Update 1 Sep 2007, 7AM: We have to arrange another time for the maintenance. Started accounts backup from 10:20PM last night till now, unfortunately it's still not completed yet. It would cause too long downtime (estimated 10 hours+) this way. We will find a better solution and arrange another time. Will keep you informed.
Please be informed that we are going to replace hard drives on Gold Server and implement hardware maintenance on this coming Friday night, 31st Aug 2007.
As you know, no hardware can last forever, so normally we replace HDD every 18-24 months on all servers as routine maintenance.
Now it's time for Gold Server.
Another reason that we decided to carry out hardware maintenance on Gold server now is that Gold server has been having hardware problems this month. Our investigation shows that possible causes include:
1)HDD bad sectors
2)Kernel bug
3)BIOS needs to be updated
4)Combination of above
To be honest, hardware failure is unavoidable as you can understand, but the worst thing this time is the bad timing.
Our original plan was to move as much accounts as possible to new server before we change HDD to avoid or reduce service disruption. However, the new server ordered has not been delivered till now and we don't expect it to arrive in next 1 or 2 days.
We simply cannot wait anymore considering current situation. So we decided to go ahead ASAP.
But, updating BIOS is a bit risky. If anything went wrong, the whole server would be spoiled and become useless. In it did happen, we must change the whole server. Therefore we bought a server from other hosting company, at rather high cost.
Please rest assured, we will try our best to complete the maintenance and keep servers in good shape.
The hardware maintenance for Gold Server is scheduled on 31st, Aug 2007, from around 11PM to 5AM next morning, 1st, Sep 2007 .
Expected downtime is 6 hours while we replace HDD, install OS, update BIOS/kernel. Hopefully it will be shorter if everything goes smoothly, but it might be longer.
You can check which server your account is on via IP address:
http://sghosting.blogspot.com/2005/05/how-do-i-know-which-server-my-site-is.html
Sorry for inconvenience caused and thank you for your kind understanding.
30 August, 2007
02 August, 2007
Problem with Gold Server
Update 12:20PM 29 Aug: It's up now. I know this is unacceptable to have same issue 3 times in one month. This is the worst case we have had in past few years. We're working on compensation plan for clients on Gold server. And most importantly, we will do hardware maintenance asap. More details will be posted when schedule is confirmed. Sorry for the downtime and trouble caused to users.
Update 11:50AM, 29 Aug: Gold server is having same issue again now. We know it's bad. We'll bring it up and update here.
Update 3pm, 21 Aug: Gold server is up now. We're investigating. Will update here if further action/maintenance is needed.
Update on 21 Aug: Gold server is having problem again today from around 11am. We're trying our best to bring it back asap. Sorry for the trouble. Will update here once we have further news.
Dear Customer,
There was problem on Gold server this morning and we managed to bring it up at around 1:55pm. Sadly while we were investigating further on the server, it went down again. Our server admin is on the way to datacenter to troubleshoot.
Very sorry for the inconvenience caused. We will try our best to bring it back as soon as possible.
Thank you for your kind understanding.
Update: It's up at around 5:50pm
There might be problem with hard disk or kernel, we will investigate to see if it's hard disk, if so, we will have to change HDD as soon as possible, most likely tonight or tomorrow night.
Therefore, unfortunately, there might be urgent HDD maintenance and downtime tonight or tomorrow night. We'll make announcement to all clients and post updates here.
Clients on Gold server, please do NOT do backup or upload anything until maintenance is complete.
Again, sorry for inconvenience and thank you for understanding.
Update 11:50AM, 29 Aug: Gold server is having same issue again now. We know it's bad. We'll bring it up and update here.
Update 3pm, 21 Aug: Gold server is up now. We're investigating. Will update here if further action/maintenance is needed.
Update on 21 Aug: Gold server is having problem again today from around 11am. We're trying our best to bring it back asap. Sorry for the trouble. Will update here once we have further news.
Dear Customer,
There was problem on Gold server this morning and we managed to bring it up at around 1:55pm. Sadly while we were investigating further on the server, it went down again. Our server admin is on the way to datacenter to troubleshoot.
Very sorry for the inconvenience caused. We will try our best to bring it back as soon as possible.
Thank you for your kind understanding.
Update: It's up at around 5:50pm
There might be problem with hard disk or kernel, we will investigate to see if it's hard disk, if so, we will have to change HDD as soon as possible, most likely tonight or tomorrow night.
Therefore, unfortunately, there might be urgent HDD maintenance and downtime tonight or tomorrow night. We'll make announcement to all clients and post updates here.
Clients on Gold server, please do NOT do backup or upload anything until maintenance is complete.
Again, sorry for inconvenience and thank you for understanding.
24 July, 2007
Go PHP 5
Dear Customers:
We will soon be dropping support for PHP version 4 since PHP developers will discontinue PHP 4 by end of this year.
More details can be read at:
http://gophp5.org/
Please do read details at above site.
PHP officially announced "PHP 4 end of life" on 13 July 2007:
http://www.php.net/
-----------------------------
[13-Jul-2007]
Today it is exactly three years ago since PHP 5 has been released. In those three years it has seen many improvements over PHP 4. PHP 5 is fast, stable & production-ready and as PHP 6 is on the way, PHP 4 will be discontinued.
The PHP development team hereby announces that support for PHP 4 will continue until the end of this year only. After 2007-12-31 there will be no more releases of PHP 4.4. We will continue to make critical security fixes available on a case-by-case basis until 2008-08-08. Please use the rest of this year to make your application suitable to run on PHP 5.
------------------------------
So, kindly make sure all your PHP applications/scripts are version 5 compatible ASAP. We only have less than 160 days to plan for the upgrading. To play safe, we will most likely upgrade before the deadline.
For documentation on migration for PHP 4 to PHP 5, please refer to PHP migration guide:
http://www.php.net/manual/en/migration5.php
In the past few years, like most of the web hosting providers, we did not upgrade to PHP 5 due to compatibility issues between PHP 4 and 5, but now all of us are forced to upgrade.
