Jump to content

wolstech

Chief Risk Officer
  • Posts

    17,034
  • Joined

  • Last visited

  • Days Won

    617

Everything posted by wolstech

  1. The domain sunnylo.tk has been cleaned up. Try it now.
  2. Sure. Please make sure that the email addresses mentioned in the report receive no further emails from you. Also, you may want to move your email service entirely off our service (not just the smtp, but the MX as well). Unsuspended. It may take a few minutes to be effective.
  3. You must use cpanel to create a database, not phpmyadmin: https://tommy.heliohost.org:2083/frontend/paper_lantern/sql/index.html After creation, you can use phpmyadmin to import the data if you wish. This behavior is by design.
  4. Accounts getting hacked is almost always due to security issues in the software you use for your site. What program were you using? In the rare case it’s not software related, it’s a weak or compromised password (usually because the password used was previously used on another site, and that site was breached). We aren’t aware of any server security issues that would cause this and others aren’t reporting such issues, so it’s something specific to your account.
  5. Start by resetting your password: https://ricky.heliohost.org:2083/resetpass?start=1 Then log in and delete everything in your public_html folder. If you’re unable to reset your password, I can ban your hacked account and send you an invite for a replacement if you prefer. As for why it got hacked, were you running Wordpress?
  6. You're suspended for spam because we received abuse reports for your account. Can you explain where you're getting these email addresses and why your account is sending these emails? We actually received several reports regarding this. Note that unsolicited email advertising is against our terms of service (Spam). We have received a complaint about your account. Please investigate and fix within 24 hours. Hurricane Electric Abuse Department support@he.net From 7025422215.8d135594@bounces.spamcop.net Wed Jan 1 07:57:59 2020 Return-Path: <7025422215.8d135594@bounces.spamcop.net> X-Original-To: report@abuse.he.net Delivered-To: report@abuse.he.net Received: from he.net (he.net [216.218.186.2]) by abuse.he.net (Postfix) with ESMTPS id D4D2254018B for <report@abuse.he.net>; Wed, 1 Jan 2020 07:57:54 -0800 (PST) Authentication-Results: he.net; spf=pass (he.net: domain of bounces.spamcop.net designates 184.94.240.112 as permitted sender) smtp.mailfrom=7025422215.8d135594@bounces.spamcop.net; dmarc=none (Policy up to you. No DMARC record found) header.from=bounces.spamcop.net Received-SPF: pass (he.net: domain of bounces.spamcop.net designates 184.94.240.112 as permitted sender) client-ip=184.94.240.112; envelope-from=7025422215.8d135594@bounces.spamcop.net; helo=vmx.spamcop.net; Received: from vmx.spamcop.net ([184.94.240.112]) by he.net with ESMTPS (ECDHE-RSA-AES256-GCM-SHA384:TLSv1.2:Kx=ECDH:Au=RSA:Enc=AESGCM(256):Mac=AEAD) for <abuse@he.net>; Wed, 1 Jan 2020 07:57:01 -0800 IronPort-SDR: eeeDElfffZYCk46bGmwKz+wAoVOHTExiaMVWuotcYS6avkLq2DXKqM1jNhDahKmM/IZZg/rv68 NPpB1LcCqoQ+hbQ8ZpUr/2XVVKiVggeUFAOAfxfaQlAJ00Eq+CG/vaG9y/WGKfAzDhzsOeH/39 EHpNbxAZQd0N00jZ6B3GzGlcHSFzHk274BN54d+SEUn8QEWmIj2fNN8LQ/2mCO1WK8N6zwIQ8C AyHu9WH1L7BEWY1D0OE8TQbcvAy752rpmIbGjAYf5Hzgx9AT37tYhRnIOyluWk+2adfXoNT3Ex