Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 20 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow InterN0T shut down by their hosting provider 1and1
EH-Net
May 18, 2013, 07:23:51 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: InterN0T shut down by their hosting provider 1and1  (Read 22936 times)
0 Members and 1 Guest are viewing this topic.
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« on: November 30, 2011, 01:33:31 PM »

Dear EH-netters,


During the last weekend (Saturday between 13:46 and 14:01), most of InterN0T was shut down by the security department at 1and1. (The hosting provider.)

The only thing the technical support could say at that time, was that the accounts were suspended due to a "security issue". The security department, didn't open until Monday 09:00am EST of course.

At Monday the 28th of November 2011, the security department at 1and1 informed me, that the account had been terminated and that I was no longer a customer at 1and1.

The reason for doing this, was because we hosted content that could be used to "hack". Immediately I responded with that it was for ethical purposes only, but that didn't matter as all kinds of "hacking", are bad according to 1and1, especially their security department which you can reach at: +1 877 206 4253, in case you want discuss ethical hacking and penetration testing with them.

After requesting a backup of all my files, the response was: "Sir, your account has been terminated." (Which the agent or whatever I talked to, kept repeating.)

According to their Terms and Conditions, any kind of content 1and1 doesn't find appropriate (especially hacking), can result in any customer's account being immediately terminated without warning. This includes deleting a domain you legally own, all your e-mail accounts, all files, databases, everything.


Some of you trying to reach intern0t.net will be redirected to: intern0t.blogspot.com

As this is the current place for updates concerning the website.


For your information, I've been hosting content that could be used to "hack", on their servers for 5 years, without any problems whatsoever.



Best regards,
MaXe
Logged

I'm an InterN0T'er
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #1 on: November 30, 2011, 01:38:19 PM »

Have you reviewed their ToS to see if you can build a case against them? This is pretty horrendous and I'm sorry you are having to deal with this. They are essentially holding your intellectual property hostage and I would think you could have grounds for legal action but IANAL...

Did you have backups?
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #2 on: November 30, 2011, 01:47:04 PM »

I've dealt with 1and1 in the past for clients and they are not my favorite hosting provider.  I use Dreamhost and have never had a problem.  I give them money they give me oodles of space and services.  Frankly I say give them bad press, but yeah review that ToS.  If anything they should reinstate your domain and allow you to transfer your files off and transfer the DNS records to a host that is a bit more open.  I think it is just some paranoia on their part.  I sense some dark times coming if Judges are taking down sites and companies are taking it upon themselves to band content of paying customers.
Logged

Certs: GCWN
(@)Dewser
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #3 on: November 30, 2011, 01:53:13 PM »

MaXe - this is sad news. I was a member of your site. Though I haven't been active in the past few months, we spoke not long ago and I know you were getting new themes up for it and everything. Very sad to hear they would do this.

Fullt agree with turner and 3xban here. I hope you have backups. Intern0t had great material.
Logged

eCPPT, GCIH, OSCP, OSWP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #4 on: November 30, 2011, 02:03:43 PM »

Was this a dedicated server or shared hosting?

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #5 on: November 30, 2011, 04:22:01 PM »

Was this a dedicated server or shared hosting?

Don

Some of it was shared, and another part was on a non-shared VPS. Keep in mind they also deleted the domain name from their nameservers and everything else in my account. (I can't even access the account, as it basically "doesn't exist".)

The domain should still legally be my property, even though I have no control over it.

MaXe - this is sad news. I was a member of your site. Though I haven't been active in the past few months, we spoke not long ago and I know you were getting new themes up for it and everything. Very sad to hear they would do this.

Fullt agree with turner and 3xban here. I hope you have backups. Intern0t had great material.


Indeed, and I remember we spoke as we occasionally do  Smiley About the theme, yes that was implemented not long ago and I had even made some custom fixes, etc. I do have backups, but the database is a bit outdated afaik.

The main problem is not backups, but the domain, and a few other things  Smiley

I've dealt with 1and1 in the past for clients and they are not my favorite hosting provider.  I use Dreamhost and have never had a problem.  I give them money they give me oodles of space and services.  Frankly I say give them bad press, but yeah review that ToS.  If anything they should reinstate your domain and allow you to transfer your files off and transfer the DNS records to a host that is a bit more open.  I think it is just some paranoia on their part.  I sense some dark times coming if Judges are taking down sites and companies are taking it upon themselves to band content of paying customers.

