Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow InterN0T shut down by their hosting provider 1and1
EH-Net
May 20, 2013, 12:20:49 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 [2]   Go Down
  Print  
Author Topic: InterN0T shut down by their hosting provider 1and1  (Read 22957 times)
0 Members and 1 Guest are viewing this topic.
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #15 on: December 17, 2011, 04:14:51 PM »

What I found most interesting about the SANS post, were the following:

The abuse department's  final email they posted showing clearly that they don't know who SANS is.

The fact that they didn't like the answer they were given.

And lastly that the person writing said email feels empowered enough to lock the account for the rest of the contract, insinuating that SANS would have to pay for service they were prevented from using.
Logged

OSWP, Sec+
group51
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #16 on: December 17, 2011, 05:07:03 PM »

I'm speechless.  I'm numb.  I have so much damn work to do because of this company.  Sometimes I feel like we can never win this battle.  It's looking more and more that what happened to MaxE, will happen to me in a slow death sort of way. 
Logged
millwalll
Guest
« Reply #17 on: December 17, 2011, 06:28:10 PM »

My site is with 1and1 and it contains links to sites and video showing how to hack wep no tools as such but links to lots of things. I never had any problem with them but some of the staff don't really have a clue. I think what they have done to  MaXe is wrong I don't know what contents were on his site but I think they should have least sent you email saying you site violates there TOS. They then could have then given you a day to fix this issue or your account would be removed.

I also understand from 1and1 point of view that some sites should be removed straight away depending on the contents. For example if you was hosting certain types of porn then sure they should remove you account and I think we would all agree with this.

It just seems like they don't really have a good enough reason or they do and wont tell you I think you will never know why they removed your account what sucks big time. but i wish the best of luck sorting it all out.
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #18 on: December 17, 2011, 08:01:01 PM »

I also understand from 1and1 point of view that some sites should be removed straight away depending on the contents. For example if you was hosting certain types of porn then sure they should remove you account and I think we would all agree with this.

I don't think I can agree with that. It's a straw man argument. The main thing is they're taking people's money as long as they are following the rules but changing those rules wihtout telling people.

The porn example is already covered by the TOS. but the hacking sites aren't. Yet they're turning around and shutting down accounts anyway.
Logged

OSWP, Sec+
millwalll
Guest
« Reply #19 on: December 18, 2011, 06:04:52 AM »

I also understand from 1and1 point of view that some sites should be removed straight away depending on the contents. For example if you was hosting certain types of porn then sure they should remove you account and I think we would all agree with this.

I don't think I can agree with that. It's a straw man argument. The main thing is they're taking people's money as long as they are following the rules but changing those rules wihtout telling people.

The porn example is already covered by the TOS. but the hacking sites aren't. Yet they're turning around and shutting down accounts anyway.

Don't get me wrong chrisj I don't think they should be able to change the rules. The point I was trying to get across was if someone for example was hosting a website that had porn on it and the people were not of legal age. Then this sort site should be shut down stright away. However in the case of hacking website I agree with everyone else here they should have NOT removed the account. But as I have said something does not sounds right and I don't think we will ever know why it was removed. Also as mention in the post lots us have hacking related material on 1and1 and have not been removed.

Logged
group51
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #20 on: December 18, 2011, 06:41:57 AM »

Quote
Also as mention in the post lots us have hacking related material on 1and1 and have not been removed.

Yet.

Perhaps I made the mistake of calling 1and1 to verify if what I'm doing could have my account closed.  Since my phone call, they have been making my life a living nightmare.  They are playing really dirty right now.  Like in the case above, blocking my admin areas to all my websites on a Friday just before their abuse team closes for the weekend.   Other things are happening as well where I suspect they want me to leave as a customer which is exactly what I'm trying to do. 

Closing websites down due to illegal content shouldn't be an issue and I also agree with the comments above.  However at the heart of all this is their misguided interpretation of the law and perhaps even their own policies that are blindly enforced by script reading employees that probably have no idea what ethical hacking is.  In contrast though, "abuse" teams and policy enforcement should allow for customer communication to verify if the violation was intended. eg. sites compromised. 

At the end of the day, I am learning a hard lesson that you get what you pay for.  If you want the ability to be able to communicate intelligently with competent staff that hosts your online content and a healthy chunk of your online identity, you need to choose companies that charge a little more.
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #21 on: December 18, 2011, 09:23:10 AM »

Don't get me wrong chrisj I don't think they should be able to change the rules. The point I was trying to get across was if someone for example was hosting a website that had porn on it and the people were not of legal age. Then this sort site should be shut down stright away. However in the case of hacking website I agree with everyone else here they should have NOT removed the account. But as I have said something does not sounds right and I don't think we will ever know why it was removed. Also as mention in the post lots us have hacking related material on 1and1 and have not been removed.