No choice, let's move forward together.
Please check your PHP scripts and make sure it's PHP5 compatible.
P.S. We are not able to check your PHP scripts as we know nothing about it. Please check with your web designer/programmer.
We will soon be dropping support for PHP version 4 since PHP developers will discontinue PHP 4 by end of this year.
More details can be read at:
http://gophp5.org/
Please do read details at above site.
PHP officially announced "PHP 4 end of life" on 13 July 2007:
http://www.php.net/
-----------------------------
[13-Jul-2007]
Today it is exactly three years ago since PHP 5 has been released. In those three years it has seen many improvements over PHP 4. PHP 5 is fast, stable & production-ready and as PHP 6 is on the way, PHP 4 will be discontinued.
The PHP development team hereby announces that support for PHP 4 will continue until the end of this year only. After 2007-12-31 there will be no more releases of PHP 4.4. We will continue to make critical security fixes available on a case-by-case basis until 2008-08-08. Please use the rest of this year to make your application suitable to run on PHP 5.
------------------------------
So, kindly make sure all your PHP applications/scripts are version 5 compatible ASAP. We only have less than 160 days to plan for the upgrading. To play safe, we will most likely upgrade before the deadline.
For documentation on migration for PHP 4 to PHP 5, please refer to PHP migration guide:
http://www.php.net/manual/en/migration5.php
In the past few years, like most of the web hosting providers, we did not upgrade to PHP 5 due to compatibility issues between PHP 4 and 5, but now all of us are forced to upgrade.
No choice, let's move forward together.
Please check your PHP scripts and make sure it's PHP5 compatible.
P.S. We are not able to check your PHP scripts as we know nothing about it. Please check with your web designer/programmer.
15 June, 2007
EXPAN: Urgent Maintenance for UPS & Incident Report for COM3 Level2 UPS Interruption
Dear Customers,
Just received "Urgent Maintenance for UPS & Incident Report for COM3 Level2 UPS Interruption" from Singtel EXPAN. There was UPS fault yesterday afternoon and at this moment (1:00pm) there was problem again.
We are trying our best to get servers back online ASAP. Sorry for the inconvenience.
As indicated in their urgent notice, there will be urgent maintenance activities required for UPS 2-3 & 2-4 on the following date/ time:
Date/ Time: 17/06/07, SGT 1pm to SGT 3pm
Sorry for the late notice as we just received the notice from EXPAN.
Extract from PDF file from EXPAN:
---------------------------------------------------------
Interim IR - Com III UPS Interruption - 14Jun07.doc 1
Restricted only when filled completely
Unless indicated, document is “Uncontrolled” when printed.
Interim Incident Report
Items
Descriptions
Remarks
Reported by:
SINGTEL EXPAN Operations
Site:
COM III Data Center, Level 2
Date of incident:
14/06/2007
Time occurred:
1414hrs
Date/Time Reported:
14/06/2007 at 1414hrs
Date/Time Resolved:
14/06/2007 at 1416hrs
Review by:
Problem Descriptions:
14 June 2007
1414hrs – UPS fault alerts for UPS 2-3 and 2-4 were received by NOC. UPS 2-3 & 2-4 provide power to equipments hosted in COM III, Level 2 EXPAN Data Centre.
1415hrs – Onsite UPS engineer was activated immediately to check on the UPS.
1416hrs – UPS power was restored.
Findings:
Review of the UPS logs shows that UPS 2-3 and 2-4 inverters were off at 14:14:41hrs and 14:14:42hrs respectively and the load was not transferred to static bypass source. The PCB controller (Control and Communication board) is determined to be faulty.
Immediate Resolution:
Immediate resolution to prevent the UPS from going offline is to replace the PCB controller:
1. 2 hrs maintenance window is required
2. Customer loads will be transferred to External bypass source so that replacement of the faulty PCB controller (Control and Communication board) and a complete test of the UPS systems can be carried out.
3. Customer loads on External bypass source will be supported by Raw power source during the maintenance period.
4. Due to the faulty PCB controller, there will be a power disruption of up to 10mins when the transfer of load to external bypass is performed.
5. The proposed maintenance window will be scheduled as stated below:
Date/ Time: 17/06/07, SGT 1pm to SGT 3pm
Recommendations to customer:
1. Customer is required to shutdown all their equipments before commencement of the maintenance window before SGT 1pm. (For those whom have subscribed to manage system services, Singtel will assist in the shut down of equipments on 17/06/07, starting from SGT 11.30am)
2. Once the faulty UPS parts are replaced and complete testing of the UPS systems are carried out, SingTel will inform customer via email/ phone to start up their equipments.
Interim IR - Com III UPS Interruption - 14Jun07.doc 2
Restricted only when filled completely
Unless indicated, document is “Uncontrolled” when printed.
3. After the maintenance is completed, customer is required to start-up all their equipments. (For those whom have subscribed to manage system services, Singtel will assist in the start-up process.)
Remarks:
Feel free to contact us should you require further clarification.
We sincerely apologized for the inconvenience cause.
--------------------------------------------------------
Will keep you updated.
Update: all servers are up by 2:10pm
Again, pls note there will be maintenance on 17/06/07, SGT 1pm to SGT 3pm
Just received "Urgent Maintenance for UPS & Incident Report for COM3 Level2 UPS Interruption" from Singtel EXPAN. There was UPS fault yesterday afternoon and at this moment (1:00pm) there was problem again.
We are trying our best to get servers back online ASAP. Sorry for the inconvenience.
As indicated in their urgent notice, there will be urgent maintenance activities required for UPS 2-3 & 2-4 on the following date/ time:
Date/ Time: 17/06/07, SGT 1pm to SGT 3pm
Sorry for the late notice as we just received the notice from EXPAN.
