Page 1 of 1

HA shut down after mail server was hacked by spammers!

Posted: January 19th, 2016, 11:39 am
by Winston
Announcement:

Hi all,
Earlier today, this site went down for a few hours because my account was deactivated by Bluehost! I got an email about it from them, saying that SpamHaus.org blacklisted my site and asked me to call them about it. It was rude for them to deactivate my account without warning. So I called Bluehost TOS department. They told me that my site server was used to send out large volumes of spam mail using a technique called "snowshoe spamming".

http://www.wisegeek.com/what-is-snowshoe-spamming.htm

Bluehost reactivated my account, but they warned me that if it happens again, I'll have to find another webhost. Apparently, someone hacked into our mail server and used it to send out tons of spam mail. I'm not sure how. Maybe by hacking into my account or email or installing malware on this site. Either way, they instructed me to deactivate my mail servers until I trace down the malware using one of their programs, or another way. So I've done that for now. This means that you won't receive any email notifications from the forum for now, until I get this thing fixed and sorted out. Then I'll have to check the mail server logs to see if it's still sending out spam. I'll also have to change my webhost account passwords too of course, in case those were hacked as well.

I'm sure not how this happened, or whether dark forces are targeting this site, or whether we were just the victim of a mass snowshoe spam attack that was widespread across many IP's and not specifically designed to target us.

Any of you know anything about this or have any suggestions? I'll update you all if I find out anything.

Re: HA shut down after mail server was hacked by spammers!

Posted: January 24th, 2016, 9:25 am
by Winston
Update:

After Bluehost support scanned my site for malware and found none, they reinstated my mail server. So you should now be receiving forum emails and notifications again. So far, the mail spammers and hackers have not come back. But I will have support monitor the mail server logs to see if they return. I don't know how they hacked our mail server in the first place. So it's hard for me to know how to prevent it. That's the problem. Anyone have any idea?

Do you think we should encrypt this site with SSL certificates so that our address starts with https rather than http? Is this necessary? Would it help protect against hackers? Anyone know anything about this? I'm referring to this:

https://googlewebmastercentral.blogspot ... ignal.html

Re: HA shut down after mail server was hacked by spammers!

Posted: January 24th, 2016, 11:08 am
by Winston
By the way, if any of you run websites, here are some free online tools that checks for malware or malicious scripts on your site.

https://aw-snap.info/file-viewer/
https://sitecheck.sucuri.net/
http://quttera.com/
http://www.unmaskparasites.com/
http://www.sparktrust.com/
https://www.virustotal.com/#url

Re: HA shut down after mail server was hacked by spammers!

Posted: January 27th, 2016, 5:27 am
by tom
Ya you should watch ALL, I know it might be a bit boring, just the beginning,



YouTube will not parse https, no minor issue,
The mouse over graphics in the navigation bar, obvious errors not fixed for a long time, a very bad sign,
<a onmouseover="setOverImg('14','');" onmouseout="setOutImg('14','');" href="http://www.happierabroad.com/team.php" target=""><img id="button14" src="buttons/undefined" border="0" vspace="1" hspace="1"></a>
just a point to reference

I am no expert, maybe a lot of vulnerable code, I have a bad feeling you may need to re-code the whole site,
scanning for a string of malicious code is not the same as vulnerable code or structure, a scanner will not find this.

Re: HA shut down after mail server was hacked by spammers!

Posted: March 3rd, 2021, 11:56 pm
by Winston
Announcement:

Sorry the site was down for a while earlier. I contacted the webhost and they deactivated my account because the Illuminati said so and that this site was exposing too many truths.

Lol. Just kidding. Actually some hacker hacked into the email accounts and sent out spam in bulk, causing Microsoft to blacklist our IP and then Bluehost deactivated my account until I changed all my passwords on my hosting account. I wonder how that happened.

Re: HA shut down after mail server was hacked by spammers!

Posted: March 4th, 2021, 1:15 am
by Tsar
Winston wrote:
March 3rd, 2021, 11:56 pm
Announcement:

Sorry the site was down for a while earlier. I contacted the webhost and they deactivated my account because the Illuminati said so and that this site was exposing too many truths.

Lol. Just kidding. Actually some hacker hacked into the email accounts and sent out spam in bulk, causing Microsoft to blacklist our IP and then Bluehost deactivated my account until I changed all my passwords on my hosting account. I wonder how that happened.
My theory was that PAG shutdown the site. Maybe the hacker was PAG?

Re: HA shut down after mail server was hacked by spammers!

Posted: March 4th, 2021, 4:42 pm
by HappyGuy
Tsar wrote:
March 4th, 2021, 1:15 am
Maybe the hacker was PAG?
Maybe it was @Contrarian Expatriate or @E Irizarry R&amp;B Singer? https://en.wikipedia.org/wiki/Luther_Stickell

Image

From all the people who hate Winston PAG might be the only one who stands to lose something if this place shuts down.