But that's the thing. Porn is already against their ToS, So it doesn't really matter anyway.

What we're talking about are things not stated in the ToS (hacking sites) and being told are ok by phone reps, then having them shut down anyway.
Logged

OSWP, Sec+
millwalll
Guest
« Reply #22 on: December 19, 2011, 04:10:51 AM »

I know porn is in the TOS I was just saying I understand why 1and1 need such rules.

But I agree with anyone comments that the TOS should be more clean about other material and they should not be aloud to change it as and when they like.
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #23 on: December 27, 2011, 11:35:31 AM »

I really am sorry for you.
I can only imagine how much passion and effort is necessary to produce and administer a site like yours or EHNet.
In my personal opinion they are a bunch of idiots and ignorants. They are the kind of security specialists we are trying not to become.
I hope that you'll pass this moment and you'll create a better one.

It has been hard so far, but it seems things are getting better, thanks!  Grin


Yep, we're on 1and1. That's why I asked. We have a dedicated server where this is the only site on the entire server...

That sounds crazy, esp. taking the risk into consideration. But I hope you won't have any problems with 1and1 in case you're still hosted at them.  Smiley


Wow, that's new.  Though, I cannot imagine form a legal point of view that they are allowed to delete your domain since it is definately not their property.

I had a talk the other day with the customer support of another hoster concerning the termination of a dedicated server and I asked them what will happen to my registered domain...

Now I am glad I didn't go to 1&1 when I bought a new hosting package last week  Smiley

Indeed, and they do state they can terminate anyone without notice. It's kind of "scary" they don't even give their customers a notice period, at least a day or three, after all, I was a customer for around 5 years.


I run an ethical hacking website who is hosted with 1&1.  Since one of my members pointed out what happened with intern0t, I could not imagine just losing everything

I think it's sick how they can just pick out which sites they don't want to host or not, where in this case they're all related to hacking.


I don't know how much space or resources are needed (for either of you) but I'm pretty happy with my $5/mo ($51/year) VPS from VPSCOLO (link). ...

Yeah I read through like 10-15 hosting provider ToS ~1½ week ago and found out most of them didn't want any content related to hacking at all. Thanks for the link btw ;-) Good prices too  Grin[/quote]


Thanks for the tip BillV.  I spent my last Saturday morning reading ToS's for a handful of different companies which included a phone call. .... they have the capacity to do what they did to Max, it's like a ticking time bomb and a risk I'm not willing to take for my site. 

I did the same thing, and found most of the same results. It's actually amazing how many bans all types of contents related to hacking, because they think it's "omg illegal" while it is often not illegal to speak about in theory, etc. Would be fun to make a forum addon that adds "hypothetically speaking: " to all threads  Cheesy

Anyway, I checked out network solutions and also saw they were an old stable hosting company, however I've already found another that is also not so offensive against hacking content. (Only if the server(s) are used for hacking.)


Update:

The following takes place between my pro-active phone call to the 1and1 "abuse" team to ensure they don't close my account and the email I got....
My 2012 mission is to get off of 1and1 servers.

It sounds crazy, did you resolve the issue or are there still issues with 1and1? I hope you've taken backup if possible and that you'll move asap. Well, that is what I'd do to a hosting company where you're sure they don't mind hacking related content.


Just some quick searching turns up all sorts of negative information about 1&1...
...
http://isc.sans.edu/diary.html?storyid=11338

The SANS entry isn't really negative but shows they selectively choose what to block


I was surprised by the SANS entry as well, in fact I wondered if it was (sorry for my word of choice) monkies working at 1and1. It seems like a manager went ballistic on the agent handling the case, hence the reason the agent told SANS to immediately remove the file.


What I found most interesting about the SANS post, were the following:

The abuse department's  final email they posted showing clearly that they don't know who SANS is.

The fact that they didn't like the answer they were given.

And lastly that the person writing said email feels empowered enough to lock the account for the rest of the contract, insinuating that SANS would have to pay for service they were prevented from using.

That also shocked me a bit, that they really didn't know who SANS was / is. It's like saying who's Microsoft lol.


My site is with 1and1 and it contains links to sites and video showing how to hack wep no tools as such but links to lots of things. I never had any problem with them but some of the staff don't really have a clue. I think what they have done to  MaXe is wrong I don't know what contents were on his site but I think they should have least sent you email saying you site violates there TOS. They then could have then given you a day to fix this issue or your account would be removed.


Thanks. The kind of content, was hacking related. Anything from advisories, to poc's, tools, program code, video guides, challenges, papers, almost anything except topics such as "CC's" and "DB Dumps" etc. There was a few other things that also were "banned content" on the site, that are typically found on other sites, but that was not on intern0t afaik.

