![]() | | ||||||||
| | #1 |
| HyperActive Warrior Join Date: Nov 2008
Posts: 251
Thanks: 5
Thanked 79 Times in 30 Posts
|
As a courtesy Public Service Announcement... you need to be aware of this, if you have not already read about it. If you don't own a website, disregard this notice. There have been numerous threads posted on the forum about site hacking, here is one way you can minimize it. Please check your Anonymous FTP settings. Go to your hosting account control panel, look for Anonymous FTP, and turn it off... like now! This is a major security hole and most hosting providers have this enabled by default. Bluehost and other hosting providers have started issuing warnings about this setting, and it is a change that many simply are not aware of or overlook. Maybe this will help someone out there. |
|
You are making this work at home stuff way harder than it is. Ready for some sanity? Clear your head and start over. | |
| | |
| | #2 |
| Senior Warrior Member War Room Member Join Date: Aug 2002 Location: Long Island N.Y.
Posts: 1,152
Thanks: 28
Thanked 192 Times in 101 Posts
|
Hello, thanks for the heads up, I do not know why this setting is even allowed in this day and age. |
|
Something new soon.
| |
| | |
| | #3 |
| HyperActive Warrior Join Date: Nov 2008
Posts: 251
Thanks: 5
Thanked 79 Times in 30 Posts
|
There are actually legitimate reasons that someone could use this with their internet business... like allowing their customers to upload things. There are other, much better ways to do that now. But back in the day when the internet was pristine, tecky an honest, who would have thunk? I agree with you wholeheartedly. The default position should be "OFF", not "ON". |
|
You are making this work at home stuff way harder than it is. Ready for some sanity? Clear your head and start over. | |
| | |
| | #4 |
| Senior Warrior Member War Room Member Join Date: Sep 2005 Location: Singapore
Posts: 4,160
Thanks: 35
Thanked 237 Times in 141 Posts
|
Thanks for the update. Good thing that my host turns it off by default. Whew!
|
| | |
| | |
| | #5 |
| Carol War Room Member Join Date: Aug 2008 Location: UK
Posts: 2,731
Blog Entries: 13 Thanks: 341
Thanked 731 Times in 514 Posts
|
Sorry to be thick DeadGuy - can you give me some clues about where to find this in cpanel? Thanks
|
| Offliners - Client Guide to Editing a Wordpress Site Atahualpa Theme Tutorial. Available to promote via Clickbank Beginners Guide to SEO - Good, solid, grounding in SEO techniques | |
| | |
| | #6 |
| HyperActive Warrior Join Date: Nov 2008
Posts: 251
Thanks: 5
Thanked 79 Times in 30 Posts
| |
|
You are making this work at home stuff way harder than it is. Ready for some sanity? Clear your head and start over. | |
| | |
| | #7 |
| The Ethical Marketer War Room Member Join Date: May 2006 Location: Wisconsin, USA
Posts: 6,045
Thanks: 1,747
Thanked 3,000 Times in 1,331 Posts
|
I agree. It should be turned off by default. If it isn't already, then the host could certainly make it the default. In other words, the notices they are sending should say something like, "We have just changed all accounts to the off position for anonymous FTP. If you would like to have that feature enabled, you will have to[list of steps]." At the very least, give a few days notice before the change so those that do use it wouldn't have an interruption of that feature. All the best, Michael |
| | |
| | |
| | #8 |
| HyperActive Warrior Join Date: May 2008 Location: Riverside, CA
Posts: 408
Thanks: 21
Thanked 26 Times in 24 Posts
|
Thanks for the heads up. I never even thought about this. I just went in to my cpanel and there it was, plain as day, enabled. If you use Hostgator, as I do, you'll want to check this out immediately. |
| | |
| | #9 |
| HyperActive Warrior Join Date: Feb 2010 Location: Bristol, UK
Posts: 375
Thanks: 77
Thanked 39 Times in 34 Posts
|
I use hostgator and mine was not enabled. Having said that, my sites are less than a year old, so perhaps they have fixed it on newer accounts? Thanks for the heads up, though! |
| I don't build in order to have clients. I have clients in order to build. - Ayn Rand | |
| | |
| | #10 |
| Senior Warrior Member War Room Member Join Date: Jan 2008 Location: Wisconsin, USA.
