xt0rt:
You should let 'Alex' know that you no longer want them as a host and arrange to get your Zen site moved over to a Certified Host.
Alot of hosts are a complete joke, it's best to pay a bit more if necessary and actually get decent service.
That may well be the ultimate solution in the final analysis. However Hosgator is not a small backroom host company. An organisation their size should be on top of this problem.
Out of interest here's excerpts from the last few exchanges we've had. Judging by his attack on ZCs php coding I think someone from the Dev. Team should take this up with someone at Hostgator - who knows how many other ZC users may be fed this poison when their stores get compromised in the same way?
Please don't insult my intelligence like this. To suggest that the spurious
iFrame string was present from original download from the official Zen Cart
website is ludicrous - are you seriously suggesting that all downloads from
that source contain this string? Incidentally the version is up to date and
contains the latest release of the ZC software.
I've checked my original files that were uploaded to your server and they
don't contain this line of malicious coding. The line of code responsible
for the problem was inserted after upload to your server, suggesting to me
that some exploit script is being deployed on your server software. Perhaps
that's the reason you can say " We see these every day when people do not
keep there scripts up to date". This has absolutely nothing to do with
keeping my scripts up to date. The scripts that were contained in my Zen
cart upload to the server were absolutely up to date.
Please investigate further and report your findings back to me. If this
situation can not be resolved in a professional manner I will have no
alternative but to seek another host, seek compensation from Hostgator and
further to advertise this wholly unacceptable stance that you have chosen to
adopt.
Gwilym.
===========================================================
----- Original Message -----
From: "HostGator Support" [email protected]
To: [email protected]
Sent: 27 June 2006 06:02 PM
Subject: [#CXE-469446]: URGENT!! REQUIRES YOUR IMMEDIATE ATTENTION
Hi,
This is a very common exploit done on the script itself not on our
servers. Just because you downloaded it from there site doesn't mean the
script is secure. You will need to edit the code out of your site and
upgrade your cart. We see these every day when people do not keep there
scripts up to date.
Best Regards,
Alex
HostGator Technical Support
Ticket Details
Ticket ID: CXE-469446
Department: Support
Status: On Hold
Follow up
Hi,
This was not present during the download. No one ever said it was. Alot of php scripts out there have Exploits allowing remote mysql insertions and or having premissions set to 777 allowing other harmful scripts to be uploaded. This is not done from a "trojan" or a "virus" on our servers. This is due to bad coding and or exploits being found on exsiting scripts. here is a clear example on what can happen. http://www.governmentsecurity.org/archive/t8822.html I highly recommend looking on zen carts fourms and seeing if theres a patch for this if is indeed the newest up to date version.
Best Regards,
Alex
HostGator Technical Support
My last reply:
Fine Alex, you may have a point with older coding, with known issues, that
is not the case with the problem I've highlighted.
Would you care to view this? http://wordpress.org/support/topic/69655
Now I still suggest that there's a malicious script on your servers that
seeks out php files and attacks them by inserting the iFrame string at the
foot of the code. Having me remove the spurious insertions and reloading my
files will not prevent the same thing happening again if that malicious
script that instigates the problem is not properly investigated and found.
Gwilym.
This is not funny - and I'm not going to give up easily on it. If anyone wants to lend some weight feel free to wade in, after all it's ZCart's reputation at stake. Their e-mail address is: [email protected]
Should this thread be relocated elsewhere on this forum?
G