I've reviewed their ToS and if they don't like the content on a particular website, then they are more than free to shut it down without any warning. See 8.6, 8.8 and 8.13 as guidelines that are vague, but describes somewhat that they can do whatever they want.

You're right about the paranoia, it's because of all the people abusing their skills that we, the legit and ethical hackers gets a bad name.

I also think that they should at least, reinstate the domain and allow me to transfer it, including the files I had stored, at least one single database, and a few other minor things.

Have you reviewed their ToS to see if you can build a case against them? This is pretty horrendous and I'm sorry you are having to deal with this. They are essentially holding your intellectual property hostage and I would think you could have grounds for legal action but IANAL...

Did you have backups?

I've reviewed it and a few other friends have too, their ToS is a bit vague, meaning they've basically defined they can do whatever they want to without any warning. It really is horrible, I hope they will one day open their eyes to what Ethical Hacking and Penetration Testing is, or at least just give people a warning to remove inappropriate material or a warning before they terminate your account.

You're right that they're holding my intellectual property hostage (esp. the domain), but there isn't much I can do, except the domain which I may have a decent chance with.
Logged

I'm an InterN0T'er
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #6 on: November 30, 2011, 05:33:16 PM »

I really am sorry for you.
I can only imagine how much passion and effort is necessary to produce and administer a site like yours or EHNet.

In my personal opinion they are a bunch of idiots and ignorants. They are the kind of security specialists we are trying not to become.

I hope that you'll pass this moment and you'll create a better one.
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #7 on: November 30, 2011, 05:40:22 PM »

Hmm, that's odd considering EH-Net is hosted with 1&1 isn't it Don?
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #8 on: November 30, 2011, 05:50:06 PM »

Yep, we're on 1and1. That's why I asked. We have a dedicated server where this is the only site on the entire server. If it's a shared plan of any sort, then they may have legitimate worry that it could affect other sites. But it does sound like they killed it just because they didn't like the content, not that they were concerned for other customers. So I'm forced to go look at my agreement with them as well.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
gromic
Newbie
*
Offline Offline

Posts: 38



View Profile
« Reply #9 on: November 30, 2011, 06:17:54 PM »

Wow, that's new.  Though, I cannot imagine form a legal point of view that they are allowed to delete your domain since it is definately not their property.

I had a talk the other day with the customer support of another hoster concerning the termination of a dedicated server and I asked them what will happen to my registered domain - I wanted it moved to another webspace within the same hoster.  He said, that they cannot just "delete or move" my domain(even within the same hoster) since they need my written approval (or something similar).  I mean sure 1&1could forge a termination "in your name" at the IANA ... but then I guess you could write the them to complain.

On the other hand... as hard as it is... they are not forced to host your content... As you have already mentioned ... every hoster has their "get rid of anybody" clauses... especially like don also wrote:
 
...If it's a shared plan of any sort, then they may have legitimate worry that it could affect other sites....

so here I see no chance...

I am sorry for you.  Hope at least it works out for your domain.
Now I am glad I didn't go to 1&1 when I bought a new hosting package last week  Smiley


« Last Edit: November 30, 2011, 06:25:56 PM by gromic » Logged

Thinking .... Please Wait...
group51
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #10 on: December 07, 2011, 05:29:27 PM »

I run an ethical hacking website who is hosted with 1&1.  Since one of my members pointed out what happened with intern0t, I could not imagine just losing everything - not just the website but resources tied to it.  So I called 1and1 and asked them to review my site so that I can at least have some opportunity to discuss the issue.  I called the general help desk who in turn gave me a separate number to their security department. There was no waiting and reached a direct person.  While he seemed on the ball he couldn't answer my question and said he would have someone look at my website.  I asked 5 times for someone to call me back to discuss and not to email.  Well they emailed me.  Their email to me is as follows.  For the record, I HATE 1and1 for the last 3 years and I am in the process of moving to another host.

--------------------------
Subject: C253550640  - 1&1 Internet Compliance

Dear ------ ------, (Customer ID: xxxxxxxxx)

Hi, you called asking if group51.org violates any terms and condtions.  As long
as a customer site does not violate our terms and conditions regarding adult
content, the abuse department does not care what the content of the site is.
Even if it is a hacker forum, it's not going to matter to us, as long as you are
not hacking with our equipment.  You can say what you want, publish what you
want, and do what you will with your own computer, but you may not use any of
our equipment for hacking.  If we discover you doing this, it can lead to the
locking and/or termination of your account.