Posts: 4,113
Blog Entries: 2 Thanks: 2,405
Thanked 3,421 Times in 1,592 Posts
|
Good warning. It's the first thing I do when I set up a new account. I don't know why, but every host I've every seen has Anonymous FTP enabled as the default setting. Maybe it's because that's the way Cpanel is configured when they install it, but regardless, it is a setting that needs to be disabled unless you have a good reason to want it.
|
| | |
| | |
| | #11 |
| Carol War Room Member Join Date: Aug 2008 Location: UK
Posts: 2,731
Blog Entries: 13 Thanks: 341
Thanked 731 Times in 514 Posts
|
Edited - found it! If anyone else is still looking - in my cpanel it isn't under files. It's in "ftp manager" - and then "setup anonymous ftp access" |
| Offliners - Client Guide to Editing a Wordpress Site Atahualpa Theme Tutorial. Available to promote via Clickbank Beginners Guide to SEO - Good, solid, grounding in SEO techniques | |
| | |
| | #12 | |||
| CEO of The Internet War Room Member Join Date: Mar 2009 Location: World Traveler!
Posts: 1,106
Thanks: 520
Thanked 628 Times in 318 Posts
| Quote:
@ DeadGuy, you have done more than a public service, you pretty much just saved the arses of a lot of IMers. I only wished that more people would read this thread, comprehend what they are reading and take the corresponding actions. Quote:
Quote:
| |||
| Tools, Strategies and Tactics Used By Savvy Internet Marketers and SEO Pros: Test Drive Market Samurai | Get Website Traffic 1000 Visitors Per Day | Test The Best Spinner | Premium WP Themes For Newbies | Get XSitePro | Back Link Building Strategies | ||||
| | |
| | #13 | |
| The IM Wiki War Room Member Join Date: Oct 2009 Location: UK
Posts: 313
Blog Entries: 8 Thanks: 390
Thanked 64 Times in 50 Posts
| Quote:
Thanks for this tip though Deadguy. I bet it has helped many people. I had never even looked in this folder and wouldn't have thought to look even if I saw it. | |
| Download The First Mastery Module Free! - Complete Step-By-Step Online Business Blueprint | ||
| | |
| | #14 |
| Active Warrior War Room Member Join Date: May 2010
Posts: 47
Thanks: 0
Thanked 3 Times in 3 Posts
|
Cpanel Service Configuration >> FTP Server Configuration |
| | |
| | #15 |
| Niche Custom Shirt Maker War Room Member Join Date: Mar 2003 Location: Fort Myers, FL , USA.
Posts: 648
Thanks: 100
Thanked 79 Times in 58 Posts
|
I use HostGator for close to 100 sites. I checked a couple and they were enabled. Anyone know of a way to change it in all of them at once? Maybe in the WHM? Thanks, Dennis |
| MatchRate Plus <-- The BEST FREE HOME BUSINESS I've Ever Seen, Monthly Residual Income Promote ANY MLM: FREE MLM Reports | Network Marketing CDs | Network Marketing Shirts HOST WEBINARS ON FaceBook: Host Opportunity & Affiliate Webinars On Facebook OIOPUBLISHER Automatically Sell Advertising Space On Your Blogs & Keep ALL The Money! PREMIUM DOMAIN CLUB Sell Any Of OUR 500+ Premium Domain Names & Keep ALL The Profit | |
| | |
| | #16 |
| ... Madly Writing! War Room Member Join Date: Feb 2007 Location: USA
Posts: 1,573
Blog Entries: 16 Thanks: 257
Thanked 162 Times in 110 Posts
|
WOW - I have to say I have never seen or heard anyone mention this before! Just checked my main host and it's already deactivated, but will check the rest. Thanks for posting this! Wendy |
| | |
| | |
| | #17 | |
| I.C.Hope War Room Member Join Date: Apr 2009 Location: Northern Ireland
Posts: 2,515
Thanks: 446
Thanked 227 Times in 181 Posts
| Quote:
Press Ctrl + F then search for the word on the page. | |
|
I want a good keyword researcher, not for min sites but for tech articles. Hit me up if you've got those skillz!
