Skip to content

Comment on GoDaddy shared servers compromised – .htaccess redirection to sokoloperkovuskeci

Comments

Someone commented on the posted article that the compromise seems to be from Godaddy itself. What I'm thinking is someone used a vulnerable 3rd party script hosted on a shared server, then somehow got root or escalated privileges and compromised all or most of the sites hosted on the shared server. If the issue was Godaddy itself being hacked, I would assume it would affect all servers, not just the shared one(s).

If somebody managed to compromise other customer's accounts via one shared hosting account, even if it is limited to a single server, then I would consider this as Godaddy being hacked.

You can do this fairly easily with Apache and symlinks, there's an issue with SymlinksIfOwnerMatch that people can circumvent if they're clever...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.