--
Sincerely,
Security Team
1&1 Internet, Inc.
« Last Edit: December 07, 2011, 06:15:43 PM by don » Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #11 on: December 07, 2011, 08:29:41 PM »

I don't know how much space or resources are needed (for either of you) but I'm pretty happy with my $5/mo ($51/year) VPS from VPSCOLO (link).

Their support is good (though with your own VPS you kind of are the support) and they are pretty flexible with what you can do. I even came out and told them I needed to do some security testing from my box and they had no problem with it.

I use GoDaddy for my other hosting needs (been there for years and don't really have any complaints).

GoDaddy ToS:
Quote
You will not use this Site or the Services found at this Site in a manner (as determined by Go Daddy in its sole and absolute discretion) that:
  • Promotes, encourages or engages in any spam or other unsolicited bulk email, or computer or network hacking or cracking;

I don't know if talking about such subjects means 'promoting or encouraging.'
« Last Edit: December 07, 2011, 08:36:35 PM by BillV » Logged
group51
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #12 on: December 07, 2011, 08:48:59 PM »

Thanks for the tip BillV.  I spent my last Saturday morning reading ToS's for a handful of different companies which included a phone call. (where those companies answered their phone).  I also read reviews online and GoDaddy didn't rank high. Other companies flat out said "we don't want ethical hacking content" and refused service. I suspect that's first line support assumptions in some cases.  The best luck I had in both speaking with someone, understanding the ToS, good shared QoS (1and1 servers are heavily taxed)... I ended up choosing Network Solutions. This is not meant to be an advertisement - just explaining my (re)action to the news while I try to run a non-profit group. I feel for Max and would encourage him to check them out.  Yes it's more expensive but in the end, they have been around for 30 years and seem to be more tolerant of this stuff.  With all the laws changing or being created, I think our days are numbered anyhow.

It may be that ethicalhacker.net is hosted on 1&1 but the very fact that they have the capacity to do what they did to Max, it's like a ticking time bomb and a risk I'm not willing to take for my site. 
Logged
group51
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #13 on: December 16, 2011, 05:51:44 PM »

Update:

The following takes place between my pro-active phone call to the 1and1 "abuse" team to ensure they don't close my account and the email I got today:

From 1and1:
Your contract number:  XXXXXXXX
Your customer ID:  XXXXXXXXX
Our reference:  [Ticket XXXXXXXXXX]
Note:  Your personal 1&1 contract number and your name certify that this e-mail
was sent by 1&1 Internet Inc.

Dear Mr. xxxxxxx,

This is an urgent notice regarding the security of your 1&1 account.

Your 1&1 webspace has been attacked via an insecure software you installed on your webspace.

You will find an analysis of the attack and instructions on how to secure your webspace against future attacks in this e-mail.

In order to impede further attacks, we have disabled these files. Please
note that part of your websites may be impaired.


-----------------------

This was bogus.  I have other accounts running similar software with no warning.  This was targeted.   I lost admin access to all my client websites - 1and1 disabled the joomla admin files.   I called them tonight and the abuse team is closed until Monday.

On a side note, I'm having extreme difficulty trying to transfer my ethical hacking site http://group51.org domain name to a new provider.  This is my second round - "Pending Registry Approval".   1and1 systems are denying my domain transfer even though I provided the auth code and followed all the security steps. 

My 2012 mission is to get off of 1and1 servers.
« Last Edit: December 16, 2011, 05:53:42 PM by group51 » Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #14 on: December 17, 2011, 08:10:56 AM »

Just some quick searching turns up all sorts of negative information about 1&1...

http://www.scam.com/showthread.php?t=119339
http://www.knowledgesutra.com/forums/topic/71430-1and1-scam/
http://www.webhostingtalk.com/showthread.php?t=1098184
http://isc.sans.edu/diary.html?storyid=11338
http://www.sitepoint.com/forums/showthread.php?682932-1AND1-%281-amp-1%29-Really-Is-a-SCAM!

The SANS entry isn't really negative but shows they selectively choose what to block
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.