s7msmemqz4bVyUVNzcS67llO X-Corpus-CASE-Score: 0 Received: from prod-sc-www02.sv4.ironport.com (HELO prod-sc-www02.spamcop.net) ([10.8.129.226]) by prod-sc-smtp-vip.sv4.ironport.com with SMTP; 01 Jan 2020 07:57:25 -0800 Received: from [50.82.208.169] by spamcop.net with HTTP; Wed, 01 Jan 2020 15:57:18 GMT Content-Type: multipart/report; report-type=feedback-report; boundary="----------=_1577894238-29281-0" Content-Transfer-Encoding: 7bit MIME-Version: 1.0 Date: Wed, 1 Jan 2020 10:22:55 -0500 From: "Scott Ca" <7025422215@reports.spamcop.net> To: abuse@he.net Subject: [SpamCop (http://marketsquare.ga/?nltr=MjszOTQyO2h0dHA6Ly9tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMDZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi) id:7025422215]Are You Ready For 2020? Precedence: list Message-ID: <rid_7025422215@msgid.spamcop.net> X-Mailer: https://www.spamcop.net/ v5.1.0 X-Spamcop-Sourceip: 52.40.142.38 This is a multi-part message in MIME format... ------------=_1577894238-29281-0 Content-Type: text/plain; charset="charset=ISO-8859-1; format=flowed" Content-Disposition: inline Content-Transfer-Encoding: 7bit [ SpamCop V5.1.0 ] This message is brief for your comfort. Please use links below for details. Spamvertised web site: http://marketsquare.ga/?nltr=MjszOTQyO2h0dHA6Ly9tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMDZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi https://www.spamcop.net/w3m?i=z7025422215z8d135594661d0e287d7e16dbbd389a6cz http://marketsquare.ga/?nltr=MjszOTQyO2h0dHA6Ly9tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMDZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi is 64.62.211.134; Wed, 01 Jan 2020 15:56:47 GMT This is an email abuse report for an email message received from IP source 52.40.142.38 on Wed, 1 Jan 2020 10:22:55 -0500 For more information about this format please see http://www.mipassoc.org/arf/ To change ARF message format to SpamCop format change settings on your preferences page: https://www.spamcop.net/mcgi?action=showispprefs ------------=_1577894238-29281-0 Content-Type: message/feedback-report Content-Disposition: inline Content-Transfer-Encoding: 7bit Feedback-Type: abuse User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36 via https://www.spamcop.net Version: 0.1 Received-Date: Wed, 1 Jan 2020 10:22:55 -0500 Source-IP: 52.40.142.38 Reported-URI: http://marketsquare.ga/?nltr=MjszOTQyO2h0dHA6Ly9tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMDZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi https://www.spamcop.net/w3m?i=z7025422215z8d135594661d0e287d7e16dbbd389a6cz Reported-URI: http://marketsquare.ga/?nltr=MjszOTQyO2h0dHA6Ly9tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMDZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi ------------=_1577894238-29281-0 Content-Type: message/rfc822; Content-Disposition: inline Content-Transfer-Encoding: binary Return-Path: <bounces+14266955-8aaa-thematrix=mchsi.com@sendgrid.net> Received: from 10.0.16.107 (LHLO njtozpfv24.mcomdc.com) (10.0.16.107) by njtozcsv18.mcomdc.com with LMTP; Wed, 1 Jan 2020 10:22:55 -0500 (EST) Received: from localhost (localhost [127.0.0.1]) by njtozpfv24.mcomdc.com (Postfix) with ESMTP id 63A05C20604 for <x>; Wed, 1 Jan 2020 10:22:55 -0500 (EST) Authentication-Results: njtozpfv24.mcomdc.com (amavisd-new); dkim=pass (1024-bit key) header.d=sendgrid.net Received: from njtozpfv24.mcomdc.com ([127.0.0.1]) by localhost (njtozpfv24.mcomdc.