Extract from PDF file from EXPAN:
---------------------------------------------------------
Interim IR - Com III UPS Interruption - 14Jun07.doc 1
Restricted only when filled completely
Unless indicated, document is “Uncontrolled” when printed.
Interim Incident Report
Items
Descriptions
Remarks
Reported by:
SINGTEL EXPAN Operations
Site:
COM III Data Center, Level 2
Date of incident:
14/06/2007
Time occurred:
1414hrs
Date/Time Reported:
14/06/2007 at 1414hrs
Date/Time Resolved:
14/06/2007 at 1416hrs
Review by:
Problem Descriptions:
14 June 2007
1414hrs – UPS fault alerts for UPS 2-3 and 2-4 were received by NOC. UPS 2-3 & 2-4 provide power to equipments hosted in COM III, Level 2 EXPAN Data Centre.
1415hrs – Onsite UPS engineer was activated immediately to check on the UPS.
1416hrs – UPS power was restored.
Findings:
Review of the UPS logs shows that UPS 2-3 and 2-4 inverters were off at 14:14:41hrs and 14:14:42hrs respectively and the load was not transferred to static bypass source. The PCB controller (Control and Communication board) is determined to be faulty.
Immediate Resolution:
Immediate resolution to prevent the UPS from going offline is to replace the PCB controller:
1. 2 hrs maintenance window is required
2. Customer loads will be transferred to External bypass source so that replacement of the faulty PCB controller (Control and Communication board) and a complete test of the UPS systems can be carried out.
3. Customer loads on External bypass source will be supported by Raw power source during the maintenance period.
4. Due to the faulty PCB controller, there will be a power disruption of up to 10mins when the transfer of load to external bypass is performed.
5. The proposed maintenance window will be scheduled as stated below:
Date/ Time: 17/06/07, SGT 1pm to SGT 3pm
Recommendations to customer:
1. Customer is required to shutdown all their equipments before commencement of the maintenance window before SGT 1pm. (For those whom have subscribed to manage system services, Singtel will assist in the shut down of equipments on 17/06/07, starting from SGT 11.30am)
2. Once the faulty UPS parts are replaced and complete testing of the UPS systems are carried out, SingTel will inform customer via email/ phone to start up their equipments.
Interim IR - Com III UPS Interruption - 14Jun07.doc 2
Restricted only when filled completely
Unless indicated, document is “Uncontrolled” when printed.
3. After the maintenance is completed, customer is required to start-up all their equipments. (For those whom have subscribed to manage system services, Singtel will assist in the start-up process.)
Remarks:
Feel free to contact us should you require further clarification.
We sincerely apologized for the inconvenience cause.
--------------------------------------------------------
Will keep you updated.
Update: all servers are up by 2:10pm
Again, pls note there will be maintenance on 17/06/07, SGT 1pm to SGT 3pm
01 June, 2007
Scheduled Maintenance on Platinum Server
Please be informed that we are going to replace hard drives on Platinum Server on this coming Sunday, 3rd June 2007.
As you know, no hardware can last forever, so normally we replace HDD every 18-24 months on all servers as routine maintenance.
Now it's time for Platinum Server.
The hard drive replacement for Platinum Server is scheduled on 3rd June 2007, starting from around 10PM-11PM.
There will be around 4 hours of downtime while we replace HDD and install new OS.
You can check which server your account is on via IP address:
http://sghosting.blogspot.com/2005/05/how-do-i-know-which-server-my-site-is.html
Sorry for inconvenience caused and thank you for your kind understanding.
As you know, no hardware can last forever, so normally we replace HDD every 18-24 months on all servers as routine maintenance.
Now it's time for Platinum Server.
The hard drive replacement for Platinum Server is scheduled on 3rd June 2007, starting from around 10PM-11PM.
There will be around 4 hours of downtime while we replace HDD and install new OS.
You can check which server your account is on via IP address:
http://sghosting.blogspot.com/2005/05/how-do-i-know-which-server-my-site-is.html
Sorry for inconvenience caused and thank you for your kind understanding.
12 March, 2007
SingTel EXPAN ComCenter III Level 2 Power Outage Report
Following are the details sent by SingTel EXPAN datacentre (where our servers are located) regarding the power outage on 11 Mar 2007:
Circuit: SGGS001
Date/Time (SGT): 11/03/2007 0045
Date/Time (UTC): 10/03/2007 2045
Duration: 5 seconds
Reason: Failure of Static Transfer Switch board on UPS system.
Impact: Customers equipment in level 2 data center might experienced power disruption / server rebooting.
Action Taken: UPS Engineers are on-site for investigation & recovery work.
We apologize for the inconvenience caused to your operations.
Circuit: SGGS001
Date/Time (SGT): 11/03/2007 0045
Date/Time (UTC): 10/03/2007 2045
Duration: 5 seconds
Reason: Failure of Static Transfer Switch board on UPS system.
Impact: Customers equipment in level 2 data center might experienced power disruption / server rebooting.
Action Taken: UPS Engineers are on-site for investigation & recovery work.
We apologize for the inconvenience caused to your operations.
28 December, 2006
Taiwan quake cuts off much of Asia Internet
If you experience connection problem with your web site or email, please read the news below. Let's all pray...
Update 29 Dec 2006 12:40PM:
Looks like things are getting better slowly, but still very unstable, especially users outside of Singapore or Asia may still experience problems every now and then at some locations in next few days.
http://news.yahoo.com/s/ap/20061227/ap_on_re_as/asia_quake
http://www.channelnewsasia.com/stories/afp_asiapacific/view/249389/1/.html
http://news.bbc.co.uk/2/hi/asia-pacific/6211451.stm
Here's the story I copy/paste from ChannelNewsAsia if you cannot access above link:
Taiwan quake cuts off much of Asia Internet
Posted: 27 December 2006 1840 hrs
HONG KONG - Internet and phone services were disrupted across much of Asia on Wednesday after an earthquake damaged undersea cables, leaving one of the world's most tech-savvy regions in a virtual blackout.