| ||
| | |
| | #18 |
| HyperActive Warrior Join Date: Dec 2009 Location: Canada
Posts: 235
Thanks: 90
Thanked 45 Times in 37 Posts
|
Thanks for this! I checked my HG CP and it wasn't allowed, but I also have an account with A Small Orange, and I did need to change my settings there. |
| | |
| | |
| | #19 |
| HyperActive Warrior War Room Member Join Date: Jul 2009 Location: Australia
Posts: 317
Thanks: 33
Thanked 283 Times in 69 Posts
|
My Hostgator account was unchecked so I guess it isn't all Hostgator accounts that have the problem.
|
|
My Blog --> Affiliate Blog Online Amazonian Profit Plan - JUST RELEASED! - Our Complete Blueprint for Making Money Online by Promoting Amazon Products - The Amazonian Profit Plan | |
| | |
| | #20 |
| Content & Copywriting Wiz War Room Member Join Date: Dec 2006 Location: Roselle, NJ, USA
Posts: 16,394
Blog Entries: 11 Thanks: 1,529
Thanked 6,185 Times in 2,282 Posts
|
Never knew, and mine was checked. Thanks...We need more of these kinds of threads here. |
| | |
| | |
| | #21 | |
| Carol War Room Member Join Date: Aug 2008 Location: UK
Posts: 2,731
Blog Entries: 13 Thanks: 341
Thanked 731 Times in 514 Posts
| Quote:
ftp manager. What do you suggest I should have searched for and where? | |
| Offliners - Client Guide to Editing a Wordpress Site Atahualpa Theme Tutorial. Available to promote via Clickbank Beginners Guide to SEO - Good, solid, grounding in SEO techniques | ||
| | |
| | #22 |
| "Sco" Riggs Join Date: Oct 2009 Location: North of San Francisco, CA.
Posts: 45
Thanks: 10
Thanked 1 Time in 1 Post
|
Thank you for the critical tip!
|
| | |
| | #23 |
| HyperActive Warrior Join Date: Nov 2008
Posts: 251
Thanks: 5
Thanked 79 Times in 30 Posts
|
The rape and pillage side of me told me to inform everyone that they needed to turn anonymous ftp on, or to buy my ecourse on "how to protect your website income" (for $497)... but I just couldn't bring myself to do it. Glad to help.
|
|
You are making this work at home stuff way harder than it is. Ready for some sanity? Clear your head and start over. | |
| | |
| | #24 |
| HyperActive Warrior Join Date: Apr 2010
Posts: 199
Thanks: 0
Thanked 11 Times in 11 Posts
|
Hey thanks so much! I'm going to do that right away!
|
| | |
| | |
| | #25 |
| Senior Warrior Member War Room Member Join Date: Sep 2005 Location: Singapore
Posts: 4,160
Thanks: 35
Thanked 237 Times in 141 Posts
|
For warriors who have over 50+ accounts in one server and have a WHM, here's how you can do it: Go to WHM: Main >> Service Configuration >> FTP Server Configuration. |
| | |
| | |
| | #26 |
| My Site spins & publishes War Room Member Join Date: May 2010 Location: NJ
Posts: 119
Thanks: 0
Thanked 7 Times in 6 Posts
|
WOW! I would have never even thought to change this. Thanks for the heads up! |
| | |
| | |
| | #27 |
| HyperActive Warrior War Room Member Join Date: Apr 2010 Location: Stockton, CA
Posts: 337
Thanks: 37
Thanked 61 Times in 35 Posts
|
Great, thank your for the update. Best Regards, UFG |
| | |
| | #28 | |
| Senior Warrior Member War Room Member Join Date: Sep 2007 Location: Cincinnati, OH and beautiful Park City, UT
Posts: 1,643
Thanks: 770
Thanked 494 Times in 334 Posts
| Quote:
:-Don | |
|
"The 25 Profit Thieves and The 14-Day Turnaround - How To Build Any Business Fast." Get the downloadable book FREE! It's NOT a sales pitch.http://www.BuildAnyBusinessFast.com | ||
| | |
| | #29 |
| Active Warrior War Room Member Join Date: Oct 2009 Location: UK
Posts: 72
Thanks: 36
Thanked 5 Times in 5 Posts
|
Dude, thanx for that! i had a look to my hostgator cpanel and the thing was enabled...the site less than six months old so who knows how they setup things there, scary stuff. You Rock! |
| | |
| | #30 |
| Word Arsenal Specialist!! War Room Member Join Date: May 2010 Location: TN
Posts: 208
Thanks: 22
Thanked 10 Times in 9 Posts
|
Thanks, I should have thought about this, but would have guess that it was off anyways. Yep, it was on. I shut it off. Appreciated.
