HawthorneVillager.com

Hawthorne Village (Milton) Discussion Board
It is currently Fri Jun 12, 2026 12:33 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Wed Dec 22, 2004 10:39 pm 
Offline
Site Admin
User avatar

Joined: Thu Jul 01, 2004 5:46 am
Posts: 4498
Location: Tothburg, Winter Cres.
Testing..1...2...3


Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: Thu Dec 23, 2004 3:05 pm 
Offline
User avatar

Joined: Thu Jul 01, 2004 10:25 am
Posts: 2441
Location: Greensburg Elev B, Robson Cres
wow, do you get money back for all the downtime?

Tim


Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: Thu Dec 23, 2004 3:13 pm 
Offline
Site Admin
User avatar

Joined: Thu Jul 01, 2004 5:46 am
Posts: 4498
Location: Tothburg, Winter Cres.
Thanks Carly!

I wish Tim! I asked what the "guarantee" means on uptime..they said this was a situation behind their control so the guarantee isn't valid. But they can say that for any downtime. I.e. a server blows up, their network cable gets cut, a hacker breaks in, those are all "situations behind their control". That's what downtime is. And yes you can control it, by having better security, more staff to patch more serves when needed, more network redundancy, etc.


Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: Fri Dec 24, 2004 9:07 am 
Offline

Joined: Thu Jul 01, 2004 2:14 pm
Posts: 292
Rick wrote:
Thanks Carly!

I wish Tim! I asked what the "guarantee" means on uptime..they said this was a situation behind their control so the guarantee isn't valid. But they can say that for any downtime. I.e. a server blows up, their network cable gets cut, a hacker breaks in, those are all "situations behind their control". That's what downtime is. And yes you can control it, by having better security, more staff to patch more serves when needed, more network redundancy, etc.


Rick what came first the worm or the patch? If the worm came first and then the patch came out to fix it, I see their point. But if the patch was available before the site got infected then you would have a case.


Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: Fri Dec 24, 2004 10:17 am 
Offline
Site Admin
User avatar

Joined: Thu Jul 01, 2004 5:46 am
Posts: 4498
Location: Tothburg, Winter Cres.
Hi Magellan,

PhpBB issued a fix for this security hole that the worm exploited back in mid november. http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

They "strongly, and I mean strongly!" urged all users/customers/host providers to take action on this fix. Canaca uses Ensim (automated type of admin tool for host providers to supply application services such as PhpBB to their customers). So Canaca uses Ensim to apply security patches/fixes when needed to these controlled services.

I'm not sure if it's Ensim or Canaca that "sat" on this until someone finally released a worm to exploit this hole. But phpBB warned all host providers of the hole back on November 18th, and it's really only a 1 line code change to fix.

Canaca could have prevented the worm by applying phpBB's fix to their servers anytime between Nov 18th and Dec 20th. Also once the worm hit, and we realized in under 3 hours what the problem was, it took them 2 days to restore from backup & make the 1 line code change. They said it took this long because they have a LOT of servers to apply it to, and they wanted to do careful testing before hand.

I've made my own backup now of the phpBB/html files offline. Cause I can't trust that I'll have access to Canaca's backup system in the future. I thought if the files got lost, Canaca would simply give me access to the backup if I needed/wanted it. But sounds like they felt they had to turn their entire backup system off during the worm, and that meant they also couldn't restore/give me any of my backed up files while their backup system is turned off.


Top
 Profile  
Reply with quote  
 Post subject:
PostPosted: Fri Dec 24, 2004 11:48 am 
Offline

Joined: Thu Jul 01, 2004 2:14 pm
Posts: 292
If that's the case Rick then I don't see how they can claim "situation behind their control" if they neglected to properly patch the application. But I know how providers can be.

Thanks for your time and hard work Rick.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
[ Time : 0.030s | 14 Queries | GZIP : Off ]