<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: dreamhost</title><link href="http://simonwillison.net/" rel="alternate"/><link href="http://simonwillison.net/tags/dreamhost.atom" rel="self"/><id>http://simonwillison.net/</id><updated>2007-06-08T08:16:37+00:00</updated><author><name>Simon Willison</name></author><entry><title>Security Breach</title><link href="https://simonwillison.net/2007/Jun/8/dreamhost/#atom-tag" rel="alternate"/><published>2007-06-08T08:16:37+00:00</published><updated>2007-06-08T08:16:37+00:00</updated><id>https://simonwillison.net/2007/Jun/8/dreamhost/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.dreamhoststatus.com/2007/06/06/security-breach"&gt;Security Breach&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
A statement from Dreamhost.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/dreamhost"&gt;dreamhost&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/hosting"&gt;hosting&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;&lt;/p&gt;



</summary><category term="dreamhost"/><category term="hosting"/><category term="security"/></entry><entry><title>Massive Dreamhost hack, WordPress not to blame</title><link href="https://simonwillison.net/2007/Jun/6/dreamhost/#atom-tag" rel="alternate"/><published>2007-06-06T09:38:00+00:00</published><updated>2007-06-06T09:38:00+00:00</updated><id>https://simonwillison.net/2007/Jun/6/dreamhost/#atom-tag</id><summary type="html">
    &lt;p&gt;On &lt;a href="http://mezzoblue.com/archives/2007/06/05/unsettling/"&gt;mezzoblue&lt;/a&gt;, Dave Shea reports that someone had modified every index.php and index.html file on his site to include spam links at the bottom of the page, hidden inside a &lt;code&gt;&amp;lt;u style="display: none;"&amp;gt;&lt;/code&gt;. Dozens of other people in his comments reported the same thing happening to their sites.&lt;/p&gt;

&lt;p&gt;At first, it looked like the common thread was WordPress hosted on Dreamhost. Initial commenters were all running WordPress (Dave has it installed for other domains on his hosting account even though he doesn't use it for mezzoblue itself) and there was &lt;a href="http://wordpress.org/development/2007/01/wordpress-207/"&gt;a vulnerability in WordPress 2.0.7&lt;/a&gt; which was fixed back in January but would still affect people who hadn't yet upgraded. I &lt;a href="http://simonwillison.net/2007/Jun/5/mezzoblue/#comments"&gt;posted a link&lt;/a&gt; suggesting that WordPress users in particular should check their sites.&lt;/p&gt;

&lt;p&gt;I apologise to the WordPress team for even suggesting that their product had something to do with this. Here's an e-mail Dreamhost sent out to some of their customers last night:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;We have detected what appears to be the exploit of a number of
accounts belonging to DreamHost customers, and it appears that your
account was one of those affected.&lt;/p&gt;

&lt;p&gt;We're still working to determine how this occurred, but it appears
that a 3rd party found a way to obtain the password information
associated with approximately 3,500 separate FTP accounts and has
used that information to append data to the index files of customer
sites using automated scripts (primarily for search engine
optimization purposes).&lt;/p&gt;

&lt;p&gt;Our records indicate that only roughly 20% of the accounts accessed -
less than 0.15% of the total accounts that we host - actually had
any changes made to them. Most accounts were untouched.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Scary stuff.&lt;/p&gt;
    
        &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/dreamhost"&gt;dreamhost&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/hosting"&gt;hosting&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/wordpress"&gt;wordpress&lt;/a&gt;&lt;/p&gt;
    

</summary><category term="dreamhost"/><category term="hosting"/><category term="security"/><category term="wordpress"/></entry><entry><title>Unsettling</title><link href="https://simonwillison.net/2007/Jun/5/mezzoblue/#atom-tag" rel="alternate"/><published>2007-06-05T21:16:58+00:00</published><updated>2007-06-05T21:16:58+00:00</updated><id>https://simonwillison.net/2007/Jun/5/mezzoblue/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://mezzoblue.com/archives/2007/06/05/unsettling/"&gt;Unsettling&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Sounds like there might be a massive scripted hack going on against out of date WordPress installs on Dreamhost. Check your site. See also discussion in the comments attached to this post.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/dave-shea"&gt;dave-shea&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/dreamhost"&gt;dreamhost&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/hosting"&gt;hosting&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/php"&gt;php&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/spam"&gt;spam&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/wordpress"&gt;wordpress&lt;/a&gt;&lt;/p&gt;



</summary><category term="dave-shea"/><category term="dreamhost"/><category term="hosting"/><category term="php"/><category term="security"/><category term="spam"/><category term="wordpress"/></entry><entry><title>Django on Dreamhost: incomplete headers</title><link href="https://simonwillison.net/2006/Dec/17/dreamhost/#atom-tag" rel="alternate"/><published>2006-12-17T09:36:43+00:00</published><updated>2006-12-17T09:36:43+00:00</updated><id>https://simonwillison.net/2006/Dec/17/dreamhost/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://automatthias.wordpress.com/2006/12/01/django-on-dreamhost-incomplete-headers/"&gt;Django on Dreamhost: incomplete headers&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Fix this problem on Dreamhost by renaming django.fcgi to dispatch.fcgi (they special-case for Rails users; Django users can tag along).


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/django"&gt;django&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/dreamhost"&gt;dreamhost&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/fastcgi"&gt;fastcgi&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/rails"&gt;rails&lt;/a&gt;&lt;/p&gt;



</summary><category term="django"/><category term="dreamhost"/><category term="fastcgi"/><category term="rails"/></entry><entry><title>Django on Dreamhost: incomplete headers</title><link href="https://simonwillison.net/2006/Dec/3/django/#atom-tag" rel="alternate"/><published>2006-12-03T19:04:08+00:00</published><updated>2006-12-03T19:04:08+00:00</updated><id>https://simonwillison.net/2006/Dec/3/django/#atom-tag</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://automatthias.wordpress.com/2006/12/01/django-on-dreamhost-incomplete-headers/"&gt;Django on Dreamhost: incomplete headers&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Calling your file dispatch.fcgi (as opposed to django.fcgi) fixes the problem.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/django"&gt;django&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/dreamhost"&gt;dreamhost&lt;/a&gt;&lt;/p&gt;



</summary><category term="django"/><category term="dreamhost"/></entry></feed>