So I got this email from my host saying my site was flagged for phishing. And I had no idea what was happening. Turned out someone uploaded a fake login page through an old contact form I forgot about. And I guess I learned more about security in three days than in five years of running this thing. The host suspended me within six hours of the abuse report. Which seems fast. But also they never told me *what* was found until I asked three times. Is that normal. Do hosts usually just pull the plug and explain later.
Anyway I spent the weekend building a file integrity monitor from scratch. And now I'm contributing to a community abuse detection tool. Funny how things work out. But I keep wondering if the host could have handled it better. Or if I should have known better...
Ah yes... the young people and their cloud nonsense... they think the provider will hold their hand through everything... back in the day we ran our own abuse desks... knew every customer by name... three dots for the holy trinity of blame... host... hacker... and hapless admin... you did the right thing building your own monitor... the tools these kids use now... all shiny dashboards and zero understanding...
I remember when Contabo... no wait... that was before they existed... when a certain provider I won't name... took forty-eight hours to notice a compromised box spewing phishing... six hours is almost too fast these days... but the silence afterward... that never changes... three dots for the mystery...
Post a reply
You need an account to reply.
Log in or
register to join the conversation.