From frustrated traders seeking in vain for stock quotes to anxious newshounds accustomed to round-the-clock updates on world events, millions of people from China to Japan to Australia were affected.
The disruption was widespread, hitting China, Japan, South Korea, Taiwan, Singapore, Thailand, Malaysia, Hong Kong and elsewhere, with knock-on effects as far away as Australia for companies whose Internet is routed through affected areas.
There was no chaos on the stock exchanges or any of the other doomsday scenarios, but reports that services could be down for weeks were dramatic enough.
South Korea's information and communication ministry said all six undersea fibreoptic cables off Taiwan were hit, causing major disruption. All services, except for exclusive business lines, returned to normal shortly afterwards as they were switched to other systems.
But officials could not put a timeframe on when business lines would be fixed. "It is not a matter of days," said Hong Seoung-Yong, a ministry official handling the problem. "It will take longer than that to repair the damaged lines."
A 7.1-magnitude earthquake off the coast of Taiwan on Tuesday night, which was followed by several smaller quakes in the region, apparently damaged the vast network of underwater cables that enables modern communication.
"The Internet capacity in Taiwan is about 40 percent now, so the service is jammed," said a spokesman for Chunghwa Telecom, Taiwan's largest phone company.
A spokesman for CAT Telecom, Thailand's communication authority, said Internet services had been disrupted across the country.
"Those whose businesses mainly rely on Internet communication have been affected. They can't do anything," he added.
Phone services in some countries were also disrupted, in particular for calls to the United States.
"Several undersea data cables were damaged," said a spokesman for PCCW, Hong Kong's biggest telecoms company.
Service providers quickly tried to redirect customers to the cables that had not been affected but the reduced capacity was no match for the normal workload of users, leaving an Internet service that was painfully slow or non-existent.
"It's a nightmare, basically, because we have no idea what is going on in the markets today," said Steve Rowles, an analyst with CFC Seymour in Hong Kong, who echoed others in saying that damage was limited due to year's end.
"It has happened on the right day as a lot of people are away for holidays, so there's low trading volumes," he said.
In China, web users in cities as far apart as Beijing in the north and Chongqing in the southwest reported difficulties accessing overseas websites, state media reported, after several undersea cables belonging to China Telecom were cut.
The Tokyo Stock Exchange, the world's largest bourse outside of New York, was functioning without problems, a spokesman said.
The Hong Kong stock exchange also said it was also working without problems, but after-hours crude trading in Singapore was affected as traders reported they could not access the New York Mercantile Exchange (Nymex).
NTT Communications, the long-distance call business of Japan's largest telecom firm Nippon Telegraph and Telephone Corp., said 1,400 toll-free phone lines and 84 international lines used internally by companies were affected.
The crux of the trouble seemed to be in the underseas routes near Taiwan, which providers would try to bypass in favour of other routes through Europe, said a spokesman for Japanese telecoms firm KDDI Corp, Satoru Ito.
"If there is too much traffic on that route, it might get blocked up and further slow down Internet connections," Ito said.
- AFP /ls
Update 29 Dec 2006 12:40PM:
Looks like things are getting better slowly, but still very unstable, especially users outside of Singapore or Asia may still experience problems every now and then at some locations in next few days.
http://news.yahoo.com/s/ap/20061227/ap_on_re_as/asia_quake
http://www.channelnewsasia.com/stories/afp_asiapacific/view/249389/1/.html
http://news.bbc.co.uk/2/hi/asia-pacific/6211451.stm
Here's the story I copy/paste from ChannelNewsAsia if you cannot access above link:
Taiwan quake cuts off much of Asia Internet
Posted: 27 December 2006 1840 hrs
HONG KONG - Internet and phone services were disrupted across much of Asia on Wednesday after an earthquake damaged undersea cables, leaving one of the world's most tech-savvy regions in a virtual blackout.
From frustrated traders seeking in vain for stock quotes to anxious newshounds accustomed to round-the-clock updates on world events, millions of people from China to Japan to Australia were affected.
The disruption was widespread, hitting China, Japan, South Korea, Taiwan, Singapore, Thailand, Malaysia, Hong Kong and elsewhere, with knock-on effects as far away as Australia for companies whose Internet is routed through affected areas.
There was no chaos on the stock exchanges or any of the other doomsday scenarios, but reports that services could be down for weeks were dramatic enough.
South Korea's information and communication ministry said all six undersea fibreoptic cables off Taiwan were hit, causing major disruption. All services, except for exclusive business lines, returned to normal shortly afterwards as they were switched to other systems.
But officials could not put a timeframe on when business lines would be fixed. "It is not a matter of days," said Hong Seoung-Yong, a ministry official handling the problem. "It will take longer than that to repair the damaged lines."
A 7.1-magnitude earthquake off the coast of Taiwan on Tuesday night, which was followed by several smaller quakes in the region, apparently damaged the vast network of underwater cables that enables modern communication.
"The Internet capacity in Taiwan is about 40 percent now, so the service is jammed," said a spokesman for Chunghwa Telecom, Taiwan's largest phone company.
A spokesman for CAT Telecom, Thailand's communication authority, said Internet services had been disrupted across the country.
"Those whose businesses mainly rely on Internet communication have been affected. They can't do anything," he added.
Phone services in some countries were also disrupted, in particular for calls to the United States.
"Several undersea data cables were damaged," said a spokesman for PCCW, Hong Kong's biggest telecoms company.
Service providers quickly tried to redirect customers to the cables that had not been affected but the reduced capacity was no match for the normal workload of users, leaving an Internet service that was painfully slow or non-existent.
"It's a nightmare, basically, because we have no idea what is going on in the markets today," said Steve Rowles, an analyst with CFC Seymour in Hong Kong, who echoed others in saying that damage was limited due to year's end.
"It has happened on the right day as a lot of people are away for holidays, so there's low trading volumes," he said.
