What the New User can Learn from the GoDaddy Account Hack



godaddy-web-hosting

Recently a security breach occurred in 445 of GoDaddy’s web hosting accounts.  While that may not seem like a lot on a percentage basis, that is also high enough to indicate that the hack was some type of systemic problem.  This can scare the new user into a lot of frantic questions.

Panicked thought is seldom a clear thought.  So even if you were one of the accounts in question, there are things that you’ll want to consider when evaluating this incident.

Innocent until proven guilty

One of the most obvious knee-jerk responses is the one that is most necessary for us to correct immediately: blaming GoDaddy.  When something like this happens, until you have very specific, proven reason to believe otherwise, it’s unwise and unfair to blame the host.  We’re hesitant to even use this as an article topic for that reason.  We only are because this will happen now and then, and it’s good to have the object lesson.

Why did this only happen with GoDaddy though, you might ask?  There are many reasons that have nothing to do with them.  The most obvious is just efficiency.  By focusing their attack on one host with many users, the hacker(s) don’t have to concern themselves with more than one system architecture.

What actually happened?

Let’s summarize the incident.  The compromised accounts had their .htaccess file changed.  This is a file that handles URL requests on the user account level.  It sets rules for how to treat different requests to that user’s web site based on different criteria.  In this case, it was set so that any hits to the user’s site that came from a major search engine were redirected to a malicious outside site.  This site in turn infected the surfer’s browser, continuing and amplifying the disease.

The accounts have since been re-secured, but this does now require that we ask the pertinent question: how were the accounts infiltrated?

They got the passwords – but how?

What we know is that somehow the bad guys got these user’s passwords.  What we don’t know is how.  So in lieu of having further information, we must use this opportunity to repeat two of the oldest security cautions:

  • Keep your software updated – One site suggested the possibility that the users exploited a hole in a web site created by an outdated version of WordPress of Joomla!  You need to decide how much it’s worth it to stay close to the news reel on security updates, but either way don’t ignore them entirely.
  • Choose secure passwords! – This is the bane of the security world.  Even after decades of warning, users still continue to have “123456” and “password” for passwords.  Do you? Change it!  This is a major reason why we must give GoDaddy the benefit of the doubt: this alone might have been the cause of the break-in.

In summary, if there’s any one piece of advice we can take from this incident, it’s this: don’t panic.  Security for your web site requires clear-thinking at all times.

Tags: , , , , , ,

Keep Your Site Safe – Learn What Not to Do

web hosting

Let’s face it: The Internet isn’t the golden playground it once was, where all could go and have their swing in peace. In fact, it’s now so overrun with bullies and miscreants that it’s a wonder we haven’t decided to swap school districts yet!...

Sep 23rd, 2011 Read more

How To Deal With A Possible Intruder On Your Server

web hosting

You’re cruising through your server’s inner network one fine day, when all of a sudden you notice an unfamiliar name accessing your files. This user may have come through SSH, or any other access method, but no matter the entry port, you certainly...

Sep 21st, 2011 Read more

Several Security Risks and How to Avoid Them

Avoid Security Risks

Yes, you’ve made sure that you’ve chosen a password that you can remember, that no one else can guess, and that has in it at least one number and one punctuation mark.  You know, though, that there is more to securing your web site than that,...

Sep 9th, 2011 Read more

Performing IP Filtering Through cPanel – A Brief Tutorial

web hosting

Security is something that nearly every webmaster has the need for, but not every webmaster knows how to pursue effectively the appropriate security measures.  Given the craftiness of the hacker world, it can seem to the novice an unwinnable fight where...

Sep 6th, 2011 Read more

Is SSL Essential for eCommerce Sites?

web hosting

As the number of eCommerce websites grows, the security software must improve to protect webmasters from hackers acquiring sensitive customer information. One such technology is Secure Sockets Layer (SSL) which permits the site administrator to transfer...

Jul 29th, 2011 Read more

LulzSec’s Hacking Career Slated to End

web hosting

Well-known Internet mayhem group LulzSec recently announced to its followers that it will cease its campaign of web-based attacks. The group implemented numerous DDoS (Distributed Denial of Service) attacks on a variety of targets during its 50-day spree...

Jul 22nd, 2011 Read more

How to Prevent Domain Hijacking

web hosting

Although a website owner may feel secure upon registering a domain name, many don’t realize that domains are subject to hijacking.  Domain hijacking, or domain theft, is a prevalent nuisance that is on the increase.  Hackers need not to even access...

Jun 10th, 2011 Read more

Concerns Raised by the PlayStation Network Outage

web hosting

In the middle of April 2011, Sony faced an outage to the PlayStation network that revealed 100 million users private information. Approximately one month later the network is still down and raising plenty of questions regarding the security of cloud computing....

May 31st, 2011 Read more

Google Chrome Browser Cracked

web hosting

Vupen Security, a group specializing in vulnerability research, claims to have broken through the Google Chrome browser as well as the sandbox thus denting claims regarding the security of the browser. A video was recently released on Vupen’s website...

May 30th, 2011 Read more

Securing Windows for Web Hosting Safety

web hosting

Although the current state of the global economy is prompting many business owners to cut costs in various areas of business management, no expense should be spared when it comes to securing your web hosting plan, especially if you are an online business...

Mar 18th, 2011 Read more

Page 1 of 212

Stay in Touch with the Geeks

Our Community

Facebook
2274 Fans
Twitter
1422 Followers
FeedBurner
60 Subscribers

Submit News

Do you have an exciting story and want the world to hear it?

Submit a Story

  • 15K monthly visitors
  • PageRank 6
  • Alexa 11,000