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BDFAt-h8NQDu for <x>; Wed, 1 Jan 2020 10:22:55 -0500 (EST) Received: from mc-ibgw-6002a (mcib-6002a.a.cloudfilter.net [52.40.142.38]) by njtozpfv24.mcomdc.com (Postfix) with ESMTPS id 21E13C21339 for <x>; Wed, 1 Jan 2020 10:22:55 -0500 (EST) Received: from o1678912x138.outbound-mail.sendgrid.net ([167.89.12.138]) by Mediacom with ESMTP id mfnmiCZs9lYYwmfnmiOJ2f; Wed, 01 Jan 2020 15:20:51 +0000 X-DMARC-Result: norecord Authentication-Results: mc-ibgw-6002a; dkim=pass header.d=sendgrid.net header.b=p8CHRYFs X-Authority-Analysis: v=2.3 cv=HsUI5HbS c=1 sm=1 tr=0 b=1 cx=a_idp_d a=5zkuKTSi+vxa01fehmAhMQ==:117 a=5zkuKTSi+vxa01fehmAhMQ==:17 a=IkcTkHD0fZMA:10 a=MKtGQD3n3ToA:10 a=1oJP67jkp3AA:10 a=oHHRNoSmSjYA:10 a=TSPwzZGP2YIA:10 a=hT-1Ee4BNzoA:10 a=ZZnuYtJkoWoA:10 a=IfdI22zvAAAA:8 a=wKnMwA_nhrWWXe8zkCAA:9 a=fBwjSB-zLZpdSzoA:21 a=_W_S_7VecoQA:10 a=QEXdDO2ut3YA:10 a=-FEs8UIgK8oA:10 a=NWVoK91CQyQA:10 a=x3xeG5V1zmYPDWtXUAgM:22 cc=prm DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sendgrid.net; h=content-transfer-encoding:content-type:from:mime-version:subject: reply-to:list-unsubscribe:to; s=smtpapi; bh=J76odr8HaGRASszDVFyMzbjUUyE3wqZAA07t0IYce3Q=; b=p8CHRYFsVjwTcI5OD9TZCepcRb2rHZM3Zov9FcayZlD4FXufL5Ow1Suv1YTkPoUKxfTg n32YHmlxaAKhpJqKeML9M87vRUEPRGtDTctU//nq5p3yDh7PC1dBaQ7P/GL6+9yA9G4Ytk mfXeJGuq62zBu7POFQjT+BLpQ/RaSULW4= Received: by filterdrecv-p3las1-5bf99c48d-j57ff with SMTP id filterdrecv-p3las1-5bf99c48d-j57ff-19-5E0CABB4-3C 2020-01-01 14:24:52.723198055 +0000 UTC m=+1345148.362552245 Received: from MTQyNjY5NTU (unknown [64.62.211.134]) by ismtpd0032p1las1.sendgrid.net (SG) with HTTP id BBBs-lZ5QnmyUlc61_5ryg Wed, 01 Jan 2020 14:24:52.628 +0000 (UTC) Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 Date: Wed, 01 Jan 2020 14:24:52 +0000 (UTC) From: Jones Patel <jonespat@marketsquare.ml> Mime-Version: 1.0 Message-ID: 6c4c________________________7a28@marketsquare.ga Subject: Are You Ready For 2020? Reply-To: jonespat@marketsquare.ml X-Mailer: Postman SMTP 2.0.6 for WordPress (https://wordpress.org/plugins/post-smtp/) List-Unsubscribe: <http://marketsquare.ga/?na=u&nk=3942-eb7efc092a&nek=2-> Precedence: bulk X-Newsletter-Email-Id: 2 X-Auto-Response-Suppress: OOF, AutoReply X-SG-EID: =?us-ascii?Q?pDa052OsVGOiXR0bxjZEJ1ZC120rv7gl0bbi0+SNLUgRbDEpoDhvSvSba5I8p8?= =?us-ascii?Q?x0nlTjU=2F16UeMIdg0IfeJG72eCYxTpht3tIHBXP?= =?us-ascii?Q?2=2F=2FG9W+1sunQlfi1AQCzFwvR+WRTHE5XSnvuMs=2F?= =?us-ascii?Q?JqK1H33cjKaTn2118dqBPL3rGWZvV305sYPfTpG?= =?us-ascii?Q?khdDajncOKGDBF8s1iQ2GWY4CtBovb4WjwtpksV?= =?us-ascii?Q?aU6Cp0bW48NeN0Tzn3Z7eeE+itR+CSC16fCVbpl?= =?us-ascii?Q?dWA18h0kzbRB2NL45t9FQ=3D=3D?= To: x X-CMAE-Envelope: MS4wfDbtvPOR/wHhd5dOUzrg42nGusvT6AP7sUXAmoyj3pC8hphH5zFZcmyHu08a2WZb0/6Z7y40rZ9faKgyxBP5l9hlsTD86THB/xldFdHCLlEX9K5bQJgl daANBcaUvvCXAWzcVf1fV+z1XFqFva4g/lnac85IPW5C3nggUlhgmb5Melm/tOX66mnDhpVVaXTYJnLCIINd02sTo33S3MnKn+ZCEvOANSUxUDHdE7XjiL4b 0DyYr9dOiYMkc9u+LgmoVQ== <html> <head> <title></title> </head> <body> <p><span style=3D"font-family:georgia;"><strong><span style=3D"font-size:20= px;">500% growth in 6 months =E2=80=93 are you up for it?