spent several hours on this forum over the past few days doing some research and have officially confused myself. I am a volunteer with a nonprofit organization and our online forums (running on vbulletin) are maxing out the database SQL connections several times per day. The host has a max_user_connections limit of 15 but doesn't have an intermediary step from shared hosting to dedicated hosting. Dedicated hosting is cost-prohibitive and the rest of our site has more than enough room to grow on our current hosting plan (including traffic bandwidth, disk space, etc).
We are planning to register a new domain name for the forums and move them off to another hosting provider. I donate the hosting fees to the organization and I don't have much of a budget to work with ($20/mo or so ideally). I am looking for recommendations for a hosting provider that will support a somewhat busy forum (usually only between 30-50 users online at once but anywhere between 1,000 and 2,500 pageviews per day) and also allow a stepped growth plan (instead of from shared straight to dedicated.)
I've seen Hawk Host, Siteground and URLJet mentioned frequently on posts here and over at vBulletin but I don't want to just jump into a new host and face a similar problem in the future.
Email on server working fine, I can send mails from webmaster@xxx.com to any email only forums like VB don't send emails to hotmail & yahoo ! but emails from forums arrive to emails like webmaster@xxx.com
I'll second what is said about Lunarpages. They are an absmal McHost whose priority is to lure in as many customers as possible without bothering about the quality of their service. I challenge anybody to ring their telephone support line and see if somebody picks it up. I have tried to call ten times in the last six months and never been able to get through once, despite hanging on for ages.
Just today my entire website was down because Lunarpages moved it to a new server (without asking me) and screwed up. The website, Azam.biz has over 17,000 references to it in Google and is critical to my business. I sat drowing in sweat for hours. I couldn't get hold of anybody at Lunarpages by telephone or live chat and the one support response I received ws addressing an unrelated issue.
Worse thing of the lot is Lunarpages censors criticism them on their forums more so than any webhost I have ever know. Every time I post a comment about downtime or not being able to get hold of anybody on the telephone, they delete the post saying it is "incorrect". I have never met a company with such a Stalinesque censorship policy.
I have feared posting anything negative about Lunarpages on other forums because I've been worried about them closing down my account. But, after having suffered so much stress because of them today, I don't care any more.
I am going to back up by entire site now, because I'm worried they will close down my account after reading this. They are not the type of company to take on board criticism and use it to improve their offerings; their obsession is to stifle any criticism.
I am now suffering pain in my heart for the first time in my life because of how badly Lunarpages have treated me today. Their arrogance shows no bounds - they are smug, full of hype and don't give a damn about ruining customers' businesses.
i run a vbuletin forum, right now i am on a virtual dedicated
All my ips are stored on the same root ip, i am moving one of my forums from the default IP to a separate IP. I populated the DNS and my webite shows up properly on the new IP, but my forum is comming up as a database error.
Does anyone know what I can do to fix the problem? Or tools I can run? Or is it merely not connecting to the database yet, because of some name server or other issue?
My site has outgrown my current host and I'm strongly leaning towards a vps. I am relatively inexperienced with web hosting as for the last 18 months I've had very few issues with my current host (Stream101.com). They are currently saying my site is very memory and processor intensive which is why I'm going to have to leave them soon(I can't pay the dedicated server prices that would give my site the stability I desire).
About my site:
My site has 18,000+ users, its about 18 months old. 5,632 threads, 78,967 posts. It used about 150gig of bandwidth last month. The site is growing quickly (IMO). The site makes some money, but not enough to justify spending what it would cost for a dedicated server.
I'm happy to provide any other information, but what I am looking for is suggestions on:
1) Is a VPS the right choice for my site in your opinion.
2) What hosting company's would you suggest I look into.
3) How much ram/processor speed should I be looking for
4) any other information you feel I should know about this.
I am going to soon be upgrading to the latest version of vBulletin (3.7.0). They are recommending PHP 5.25 with APC installed. I am talled that Zend (which I have installed and eaccelerator) is not compatible with APC.
The vBulletin people say that APC will perform better than Zend, and that zend should be disabled and APC installed and enabled.
A couple questions.
1. I'm curious what people's opinions are on here about APC vs. Zend (eaccellerator) or possibly xcache.
2. I have once been told that APC and xcache aren't compatible with Cpanel/WHM. Is this correct?
3. Assuming 2 isn't correct, if I decide to move to APC, what do I need to do to disable/uninstall Zend/Eaccellerator and install/setup APC?
I have the max vars and all that set right to conform to vbulletin, Only problem is now I keep getting this in /var/log/messages
suhosin[8569]: ALERT - script tried to increase memory_limit to 4294967295 bytes which is above the allowed value (attacker '*******', file '/home/user/public_html/includes/class_xml.php', line 35)
The line its pertaining to is @ini_set('memory_limit', -1);
I'm pretty sure its not blocking anything, least nothing I see but it does this everytime someone accesses certain pages on a forum.
My memory_limit for php is 60 mb, I checked out different ways of configuring it, but the only thing I think would stop the alerts is setting the suhosin memory limit to 4 gb, as it says the script is calling for that. But I suppose if there was a crappy or malicious php script they would easily be able to ini-set and suck all the memory.
So basically what i want to do is just disable this alert as its filling the messages up. Has anyone dealt with this before?
Anyone here have problem with Mod_Security and VBulletin ? Currently running Apache 1.3.x and Vbulletin 3.6.8 patch 2 and want to install Mod_Security on Apache so I want to know if there any conflict with Mod_Security and Vbulletin.
1) From time to time my vbulleting message board loads slow, and at that time the server isn't even at a high load this happen at loads 0.9 nothing much really but always below 4.
2) Not only does it load slow but it often return the server cannot be found error, this minute it works fine and the next minute it doesn't, all i can see from the error log for my domain is
3) php warning: Zend Optimizer for PHP 4.3.x cannot be found (expected at '/usr/local/Zend/lib/Optimizer-2.1.0/php-4.3.x/Zendoptimizer.so') - try reinstalling the zend optimizer in Unknown on line 0, referer [url]
4) Does vbulletin relies on zend at all to be fully functional?
5) will zend actualy help at all?
Yes there are other sites on the box and they seem to work fine. rhel4, ensim X 10.1 with all hot fix to date. php4 mysql4
A quick question for those running Vbulletin in Windows. I am running on a shared Windows 2003 server the Open Basedir is not enabled and the Safe Mode is off as per default setting. I can't change it as it is a shared hosting. The upload function is having problem due to the Open Basedir restrictions. Anyway to overcome that? The PHP is running in CGI mode.
I installed a vBulletin forum with e-mail validation on a dedicated I setup. The same board worked when I used to have shared hosting, however now when someone signs up some of the time they do not get an e-mail.
i run vbulletin, and set it to send out confirmation e-mail after registration, but for some reason mail doesn't send out to the user it stay in mail queue for days after days until i delete it.
I'm on a dedicated server and the httpd service of the server keeps going down which results in downtime for the number of hours until i dont realise that the site is down.
So when I realise the site is down, I ask the hosting support to look into the issue, they tell me the server loads are high and ask me to upgrade even when I just upgraded the server last month.
Generally the forum has around (250 - 300 members) + guests visitors online and is in the alexa top 20k sites.
The first thing I would want to do is hire a person who specializes in server optimization but then I have heard a lot of bad things like the server admin stealing databases and selling it in open market.
The second thing I wanted to do is contact vbulletin for server optimization but they need me to give them server specs and I dont know how to obtain them.