In China, web users in cities as far apart as Beijing in the north and Chongqing in the southwest reported difficulties accessing overseas websites, state media reported, after several undersea cables belonging to China Telecom were cut.
The Tokyo Stock Exchange, the world's largest bourse outside of New York, was functioning without problems, a spokesman said.
The Hong Kong stock exchange also said it was also working without problems, but after-hours crude trading in Singapore was affected as traders reported they could not access the New York Mercantile Exchange (Nymex).
NTT Communications, the long-distance call business of Japan's largest telecom firm Nippon Telegraph and Telephone Corp., said 1,400 toll-free phone lines and 84 international lines used internally by companies were affected.
The crux of the trouble seemed to be in the underseas routes near Taiwan, which providers would try to bypass in favour of other routes through Europe, said a spokesman for Japanese telecoms firm KDDI Corp, Satoru Ito.
"If there is too much traffic on that route, it might get blocked up and further slow down Internet connections," Ito said.
- AFP /ls
03 August, 2006
register_globals disabled
Due to recent vulnerabilities for varies php web applications making full use of register_globals enabled, we have disabled register_globals on all our Unix/Linux servers on 20 July 2006.
Part of the past exploits found making use of register_globals or as one of the causes are as below:
PmWiki Unregister "register_globals" Layer Bypass -
http://secunia.com/advisories/18634/
phpMyAdmin register_globals Emulation "import_blacklist" Manipulation -
http://secunia.com/advisories/17925/
Mambo "register_globals" Emulation Layer Overwrite Vulnerability -
http://secunia.com/advisories/17622/
phpSysInfo "register_globals" Emulation Layer Overwrite Vulnerability -
http://secunia.com/advisories/17441/
Mambo / Joomla perForms "mosConfig_absolute_path" File Inclusion -
http://secunia.com/advisories/21044/
CzarNews "tpath" File Inclusion Vulnerability -
http://secunia.com/advisories/21038/
Phorum Cross-Site Scripting and Local File Inclusion -
http://secunia.com/advisories/21043/
Mambo SiteMap Component File Inclusion Vulnerability -
http://secunia.com/advisories/21055/
Joomla com_hashcash Component File Inclusion Vulnerability -
http://secunia.com/advisories/21053/
Pivot Multiple Vulnerabilities -
http://secunia.com/advisories/20962/
Mambo PccookBook Component File Inclusion Vulnerability -
http://secunia.com/advisories/21015/
Mambo SimpleBoard Component "sbp" File Inclusion Vulnerability -
http://secunia.com/advisories/20981/
Mambo Galleria Module "mosConfig_absolute_path" File Inclusion -
http://secunia.com/advisories/20949/
phpRaid SQL Injection and File Inclusion Vulnerabilities -
http://secunia.com/advisories/20200/
phpRaid SQL Injection and File Inclusion Vulnerabilities -
http://secunia.com/advisories/20865/
Pearl Products File Inclusion Vulnerabilities -
http://secunia.com/advisories/20819/
Mambo MOD_CBSMS Module File Inclusion Vulnerability -
http://secunia.com/advisories/20823/
Qdig Cross-Site Scripting Vulnerabilities -
http://secunia.com/advisories/20808/
phpBB THoRCMS Add-On "phpbb_root_path" File Inclusion -
http://secunia.com/advisories/20815/
Bee-hive Lite Multiple File Inclusion Vulnerabilities -
http://secunia.com/advisories/20814/
BandSite CMS "root_path" File Inclusion Vulnerabilities -
http://secunia.com/advisories/20768/
More such can be found at
http://secunia.com/search/?search=register_globals
Security is always our first priority.
By disabling register_globals, only those php web applications that were written with no code security in mind therefore depend on it will be affected.
There is a work around to have it enabled per site/directory basis by uploading the .htaccess file with the following content to the directory/site:
----------------------------------------
php_value register_globals 1
----------------------------------------
However please note enabling register_globals would open security hole for your application.
No matter where/how you get your script/application, written by your programmer, installed from cpanel, downloaded or bought from somewhere... please make sure your application is up to date and secure. Upgrade your application whenever there's new release.
We will not hesitate to remove any script affected/exploited immediately without notice.
Thank you for your attention.
Part of the past exploits found making use of register_globals or as one of the causes are as below:
PmWiki Unregister "register_globals" Layer Bypass -
http://secunia.com/advisories/18634/
phpMyAdmin register_globals Emulation "import_blacklist" Manipulation -
http://secunia.com/advisories/17925/
Mambo "register_globals" Emulation Layer Overwrite Vulnerability -
http://secunia.com/advisories/17622/
phpSysInfo "register_globals" Emulation Layer Overwrite Vulnerability -
http://secunia.com/advisories/17441/
Mambo / Joomla perForms "mosConfig_absolute_path" File Inclusion -
http://secunia.com/advisories/21044/
CzarNews "tpath" File Inclusion Vulnerability -
http://secunia.com/advisories/21038/
Phorum Cross-Site Scripting and Local File Inclusion -
http://secunia.com/advisories/21043/
Mambo SiteMap Component File Inclusion Vulnerability -
http://secunia.com/advisories/21055/
Joomla com_hashcash Component File Inclusion Vulnerability -
http://secunia.com/advisories/21053/
Pivot Multiple Vulnerabilities -
http://secunia.com/advisories/20962/
Mambo PccookBook Component File Inclusion Vulnerability -
http://secunia.com/advisories/21015/
Mambo SimpleBoard Component "sbp" File Inclusion Vulnerability -
http://secunia.com/advisories/20981/
Mambo Galleria Module "mosConfig_absolute_path" File Inclusion -
http://secunia.com/advisories/20949/
phpRaid SQL Injection and File Inclusion Vulnerabilities -
http://secunia.com/advisories/20200/
phpRaid SQL Injection and File Inclusion Vulnerabilities -
http://secunia.com/advisories/20865/
Pearl Products File Inclusion Vulnerabilities -
http://secunia.com/advisories/20819/
Mambo MOD_CBSMS Module File Inclusion Vulnerability -
http://secunia.com/advisories/20823/
Qdig Cross-Site Scripting Vulnerabilities -
http://secunia.com/advisories/20808/
phpBB THoRCMS Add-On "phpbb_root_path" File Inclusion -
http://secunia.com/advisories/20815/
Bee-hive Lite Multiple File Inclusion Vulnerabilities -
http://secunia.com/advisories/20814/
BandSite CMS "root_path" File Inclusion Vulnerabilities -
http://secunia.com/advisories/20768/
More such can be found at
http://secunia.com/search/?search=register_globals
Security is always our first priority.
