Tagged - scam

Comical? Yes. Upsetting? Possibly. Shared Web Hosting

Wednesday, December 31st, 2008

I am on shared hosting, by JustHost.com. This service has not given me any issues, customer support is very good. When I’ve contacted them about something, I get a response within 20-30 minutes. So, mostly I’ve had no issues, and the loading time for my site is fine. It acts up a little, but not much, not any more than what you would expect from a shared host.

They offer a sort of gimmicky sign up, with unlimited everything, I’ve yet to find that limit, but perhaps I will some day if I get too much traffic.

I admit, I’m a noob when it comes to web hosting, and there’s so many options out there I basically just chose one. My experience has been limited to playing with MySQL databases and PHP on free hosts.

Recently, I found this information about JustHost here

Apparently, they went as far as to create a fake website with them at the top, here. If you look at the website, JustHost.com you see that they are proudly displaying their fake badge.

I found this more comical, than upsetting really. Like I said, for my purpose I don’t really care so long as it “works”.

It seems as if a lot of shared web hosting providers are using the same tactics, so it’s nothing new. (well, it’s new to me) Hopefully someday I will be able to go on a dedicated host, I’m really not impressed with shared hosts, not JustHost specifically, but all of them. I may be on a dedicated host sooner than I think, because my traffic has been increasing day by day. Perhaps I’m just giddy and want to try out a dedicated host. I wish I could, but I’m not sure I can afford it. I might try out a cheap dedicated host in the near future for a month or two.

I’m posting this in the tutorials section as well, because I believe it is a tutorial to understanding shared host gimmicks.

RoyalSurf & Brief ramble about trojans/virii

Saturday, December 6th, 2008
Trojan Horse

Trojan Horse

I don’t recommend this. I was using IE on it (Don’t exactly remember why, I hate IE) and there must be a new exploit of some sort for IE. I visited a certain site and zonealarm freaks out about ~.exe trying to become a startup item. I denied that, then denied access to the internet & trusted zone. I then searched for this file and lo and behold it was in the system32 folder. In case you don’t know, most virii/trojans hang out in that folder. I could not delete it nor could I end it’s process, since it was not added to a startup item I decided I should reboot. I then disconnected my modem, went into system32 and deleted it. Then I proceeded to do a full virus scan with nod32 & zonealarm. Nothing came up, so I guess I made it out alright.

I would have liked to analyze this file, but I would have to setup a vmware machine and play with ollydbg and I wasn’t really in the mood to go that far with it. Of course, I suppose I could have analyzed it with IDA Pro, but alas I didn’t bother since I wanted it gone. I was kind of interested in whether it was a trojan or a downloader for adware. Could’ve dropped it into one of the various online virus scan sites as well I suppose.

looking at milw0rm it looks like there are quite a few IE exploits. Still, most of the sites on RoyalSurf are shady and I really would not recommend using them.

On the flip side, I highly recommend ZoneAlarm, because it has saved me a few times from being infected. I usually don’t have issues with infections, it’s rare but it happens. I wonder sometimes how everyone else gets along with out getting infected with anything.. I think I read somewhere that most Windows PC’s were infected with one thing or another.

So many ways to disguise a file and hide it from virus scanners. Packing, hex modification etc, and with a nicely packed trojan, spliced onto a regular exe I can’t see how a normal user would notice. On top of that, they’re often disguised as FireFox.exe or IEXpore.exe or a system process. So, even if a user bothers to check out running processes, it’s unlikely they’ll see it.