Quote
Also as mention in the post lots us have hacking related material on 1and1 and have not been removed.

Yet.

Perhaps I made the mistake of calling 1and1 to verify if what I'm doing could have my account closed.  Since my phone call, they have been making my life a living nightmare.  They are playing really dirty right now.  Like in the case above, blocking my admin areas to all my websites on a Friday just before their abuse team closes for the weekend.   Other things are happening as well where I suspect they want me to leave as a customer which is exactly what I'm trying to do. 

Closing websites down due to illegal content shouldn't be an issue and I also agree with the comments above.  However at the heart of all this is their misguided interpretation of the law and perhaps even their own policies that are blindly enforced by script reading employees that probably have no idea what ethical hacking is.  In contrast though, "abuse" teams and policy enforcement should allow for customer communication to verify if the violation was intended. eg. sites compromised.  ...


I think it's horrible, especially that they first block access to the admin areas, and THEN suspend _everything_ so it's impossible to even get backups of your files and databases.

It is most likely also a misinterpretation of the law, as there's thankfully no law yet afaik that says you can't talk about hacking. After all, that would be a breach of the freedom of speech. Hacking in its highest form is not just about attacking machines, it's about taking things appart to see how they work, either by reverse engineering / fuzzing / testing the application or reviewing the source code, and then perhaps finding a bug that leads to a security issue, and then fixing it unless the info is just sent to the developers. That, is also just a small part of hacking as there's so many types of hacking. In fact one of the oldest meanings, was  for a person who was good at craftsman work with wooden objects. As he would "hack them" too. Of course, that has nothing to do with computers.

Some of the best hacks I see, are made within open source. "Hacks", that makes our life better. These are also hacks, and I'm not talking about attacking a program, service, computer, or a device, but actually improving it.

I think 1and1 should educate themselves on the topic of hacking and realise it's soon year 2012 and now year 1999 we're living in.



Anyway, it seems like things are slowly working out except for the domain which they are still holding hostage. It's just such a long process of filing a complaint to ICANN as 1and1 hasn't responded yet.
Logged

I'm an InterN0T'er
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #24 on: January 02, 2012, 03:45:36 AM »

wow, what a bummer (to say the least). just some advice: do not try to win the battle on the "my site is 100% ethical" discussion, just do whatever it takes to get a decent backup and move your site/documents/etc to another hosting...good luck on this one! and remember, EH.net got your back Wink
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #25 on: January 03, 2012, 04:56:50 PM »

Indeed it was j0rDy and yes, I've given up on the discussion about the "ethicality" of the site as I'm sure they could pick things out of context. Anyway, work is going slow but steady, so eventually, intern0t will get back  Smiley Thanks hehe
Logged

I'm an InterN0T'er
Ignatius
Jr. Member
**
Offline Offline

Posts: 91


View Profile
« Reply #26 on: January 04, 2012, 08:11:35 AM »

I realise that this situation is well-known here and many have expressed concern about what has happened but I wonder if this situation should be published more widely in the infosec community.  We all know what happened between Peter and Infosec Institute and that seems to have been resolved to everyone's satisfaction.

I would have thought that publishing information about MaXe's experience as widely as possible, providing it is correct factually and doesn't stray into the realm of defamation etc. (I have no reason to believe that it would), wouldn't do any harm.

Having seen the comments here about MaXe's former host, I would avoid them even though I note that others' experiences are more favourable.
Logged
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #27 on: January 04, 2012, 09:25:05 AM »

Having seen the comments here about MaXe's former host, I would avoid them even though I note that others' experiences are more favourable.

The thing is, MaXe's experience was probably also favorable until this happened. Knowing that your provider can (and will) flip the kill switch on a whim should be concerning to everyone that uses them. It would be an entirely different story if they called him, provided his data and DNS changes in a reasonable period of time, etc., but this is customer service at its worst.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Ignatius
Jr. Member
**
Offline Offline

Posts: 91


View Profile
« Reply #28 on: January 04, 2012, 12:45:15 PM »

The thing is, MaXe's experience was probably also favorable until this happened.

Exactly, hence the suggestion that this situation is publicised widely, just as Peter decided to make his ongoing situation with Infosec Institute widely known a few months ago.  Obviously, it's up to individuals here on EH.net who use 1and1 to decide whether they plan to continue using them with the possibility that they might pull the plug without any notice.
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #29 on: January 04, 2012, 06:34:48 PM »

If you search for "1and1 shut" on Google, two keywords, you'll see this post which is quite good. http://goo.gl/4yJyr

Furthermore, a few has already moved away from 1and1 after they heard this "horror story".
Logged

I'm an InterN0T'er
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.114 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.