</span></strong></= span></p> <p><span style=3D"font-family:georgia;">Have you looked at your marketing a= nd sales objectives for this quarter, or this year, and noticed they requir= e one core element: growth. And wondered, how do I get from where where I a= m today to my goals? And how do I achieve growth like Uber, Slack, Shopify,= and Atlassian?</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;">Whether you=E2=80=99re in a hotly c= ompetitive market or have a blue ocean in front of you, both the strategy a= nd the tools you use will pave the way toward achieving your objectives. Bu= t all too often, the conversation around growth starts with a consideration= of tools instead of strategy.</span></p> <p>=C2=A0</p> <p style=3D"text-align: center;"><span style=3D"font-family:times new roman= ;"><span style=3D"color:#FFFFFF;"><span style=3D"font-size:36px;"><span sty= le=3D"background-color:#0000FF;">Growth is never by mere chance; it is the = result of forces working together.</span></span></span></span><br /> <span style=3D"font-family:georgia;"><em>JAMES CASH PENNEY</em><br /> Founder, JC Penney</span></p> <p style=3D"text-align: center;">=C2=A0</p> <p><span style=3D"font-family:georgia;">And that is why I am here to guide = you through the process of selecting tools and choosing what is essential f= or your marketing, and sales teams.</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;">Unless you=E2=80=99ll been hiding u= nder a rock, you=E2=80=99ll find a library of the best free tools and consi= derations when selecting a tool for any aspect of your business that fuels = your growth in my subsequent emails.</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;">They will cover everything from the= essential technology your marketing and sales teams should use, to exactly= what tools are working now (and what are not) so you don=E2=80=99t waste m= oney on tools that don=E2=80=99t work.</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;">In the next email, you will be gett= ing my most important website agency tools worth hundreds of dollars For Fr= ee.</span></p> <p><span style=3D"font-family:georgia;">Kind regards<br /> Jones Patel<br /> Digital Marketing Manager<br /> [HubSpot]</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;">PS: Don=E2=80=99t miss my next mail= .. BONUSES Will be added to it, remember to mark this email as important or = add to contact so you don=E2=80=99t miss out.</span></p> <p>=C2=A0</p> <p><span style=3D"font-family:georgia;"><p>However, if you feel the need to= unsubscribe, <a href=3D"http://marketsquare.ga/?nltr=3DMjszOTQyO2h0dHA6Ly9= tYXJrZXRzcXVhcmUuZ2EvP25hPXVjJm5rPTM5NDItZWI3ZWZjMDkyYSZuZWs9Mi07Ozc4MWRkMD= ZhNzZhZWMyNGZiMDZlNzI3ODIyYjgxMmRi">click here</a>.</span></p> <img width=3D"1" height=3D"1" alt=3D"" src=3D"http://marketsquare.ga/?noti= =3DMjszOTQyO2I0NGQ0MzBiNzQ1NGUzZTdlYWUwNjM2ZGVmZDY4YWJi"/></body> </html> ------------=_1577894238-29281-0--
  7. Try using this to reset it instead of our website. https://johnny.heliohost.org:2083/resetpass?start=1 Our website's password reset fails a lot, especially if the server has high load when you try it.
  8. Escalating. Do note that if you use a scheduled task on Lily, you can fix it yourself by simply editing the file it points to. You just won't be able to change the schedule yourself.