By disabling register_globals, only those php web applications that were written with no code security in mind therefore depend on it will be affected.
There is a work around to have it enabled per site/directory basis by uploading the .htaccess file with the following content to the directory/site:
----------------------------------------
php_value register_globals 1
----------------------------------------
However please note enabling register_globals would open security hole for your application.
No matter where/how you get your script/application, written by your programmer, installed from cpanel, downloaded or bought from somewhere... please make sure your application is up to date and secure. Upgrade your application whenever there's new release.
We will not hesitate to remove any script affected/exploited immediately without notice.
Thank you for your attention.
12 March, 2006
EXPAN Down
The datacenter we locate our Linux servers, Singtel EXPAN, went down from around 2:10AM. Basically all EXPAN network down. Many web sites in Singapore affected, not only ours.
Will monitor and post here.
Update at 5:22am: 3 hours and still counting. This must be something screwed up big time in Singtel. All servers housed in EXPAN are not accessable.
Update at 5:45am: it's up now. Waiting for explanation from EXPAN.
Will monitor and post here.
Update at 5:22am: 3 hours and still counting. This must be something screwed up big time in Singtel. All servers housed in EXPAN are not accessable.
Update at 5:45am: it's up now. Waiting for explanation from EXPAN.
20 December, 2005
Update of Network Problem on 19/12/2005
First of all, service is back to normal. We've beening monitoring and working on it from yesterday afternoon til this morning, all servers have been stable.
Sorry for the trouble, frustration, waiting, complaints, etc. caused by the downtime, and thank you for your patience and kind understanding.
The service interruption was caused by our network provider's issue with SingTel. As most hosting providers do, we had been using 2nd tier network provider's service til yesterday. After quick but careful consideration and discussion, we decided to go with SingTel directly, instead of waiting for the network provider to solve their problem or moving to another 2nd tier provider.
Going with SingTel directly would triple our cost, that's why very few hosting provider is doing this. However we decided to do so in order to secure our business. We do not want our services affected when our provider has problem.
Hosting fee for all existing clients would remain the same, but we have to increase hosting fee for new clients. So please don't be surprised if you see pricing change on our web site, it would not affect existing clients.
All Unix servers were brought back up at around 4PM yesterday afternoon. There were still short interruptions after 4PM til midnight because there were lots of routing, IP, switching, etc. that we had to do.
We understand the downtime had caused lots of troubles to our clients, we sincerely apologise. And sorry if we have yet replied your email or did not answer your phonecall, please understand our first priority is to bring the servers back to normal.
Now situation has been stable for quite a few hours. We will do our best to provide more secure, stable services.
We'll keep you informed.
Last but not least, if your domain is NOT using our nameservers, you have to ask your DNS host to update your domain A record and/or MX record to our new IP address ASAP:
If your account is on 203.124.122.60 (Silver Server), please change to 203.175.160.76
If your account is on 203.124.122.93 (Platinum Server), please change to 203.175.160.84
If your account is on 203.124.122.117 (Gold Server), please change to 203.175.160.100
Sorry for the trouble, frustration, waiting, complaints, etc. caused by the downtime, and thank you for your patience and kind understanding.
The service interruption was caused by our network provider's issue with SingTel. As most hosting providers do, we had been using 2nd tier network provider's service til yesterday. After quick but careful consideration and discussion, we decided to go with SingTel directly, instead of waiting for the network provider to solve their problem or moving to another 2nd tier provider.
Going with SingTel directly would triple our cost, that's why very few hosting provider is doing this. However we decided to do so in order to secure our business. We do not want our services affected when our provider has problem.
Hosting fee for all existing clients would remain the same, but we have to increase hosting fee for new clients. So please don't be surprised if you see pricing change on our web site, it would not affect existing clients.
All Unix servers were brought back up at around 4PM yesterday afternoon. There were still short interruptions after 4PM til midnight because there were lots of routing, IP, switching, etc. that we had to do.
We understand the downtime had caused lots of troubles to our clients, we sincerely apologise. And sorry if we have yet replied your email or did not answer your phonecall, please understand our first priority is to bring the servers back to normal.
Now situation has been stable for quite a few hours. We will do our best to provide more secure, stable services.
We'll keep you informed.
Last but not least, if your domain is NOT using our nameservers, you have to ask your DNS host to update your domain A record and/or MX record to our new IP address ASAP:
If your account is on 203.124.122.60 (Silver Server), please change to 203.175.160.76
If your account is on 203.124.122.93 (Platinum Server), please change to 203.175.160.84
If your account is on 203.124.122.117 (Gold Server), please change to 203.175.160.100
19 December, 2005
Network Problem 19/12/2005 2PM
Update: All servers are up now. We're still working on the servers and routers, there might be interruptions while we're working on it. We'll email all clients when it's settled down. 19/12/2005 4pm.
Our network provider is having network problem, Unix servers are not accessable at this moment 19/12/2005 2PM. Our technical guy is in datacenter. We're trying our best to solve the problem ASAP.
Will update you when there's further news.
Sorry for inconvenience caused and we seek your kind understanding.
Our network provider is having network problem, Unix servers are not accessable at this moment 19/12/2005 2PM. Our technical guy is in datacenter. We're trying our best to solve the problem ASAP.