|
| | |
| | #31 |
| HyperActive Warrior War Room Member Join Date: Jul 2007 Location: CA , USA.
Posts: 114
Thanks: 17
Thanked 22 Times in 19 Posts
|
What a great post!!! I manage over 1000 domains and I have seen non anonymous FTP get hacked. This is because when you authenticate on FTP your user name and password is sent plain text. The easy answer to this is sFTP or FTP over port 22. the "s" mean secure. This is not always available but if you have WHM and can SSH to your server then you can run sFTP and I recommend that you use it. Filezilla is a good free FTP app that supports sFTP In many hosting environment you cannot run sFTP so this whole text user and password can be an issue. You can follow some simple rules 1) make difficult passwords 2) change them often I hope this helps |
|
I hope everyone is having a Great Day!!! I am here to help out and to be helped Everyone can use a helping hand now and then!! Great merchant account company | |
| | |
| | #32 |
| Advanced Warrior War Room Member Join Date: Dec 2009
Posts: 655
Thanks: 10
Thanked 85 Times in 74 Posts
|
I just checked and mine was checked. I just disabled it. Thanks for the heads up. |
| | |
| | #33 |
| Anti-scam warrior War Room Member Join Date: Jul 2009 Location: Upper Michigan
Posts: 436
Thanks: 272
Thanked 60 Times in 44 Posts
|
I can't thank you enough for posting this. I have had 5 sites on Host Gator hacked (3 just today), and now I know the likely reason why. I can't find this in my WHM, although I have fewer than 50 accounts, but enough that I don't want to do them one by one. |
| | |
| | |
| | #34 | |
| Platinum Warrior Member War Room Member Join Date: Mar 2009 Location: AU
Posts: 2,686
Thanks: 472
Thanked 325 Times in 264 Posts
| Quote:
Yes there should be more like it | |
| How To Explode Your Online Income x 67 Times! You Are About to Experience the VIRAL EFFECT!!! Get Your Ad Sent to 55,000 People RIGHT HERE Who The Heck Else Wants 10,000 FREE Top Banner Impressions? | ||
| | |
| | #35 |
| Advanced Warrior War Room Member Join Date: Jan 2006 Location: North Carolina
Posts: 903
Thanks: 98
Thanked 31 Times in 25 Posts
|
Same here, the WHM [for my reseller account] -> Service Configuration -> FTP Server Configuration doesn't exist. Other than giving number to how many FTP accounts each package you set up can have, there is no other mention of FTP at all in my WHM. Now where do I look? |
| | |
| | |
| | #36 | |
| Senior Warrior Member War Room Member Join Date: Sep 2005 Location: Singapore
Posts: 4,160
Thanks: 35
Thanked 237 Times in 141 Posts
| Quote:
| |
| | ||
| | |
| | #37 | ||
| Retired Internet Marketer Join Date: Nov 2008 Location: Alabama
Posts: 1,089
Thanks: 47
Thanked 123 Times in 97 Posts
|
I don't even see the following: Quote:
Quote:
| ||
| | |
| | #38 |
| Advanced Warrior War Room Member Join Date: May 2008 Location: Swansea, South Wales, UK
Posts: 981
Thanks: 512
Thanked 182 Times in 123 Posts
|
Anyone else using Hostgator Reseller manage to do this from the WHM yet? I can't see where it is and looked all over - when I go to "Server Configuration" all I have as the next choice is "Basic Cpanel/WHM SetUp" and nothing else? Any help appreciated, Sue |
