HawthorneVillager.com
http://www.hawthornevillager.com/phpbb/

Testing...site back up......
http://www.hawthornevillager.com/phpbb/viewtopic.php?f=1&t=260
Page 1 of 1

Author:  Rick Di Lorenzo [ Wed Dec 22, 2004 10:39 pm ]
Post subject:  Testing...site back up......

Testing..1...2...3

Author:  Tim&Sandra [ Thu Dec 23, 2004 3:05 pm ]
Post subject: 

wow, do you get money back for all the downtime?

Tim

Author:  Rick Di Lorenzo [ Thu Dec 23, 2004 3:13 pm ]
Post subject: 

Thanks Carly!

I wish Tim! I asked what the "guarantee" means on uptime..they said this was a situation behind their control so the guarantee isn't valid. But they can say that for any downtime. I.e. a server blows up, their network cable gets cut, a hacker breaks in, those are all "situations behind their control". That's what downtime is. And yes you can control it, by having better security, more staff to patch more serves when needed, more network redundancy, etc.

Author:  Magellan [ Fri Dec 24, 2004 9:07 am ]
Post subject: 

Rick wrote:
Thanks Carly!

I wish Tim! I asked what the "guarantee" means on uptime..they said this was a situation behind their control so the guarantee isn't valid. But they can say that for any downtime. I.e. a server blows up, their network cable gets cut, a hacker breaks in, those are all "situations behind their control". That's what downtime is. And yes you can control it, by having better security, more staff to patch more serves when needed, more network redundancy, etc.


Rick what came first the worm or the patch? If the worm came first and then the patch came out to fix it, I see their point. But if the patch was available before the site got infected then you would have a case.

Author:  Rick Di Lorenzo [ Fri Dec 24, 2004 10:17 am ]
Post subject: 

Hi Magellan,

PhpBB issued a fix for this security hole that the worm exploited back in mid november. http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

They "strongly, and I mean strongly!" urged all users/customers/host providers to take action on this fix. Canaca uses Ensim (automated type of admin tool for host providers to supply application services such as PhpBB to their customers). So Canaca uses Ensim to apply security patches/fixes when needed to these controlled services.

I'm not sure if it's Ensim or Canaca that "sat" on this until someone finally released a worm to exploit this hole. But phpBB warned all host providers of the hole back on November 18th, and it's really only a 1 line code change to fix.

Canaca could have prevented the worm by applying phpBB's fix to their servers anytime between Nov 18th and Dec 20th. Also once the worm hit, and we realized in under 3 hours what the problem was, it took them 2 days to restore from backup & make the 1 line code change. They said it took this long because they have a LOT of servers to apply it to, and they wanted to do careful testing before hand.

I've made my own backup now of the phpBB/html files offline. Cause I can't trust that I'll have access to Canaca's backup system in the future. I thought if the files got lost, Canaca would simply give me access to the backup if I needed/wanted it. But sounds like they felt they had to turn their entire backup system off during the worm, and that meant they also couldn't restore/give me any of my backed up files while their backup system is turned off.

Author:  Magellan [ Fri Dec 24, 2004 11:48 am ]
Post subject: 

If that's the case Rick then I don't see how they can claim "situation behind their control" if they neglected to properly patch the application. But I know how providers can be.

Thanks for your time and hard work Rick.

Page 1 of 1 All times are UTC - 5 hours
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/