  9. These are Krydos questions. Node is very new, so not too much is documented on how it behaves here.
  10. That domain is not attached to the suspended account. It's attached to an active account called vfullnet as the main domain. Try changing the main domain of that account in order to remove it, or delete that account.
  11. Just put a blank index.php in there and users visiting the folder will see a blank page instead of a file listing. They would need to know the full path including filename to see anything. If you actually block access to it with something like htaccess, the users who do need to load those pictures as part of your site will be unable to do so.
  12. Lily has no user configuration for much of anything. I probably will have to create it for you once you upload the files. Just let me know the command to run and the schedule at which it should be run and I can schedule it. If your software will use pg though, you might just want to make a script that runs on Johnny. That way it's not dependent on both servers to work.
  13. Moving to tommy is basically night and day compared to Johnny's dismal performance. Johnny was down half of yesterday based on the charts...
  14. There's a limit of 4 concurrent connections since you're on Johnny. You will need to make your software use fewer connections, or you can move to tommy where there currently is no limit (though this may change if people abuse the mysql server there).
  15. This one is a Krydos question. I don't know of too many if anyone who has tried to make additional schemas in PG here, simply because almost nobody uses PG here. The pg_cron question you had is also best answered by Krydos: https://www.helionet.org/index/topic/38190-pg-cron-for-postgresql/?do=findComment&comment=169411 though I've responded there as well with a few alternate solutions. You're one of the first to really exercise some technologies we offer (especially ASP.NET), so lots of things to fix and adapt As for version, I doubt it. We generally have to use whatever versions cPanel offers to avoid breaking cPanel.
  16. Would a regular cron and a PHP script or regular program with code to carry out the task work? The SQL Server on Lily doesn't support scheduling either (the free version of SQL Server lacks this function). The servers do support cron (2 per day), and Lily supports scheduled tasks (currently no limit as long as the task is reasonable and doesn't hog the server).
  17. @sohamb03: A DNS issue won't cause a 500 error either. It'd cause a 404, or more likely, a queued page.
  18. Usually it's within 10. At this point though, it's sort of moot since your login issues were because you're suspended for having two accounts.
  19. He seems like he really wants benitez1, so the account jlbislas will be left suspended and benitez1 has been unsuspended. IP unblocked. And there's no way these aren't both his. He used an email address on the first account's domain to create the second account...
  20. I was on 7.1, but it was pre-rebuild. I haven't tried it myself since tommy got rebuilt since it's happily running on Lily on 7.3.
  21. Unblocked. It may take a few minutes to be effective. Also, if you use https://heliohost.org/login/ this won't happen to you.
  22. The Joomla updater doesn't work reliably on our service for some reason, probably something related to memory or execution time limits. Krydos might have an idea what causes it, but you're not alone. I moved my Joomla site to Lily for this exact reason...of course IIS has its own issues with updating Joomla, but nonetheless. Lets see if Krydos knows more about this. I'd be interested in getting this to work reliably. @sohmab03: DNS flush is not relevant here. He would not be able to access the site at all if that was the problem (a DNS flush is usually only needed if you moved servers).
  23. All of our servers experience this from time to time. If you need zero downtime, you'll need to buy a VPS or find another host. Tommy has by far the best uptime of the 3 shared hosting options though. Johnny is the worst and should be avoided if you need any sense of stable service (Johnny uptime is sometimes as little as 50%). I run several production websites on Tommy, and downtime of ~0-10 minutes a day is normal, generally due to load spikes (which are typically caused by other users abusing the server or running scripts that are broken...these self-correct when the server suspends the abusive account). The spikes usually last a few minutes each. For reference, take a look here: http://heliohost.grd.net.pl/monitor/ (Odds are you were trying to access your site during one of those orange/blue spots on the Tommy server load bar).
  24. To be more specific, this account was hosting a fake money transfer service. Fake financial service websites are prohibited, even if they're not actually stealing user information, and when found are subject to a phishing ban due to the associated security risks.
  25. That site is loading for me now. A bit slow, but it's working. If you need faster performance, moving to tommy is your best bet.
×
×
  • Create New...