Account compromised and suspended -- Can I re-secure my account?

Status
Not open for further replies.

scoreill

New Member
Messages
8
Reaction score
0
Points
1
Hello, my account appears to have been compromised and malicious software installed which led to an account suspension. Someone else initiated an appeal. Is there any way that I can re-secure my account or change the password while the appeal is ongoing? I do not want someone else to have control of the account should the appeal be successful!
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
When you say someone else initiated the appeal, are you not in control of your account right now?

Edit: I should note that if you can still login at x10hosting.com, I believe you can still change the password associated to the account, but make sure your email account hasn't been compromised either - if that's been cracked too, then changing the password won't be enough until you fix that too.
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
The password is the same, but I did not initiate the appeal, which means that someone else has access to the account and initiated the appeal.
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
Can you change the password through the account panel if you login on x10hosting.com?

(reposted cause my edit went through after your last post)
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
No, the only pages I can access are the "account suspended" and appeal pages. I cannot do anything else.
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
I'm pinging an admin to see how to go about fixing this; for the moment I've marked the Appeal to remain unresolved so we don't restore access until we get this resolved.
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
May take some time for them to reply, but at least it won't restore the access to the wrong person :)
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
I got a partial response back but I'm waiting for the rest; it won't let us change the password when the cPanel account is suspended. I'm making sure that the passes synchronize properly if I do a reset password immediately after unsuspension, since I can just send the password to your email. In the mean time, make sure your email address isn't compromised either (if it used the same pass, set a new one) as if we can get it to synchronize properly, the new pass would be emailed there.
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
Got the last bit I needed; the account will be unsuspended shortly, however part of the process is going to be a bit unusual so I'll explain it in detail. Prior to doing ANYTHING though, make 100% sure the email account associated with your hosting account is secure, as if it's not, this would all be for naught since the compromiser could simply jump in and take the account again.
  1. First and foremost, after I erase the botnet script, the public_html folder will be moved to public_html_compromised, and a new one created in its place. Go through these files and make sure none of them are compromised before moving them live, since we can only lift a compromised account's suspension once.
  2. The cPanel and main login passwords will BOTH be changed to something random; this will prevent logging into cPanel or the main site directly until you head to x10hosting.com, click on "Sign In" in the upper right, then "Can't access your account?"
  3. Enter the email address associated with the account, which will begin the process of a password reset. Once that's completed, all the passwords set will match whatever you reset it to, including cPanel. This will restore login access so you can work on getting the old content live again.
You may get a few emails during the next few minutes, with one indicating that the account was unsuspended, and one or two regarding the passwords having been changed. This'll be normal, since it's what we need to do in order to effectively disable the logins until you can get them reset. If you run into questions let us know and we'll do our best to clarify along the way.
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
Thank you so much! I have reset the password on my email account, just in case, and set my email so that a text message code is needed to log in from another computer.
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
Thanks again for all of your help! In your first post, you said, "I can just send the password to your email," but in the second post, it says to use the password reset. Should I wait for a password to be emailed or should I use the password reset?
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
Use the password reset; at the time I wasn't aware that the only way to get all the passwords to sync up properly is through the reset form. Bear in mind that will also update your forum password, cPanel, and main login all at once, so everything'll be changed :)
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
Thanks! I've tried the password reset in firefox and chrome (on two computers running different versions of OS X) and every time, the emailed link redirects to the regular login page.
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
Are cookies enabled in your browser? The update I got from staff is that error can come back if it's followed from a browser that doesn't have cookies, or isn't the one that requested the reset. The page -should- be showing an error though; if it is, can you post what error it's giving?
 

scoreill

New Member
Messages
8
Reaction score
0
Points
1
I got it working through Safari, so I am finally back in my account! :) Thank you again for seeing this through!!
 

Livewire

Abuse Compliance Officer
Staff member
Messages
18,169
Reaction score
216
Points
63
Awesome, let us know if you need anything else :)
 
Status
Not open for further replies.
Top