Jump to content

wolstech

Chief Risk Officer
  • Posts

    19192
  • Joined

  • Last visited

  • Days Won

    760

wolstech last won the day on June 17

wolstech had the most liked content!

About wolstech

  • Birthday May 17

Contact Methods

  • Website URL
    https://www.raxsoft.com

Profile Information

  • Gender
    Male
  • Location
    Pennsylvania

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

wolstech's Achievements

Grand Master

Grand Master (14/14)

  • Well Followed Rare
  • Reacting Well Rare
  • Conversation Starter Rare
  • Dedicated Rare
  • Very Popular Rare

Recent Badges

1.6k

Reputation

  1. Note that when you actually buy a VPS, nothing happens to the hosting account automatically. You just get a VPS alongside. If you want to move everything to the VPS as a replacement for the Plesk hosting account, you would need to do so manually, then cancel the hosting account. Some of our VPS users do have both, they typically use the Plesk account for their main website, and set up the VPS on a subdomain to use for hosting large files or running a specific a heavy application like a game server.
  2. That IP address is not blocked on our end from what I can see. DNS on your domains looks fine (we usually recommend just setting the MX records directly to tommy.heliohost.org for simplicity, but this is not going to cause the issue you're describing and the configuration you're using should work). Krydos can confirm the firewall stuff on our side. If there isn't anything found, this may be an Azure issue.
  3. Very few of us use awstats, so odds are nobody really knows. It's also listed as deprecated in Plesk... Perhaps Krydos would know?
  4. That error looks more like the FROM address is wrong. If I'm reading that right, Windows mail is trying to send email on behalf of unqsoft@gmx.com using Tommy as the mail server. That will never work simply because Tommy isn't allowed to send mail for the gmx domain. You probably need to change the FROM address to match whatever mailbox you created on Tommy. I went ahead and set DKIM and SPF up on your main domain since its the only one on your account that's actually hosted here at the moment, but I suspect its the above mail settings issue in your client causing that error.
  5. The pending suspension for account oshekher has been cancelled. Thank you for complying with our terms of service.
  6. What is your username?
  7. No problem. For what it's worth, the page you described is normal for up to about 2 hours after a domain is added or an account reset is completed. If you recently completed a reset or had the domain added back to the account, that's why you were seeing the message.
  8. Johnny accounts have a 5 domain limit, so these won't fit as written. To make them fit, we need to reduce the number of domains by one. I would suggest either making one of them your main domain (and remove ashraf.helioho.st), or skip the alias. How do you want to proceed?
  9. In regards to your original request, you must send your support request from the email address on the account in order for it to be reset. Providing the email address in the body of the email is not sufficient, the email must actually be sent from that mailbox to prove that you control the associated email address.
  10. non-WordPress domain on this account) That's why I missed it...that domain has node instead. When I went through the domains, I saw that one had node enabled and just skipped over it, as I was focused on the WP stuff. Good news is that those files, while definitely malicious, likely would not have been able to run anyway since you had Node enabled (passenger redirects everything to node when enabled on a domain, so Apache never gets to run the PHP files). The interesting part is that the index.php is clearly meant for a nonexistent WP on that domain, and the mac.php looks like it may be the same or a very similar file to a file called bless24.php that was on the compromised lda.ng domain (I recognize this string from the top: xtamdxsirm from the other day).
  11. Updated and unsuspended. Your account may take up to 2 hours to function.
  12. The files from your old account can be downloaded from https://heliohost.org/backup/
  13. What is your username?
  14. The contents of the domain lda.ng have been discarded, the associated WP database developer1_lda has been dropped, and you've been unsuspended. Your account may take up to 2 hours to function fully. The attack came in through Wordpress itself, which is usually either a result of plugins with vulnerabilities, or failure to install updates. A backup from February actually does exist for your account at https://heliohost.org/backup/ if you need anything from that timeframe. You can make backups using the backup tool in Plesk. Note that if you use this, it is advised that you configure remote storage, as the backups it creates count towards your disk space quota and can quickly cause you to run out of space.
  15. Krydos can install this for you.
×
×
  • Create New...