Jump to content

wolstech

Chief Risk Officer
  • Posts

    18,624
  • Joined

  • Last visited

  • Days Won

    726

Posts posted by wolstech

  1. You're suspended because your Wordpress installation got hacked and your account is full of malware. Wordpress is infamous for having security issues, especially when plugins are used. It's an easy target for hackers, and once they get in, they use your site to deploy malware, send spam, or set up a phishing site.

    Because the account contains malware, it will need to be reset without a backup in order to be unsuspended, which permanently deletes all of your data. Are you ready to reset your account?

  2. Moodle is quite literally the heaviest software we've ever tested on our service. Johnny accounts are basically guaranteed a high load suspension for memory usage if you run it due to excessive load the cron job. Please see https://wiki.helionet.org/Common_Software_Load You only have a 200GB/day memory limit on Johnny and Tommy, Moodle needs 550GB/day just to sit there and do nothing.

    The paid Morty account will run the software decently enough and won't get suspended, but will incur overage fees because of the memory usage. Moodle is meant to be run on a VPS.

    That said, I've added the extra domain and increased max_input_vars on the new domain for you. The domain and PHP settings changes can take up to 2 hours to function.

  3. It's against US law to "enable access" or "make available" illegal content that's hosted elsewhere too (it's still considered copyright infringement), so your site cannot access/convert IPTV or other copyrighted streaming content that the user provides either. The high load was also the Lily app. It pegged the CPU at 100% and almost hung the server (in fact, it may have been the cause of a hang a few weeks ago, though I cannot verify that since I couldn't even log in at the time to see why the server was overloaded, it had to be restarted). That said, this app is way too heavy for Lily...a VPS is really the appropriate way to run something like this.

    Here's a screenshot of your IIS process using 97% of the entire server's CPU from when you got suspended...it was like that for about a half hour before we suspended you.

    image.png.16de5af4474177339c0502b17755226e.png

    That TempDuckUrls is indeed what triggered the porn detection. If that's just a cache, that's fine, it sounds like someone just went searching for that content and the cache kept the URLs. I didn't see any other mentions of adult content besides these, so just need to clear the cache.

    To be unsuspended, you'll need to:

    • Remove the IPTV to video M3U functions (the other pieces of the tool that just provide non-video statistics like game scores and such should be fine to keep, it's the IPTV piece specifically that is a copyright issue)
    • Delete the proxy PHP file on the plesk account.
    • Make sure the image search tool doesn't cause excessive load, remove if load cannot be controlled. You'll probably need to ask to check your load on Lily since there isn't a way for you to see it like there is on Plesk.
    • Fix the content filter on the image search tool. You mentioned it's supposed to have one, getting it working should solve the porn issue.
    • Clear the TempDuckUrls cache.

    Would you be good with that? If so, I'll give you 24 hours to do so.

  4. There is also an associated Lily account for this user that's banned for copyright infringement, causing high server load (he had a video converter running on Lily), and porn (there was a file with links to adult content found in the account).

    This user cannot be unsuspended.

  5. Old domain removed and new domain added. It can take up to 2 hours to function.

    Also, just because of the names of your domains, I do want to point out that our terms of service prohibits you from using our service to provide financial services of any kind. Please make sure that you do not offer such services on your site, as doing so may subject you to a ban.

    Quote
    • Your website will not offer banking, investment, credit/loans, or similar financial services, as our data center does not meet PCI DSS compliance or ISO/IEC 27001 certification.

     

  6. Backups for user LordSterben have been discarded and scheduled backups have been turned off to prevent the account from filling up again. If you want to use scheduled backups, please set up remote storage for them so the account doesn't fill up. 

    One backup from today has been left in place for you, and a backup of your account is also available via https://heliohost.org/backup/ if anything is missing.

     

×
×
  • Create New...