Will update you when there's further news.
Sorry for inconvenience caused and we seek your kind understanding.
14 October, 2005
Unix Server Cpanel Update - Emails May Affected
All clients, please be informed that we just updated all our Unix (cPanel) servers at around 11:30pm 13th Oct 2005:
(1) Switch uwimap server to courier-imap server. Why? Security!!! Please read it at: http://secunia.com/advisories/17062/
(2) Update cPanel RELEASE BUILD to version 10.8.0-RELEASE_65
For this particular update, there are some issues might occur as below:
(a) Email users using Client Email Program such as Outlook Express might encounter re-downloading all the past mails. This is due to cPanel changed support for mailbox format from mbox to maildir.
(b) NeoMail won't be working after the switch from mbox format to maildir format. So Cpanel has stopped supporting NeoMail.
(c) Some Horde and SquirrelMail features might not be working.
(d) Some email users might not be able to relay their mails using SMTP server and/or encounter login problems.
Please note that as hosting service provider, our stand will be security as first priority thus anything to do with security we will do so without any delay.
We've tested email accounts on all our servers from our own computers, no problem encountered so far. However, some customers might encounter problems mentioned above. Should you have problem with email login, please login to cpanel and reset email account password.
Also please note, webmail (currently Horde and SquirreMail available) is only meant for urgent use for example while travelling. Please do NOT use webmail as primary channel to access email. And do NOT store emails on server. Please download all important emails to your computer.
If you used NeoMail before and store emails and address book in NeoMail, the emails can be accessed via Horde. The NeoMail address book can not be imported to other webmail but can be downloaded in plain text format: FTP into your hosting account, go to .neomail-emailuser/cpaneluser directory, there is a file called addressbook, download it into your computer, and open by any text editor.
However, again, please do NOT repy on webmail, download emails to your own computer.
Please open support ticket if you have email problem.
Sorry for inconvenience caused, and we seek your kind understanding that security is always our first priority.
(1) Switch uwimap server to courier-imap server. Why? Security!!! Please read it at: http://secunia.com/advisories/17062/
(2) Update cPanel RELEASE BUILD to version 10.8.0-RELEASE_65
For this particular update, there are some issues might occur as below:
(a) Email users using Client Email Program such as Outlook Express might encounter re-downloading all the past mails. This is due to cPanel changed support for mailbox format from mbox to maildir.
(b) NeoMail won't be working after the switch from mbox format to maildir format. So Cpanel has stopped supporting NeoMail.
(c) Some Horde and SquirrelMail features might not be working.
(d) Some email users might not be able to relay their mails using SMTP server and/or encounter login problems.
Please note that as hosting service provider, our stand will be security as first priority thus anything to do with security we will do so without any delay.
We've tested email accounts on all our servers from our own computers, no problem encountered so far. However, some customers might encounter problems mentioned above. Should you have problem with email login, please login to cpanel and reset email account password.
Also please note, webmail (currently Horde and SquirreMail available) is only meant for urgent use for example while travelling. Please do NOT use webmail as primary channel to access email. And do NOT store emails on server. Please download all important emails to your computer.
If you used NeoMail before and store emails and address book in NeoMail, the emails can be accessed via Horde. The NeoMail address book can not be imported to other webmail but can be downloaded in plain text format: FTP into your hosting account, go to .neomail-emailuser/cpaneluser directory, there is a file called addressbook, download it into your computer, and open by any text editor.
However, again, please do NOT repy on webmail, download emails to your own computer.
Please open support ticket if you have email problem.
Sorry for inconvenience caused, and we seek your kind understanding that security is always our first priority.
19 August, 2005
Kernel Compilation on Gold Server
Update: completed by 4pm.
We'll be compiling kernel on Gold server on 20th Aug 2005 from 2:30pm. There might be a few reboots, web sites on Gold server may experience short downtime while rebooting .
It will take 1 to 2 hours to complete.
Sorry fot inconvience caused and thank you for your kind understanding.
We'll be compiling kernel on Gold server on 20th Aug 2005 from 2:30pm. There might be a few reboots, web sites on Gold server may experience short downtime while rebooting .
It will take 1 to 2 hours to complete.
Sorry fot inconvience caused and thank you for your kind understanding.
08 August, 2005
Cpanel/WHM/WebMail SSL disabled
To make our servers more secure, we've installed Brute-force Protection systems on all our Unix servers protecting SSH, POP3, FTP, SMTP, HTTP, Cpanel, WHM, WebMail.
As cPanel/WHM/WebMail via SSL which is using stunnel would not be protected due to the login log will show as IP 127.0.0.1 which is localhost, we have to disable cPanel/WHM/WebMail via SSL.
We've never informed customers to login to cPanel/WHM/WebMail via SSL (https://www.domain.com:2083 etc.), just in case some of you did login via SSL somehow, it would be disabled from midnight today Aug 8th 2005.
As cPanel/WHM/WebMail via SSL which is using stunnel would not be protected due to the login log will show as IP 127.0.0.1 which is localhost, we have to disable cPanel/WHM/WebMail via SSL.
We've never informed customers to login to cPanel/WHM/WebMail via SSL (https://www.domain.com:2083 etc.), just in case some of you did login via SSL somehow, it would be disabled from midnight today Aug 8th 2005.
25 June, 2005
Platinum Server Unaccessable for Unknown Reason - Now OK
Update: Platinum server is up now 11:20PM 25th June 2005.
Platinum server is unaccessable from around 10:00PM 25th June 2005, both web pages and email, for unknown reason. We can ping the IP address and the response time is ok, but web site/SSH/email is not accessable.
Our server admin is on the way to datacenter.
Thank you for your patience and sorry for inconvenience. Will update once we have news.
Platinum server is unaccessable from around 10:00PM 25th June 2005, both web pages and email, for unknown reason. We can ping the IP address and the response time is ok, but web site/SSH/email is not accessable.
Our server admin is on the way to datacenter.
