Skip to content

Comment on Bluehost got hacked and responded pretty badly (by lying to their customers)

Comments

I've been having the worst experience with this. First the client emailed us because they couldn't reach their website due to a "This website may harm your computer" warning. I isolated the script and got that warning removed (it looked similar to the one referenced in this post: http://rayschamp.com/misc/spammer.html - scroll down for the original obfuscated version).

When I contacted Bluehost about it, they gave me a canned response about php script security. I wanted to check my logs for any suspicious activity on any scripts hosted on the site, but the logs for the relevant time period weren't available. Strange, because the Webalizer stats do show information from this period. The current log only has information since the 29th, and the June archive only has information from June 1.

Then I tried to contact Bluehost several times through chat and email to retrieve the missing June data, and each time they either told me it was gone forever (despite the Webalizer stats) or they told me it was in one of the files I explicitly noted it was missing from. Now I realize that ALL of the monthly raw access log archives only have 2 days of logs stored. It appears that their logging system is broken, and no amount of contacting them will retrieve the June 1-29 data (the period in which the site was hacked).

From my perspective, if I can't determine it's one of the scripts on the site, I have to assume the vulnerability is with Bluehost. Bluehost hasn't notified anyone of a breach, so I don't know if they're handling it or not. If they were clear about what was going on, I would probably stay with them because I could tell the client what was being done to resolve the issue. The only logical thing I can offer my client now is to move hosts, which is inconvenient for everyone involved.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.