| One-to-One WordPress Coaching Service Available at Low Hourly Rate - Let the frustration end now! WordPress Installs, Theme Design, Site Tweaks & other WordPress services available Last edited by SusanneUK; 05-21-2010 at 01:56 AM. Reason: typo | |
| | |
| | #39 |
| Advanced Warrior War Room Member Join Date: May 2008 Location: Swansea, South Wales, UK
Posts: 981
Thanks: 512
Thanked 182 Times in 123 Posts
| I had to get hold of HG Support in the end to put my mind at rest, these are the two relevent responses that apply to anyone with reseller hosting: 1st one: Anonymous FTP is disabled on all of our shared and reseller servers by default, if someone connects anonymously, it will default them to a folder on the server that has no write, or execute perms. Unless you have specifically set it enabled.2nd one because I did have a question: Sorry for the confusion - it's technically 'enabled', but it's crippled to the point that it's disabled. Specifically, it's 'enabled' in that someone can FTP to the account anonymously, but it's disabled as in that's all they can do.Hope that puts people's mind at rest on some areas of this. Sue |
| One-to-One WordPress Coaching Service Available at Low Hourly Rate - Let the frustration end now! WordPress Installs, Theme Design, Site Tweaks & other WordPress services available | |
| | |
| | #40 |
| QuiteTired Warrior War Room Member Join Date: May 2010 Location: Australia
Posts: 157
Thanks: 109
Thanked 18 Times in 16 Posts
|
Good thing my hosting provider disables this by default!
|
| | |
| | #41 |
| Senior Warrior Member War Room Member Join Date: Jun 2008 Location: Hungary
Posts: 1,308
Thanks: 213
Thanked 212 Times in 151 Posts
|
Hi Deadguy, Thank you for your heads up, this is a very important and useful message. People (including myself, too) may overlook such things oftentimes. Then we doesn't take it why we had a problem... LOL Have a nice day, Sandor ___________________ - nothing to sell now - |
| | |
| | #42 |
| Advanced Warrior Join Date: Mar 2010
Posts: 557
Thanks: 18
Thanked 19 Times in 19 Posts
|
My host has anon FTP disabled by default. You actually have to pay to have it switched on. I would think most hosts disable it these days.
|
| Warrior cats is a Roleplaying Forum for the Warriors series! That's right, a fun game, and yes it is free! If you are into writing and roleplaying just come check it out. :) | |
| | |
| | #43 |
| HyperActive Warrior War Room Member Join Date: Dec 2009 Location: Tucson, Arizona
Posts: 154
Thanks: 68
Thanked 22 Times in 18 Posts
|
I took a look... and there was no Anonymous FTP icon! Checked with the tech staff, and Jeff already has it *unavailable* over at ChrisFarrellMembership... Jeff and his staff *ROCK* ! They spoil us over there... ![]() L8ter... |
| Internet Safety Tips - The Essentials Internet Safety Tips – “The Essentials” – Examples Of Attacks Check out this chapter, then sign up to download YOUR copy! | |
| | |
| | #44 |
| Senior Warrior Member War Room Member Join Date: Jun 2005 Location: So Calif USA.
Posts: 1,833
Thanks: 171
Thanked 56 Times in 36 Posts
|
Thanks for the heads up. I unchecked my Hostgator domains. I could not find any settings at GoDaddy or 1and1. Anyone have any ideas where the settings are on those other hosts? |
| Bob Hale | |
| | |
![]() |
|
| Tags |
| hurt, pants |
| Thread Tools | |
| |
![]() |