Thank you for your patience and sorry for inconvenience. Will update once we have news.
18 May, 2005
Accounts On Gold Server Moving To Platinum Server
To serve you better in a more secured environment, we'll be moving all accounts on Gold server to Platinum server, starting from 18 May 2005.
There will not be downtime, all sites will perform as usual.
For domains that were registered by us, we'll update DNS from our side, clients do not have to do anything.
For domains that are not under our control, we'll email account owner new DNS information so that clients can update DNS themselves. When you receive such email, please update DNS asap. Note, do not update anything until you receive email from us.
If your site is on Gold server and you experience problems, please open support ticket or email us.
Sites on other servers will not be affected. To find out which server your site is on, read this post.
Migration in process.
Update 27/05/2005: Migration complete smoothly. We've mannually sent emails to all clients who need to update nameservers. Old nameservers will stop working next month. If your domain was on Gold server and you are still using old nameservers, please change to new nameservers as instructed ASAP. Otherwise, your site will be down next month.
There will not be downtime, all sites will perform as usual.
For domains that were registered by us, we'll update DNS from our side, clients do not have to do anything.
For domains that are not under our control, we'll email account owner new DNS information so that clients can update DNS themselves. When you receive such email, please update DNS asap. Note, do not update anything until you receive email from us.
If your site is on Gold server and you experience problems, please open support ticket or email us.
Sites on other servers will not be affected. To find out which server your site is on, read this post.
Migration in process.
Update 27/05/2005: Migration complete smoothly. We've mannually sent emails to all clients who need to update nameservers. Old nameservers will stop working next month. If your domain was on Gold server and you are still using old nameservers, please change to new nameservers as instructed ASAP. Otherwise, your site will be down next month.
What's This Blog For?
This blog was set up to keep our clients informed on latest updates of our servers.
Normally we make annoucements (maintenace, news, updates, etc.) to clients via email. However, we have to think of urgent case as well. For example, if server goes down, that would be busiest time for us , troubeshooting and repairing. The first priority in such situation would be to bring server up asap, instead of anwsering phonecalls, replying emails, explaining to clients.
And if the server that our own domain is on goes down, we cannot send/receive emails at all.
But we understand that clients must know what's happening to their site, especially if it's down. That's why we set up this blog to keep clients informed.
We will post and update server specs such as Apache version, PHP version, MySQL version, software upgrade, etc.
If any server goes down, we'll post latest update here as well so that clients would know what's going on. If you see maintenance/troubleshooting going on, please forgive us for not being able to answer your calls or emails while we're working on it.
Since this blog is not hosted on our server (blogspot belongs to Google, BTW), the chance that both this blog and our own site are down at the same time is next to impossible. Another good thing is, we can post updates anywhere, anytime.
So, please bookmark this blog. If you find something strange on your site, check it out here first.
Normally we make annoucements (maintenace, news, updates, etc.) to clients via email. However, we have to think of urgent case as well. For example, if server goes down, that would be busiest time for us , troubeshooting and repairing. The first priority in such situation would be to bring server up asap, instead of anwsering phonecalls, replying emails, explaining to clients.
And if the server that our own domain is on goes down, we cannot send/receive emails at all.
But we understand that clients must know what's happening to their site, especially if it's down. That's why we set up this blog to keep clients informed.
We will post and update server specs such as Apache version, PHP version, MySQL version, software upgrade, etc.
If any server goes down, we'll post latest update here as well so that clients would know what's going on. If you see maintenance/troubleshooting going on, please forgive us for not being able to answer your calls or emails while we're working on it.
Since this blog is not hosted on our server (blogspot belongs to Google, BTW), the chance that both this blog and our own site are down at the same time is next to impossible. Another good thing is, we can post updates anywhere, anytime.
So, please bookmark this blog. If you find something strange on your site, check it out here first.
17 May, 2005
How Do I Know Which Server My Site Is On?
In order to see if there's anything going on to your hosting account, you need to know which server your site is on.
Here's how to find out which server your site is on:
Go to http://www.dnsstuff.com/ , do a ping to your domain name (3d one in right colume), you will then see which IP address your site is on.
If your site is on IP between 203.175.163.74 - 203.175.163.78, your site is on Silver Server.
If your site is on IP between 203.175.163.98 - 203.175.163.102, your site is on Gold Server.
If your site is on IP between 203.175.163.82 - 203.175.163.86, your site is on Platinum Server.
If your site is on IP between 203.175.163.178 - 203.175.163.182, your site is on Tina Server.
If your site is on IP between 70.84.42.132 - 70.84.42.142, your site is on Ulysses Server.
Server List & Specs
Silver:
- Intel Pentium 4, 2.8GHz (with hyperthreading) 512Kb 800MHz FSB
- 2 GB DDR RAM
- 2 x 120GB (7200 RPM) IDE HDD
- CentOS 3.7
- DELL PowerEdge(TM) 750 with Intel Pentium 4 2.8GHz/1MB, 800MHz FSB
- 2 GB DDR RAM, Dual Channel DDR 400MHz ECC Memory
- 2 x 80GB (7200 RPM) SATA HDD
- CentOS 4.3
- DELL PowerEdge(TM) 750 with Intel Pentium 4 3.2GHz/1MB (with hyperthreading), 800MHz FSB
- 2 GB DDR RAM, Dual Channel DDR 400MHz ECC Memory
- 2 x 80GB (7200 RPM) SATA HDD
- CentOS 3.7
Tina:
- DELL PowerEdge(TM) 750 with Intel Pentium 4 3.2GHz/1MB (with hyperthreading), 800MHz FSB
- 2 GB DDR RAM, Dual Channel DDR 400MHz ECC Memory
- 2 x 160GB (7200 RPM) SATA HDD
- CentOS 4.3
Ulysses:
- Dual Opteron 240
- 1GB RAM
- 120GB SATA HDD
- Windows 2003
Subscribe to:
Posts (Atom)