|
|
Dear Sir/Madam,
Regarding your hosting account XXX.com:
The XXX.comweb site has been found to be compromised which is a violation of section 3 "Your Obligations" of Go Daddy's Web Hosting and Virtual Dedicated Hosting Service Agreement.
The relevant passage of this agreement has been provided below:
"You may not use Go Daddy's servers and Your web site as a source, intermediary, reply to address, or destination address for mail bombs, Internet packet flooding, packet corruption, denial of service, or other abusive activities. Server hacking or other perpetration of security breaches is prohibited and Go Daddy reserves the right to remove sites containing information about hacking or links to such information."
Go Daddy's "Web Hosting and Virtual Dedicated Hosting Service Agreement" is located at the following URL: https://www.godaddy.com/agreements/showdoc.aspx?pageid=HOSTING_SA
This situation has resulted in a potential security threat to Go Daddy's network and the security we provide to other customers. It appears that this abusive action may have been the result of your server becoming compromised and ultimately exploited by a third party. Upon detection of this problem Go Daddy's Security Operations Center requested that Go Daddy's Advanced Hosting Team alert you of this action in the hope that you can resolve the issue.
*** IMPORTANT ***
Due to the serious nature of this situation, your site is scheduled to be suspended if you do not take immediate action. Your site is eligible for suspension on February 17, 2012 To avoid this suspension, not only must you prevent a repeat occurrence of this problem, you must also reply to this notice with an email message containing the statements outlined below.
****************
These statements are as follows:
1. A statement that you have reviewed and agree to abide by the terms of the "Web Hosting and Virtual Dedicated Hosting Service Agreement," and
2. A statement that you have removed any malicious content residing on your web site, and
3. A statement that you agree to secure your web site in such a way as to ensure that there is not a re-occurrence of this issue in the future.
After providing the above statements in your reply, you must immediately follow through on your commitments. (We reserve the right to suspend the site if a repeat occurrence of this security violation is discovered.)
Go Daddy's security team has collected the following information to assist you in troubleshooting this issue:
. site contains an anonymous upload script which allowed attackers to upload malicious content to the server on or before 2/3/2012. In order to prevent further compromise, we have disabled access to the D:\Hosting\8112212\html\web1\Member\Web_File_Upload.asp. Please advise the customer to perform the following actions:1) Verify all site content to ensure that it does not contain any malicious content, or preferably restore from clean backups to a date previous to the compromise2) Update all applications to their latest version including all plugins, themes and extensions3) Update all account passwordsSource IP: 59.40.168.69Source Country: CN
|
|