Skip to main content

Posts

OpenSSL Vulnerability - Patches for CPanel servers.

Our upstream providers are applying patches to the CPanel servers, in response to the vulerability related to OpenSSL. Clients on our Auckland based non CPanel servers are not affected by this. A vulnerability, called Heartbleed, was recently identified impacting many platforms that use OpenSSL, including the CPanel servers. Potentially millions of servers are affected by this. Nicknamed "Heartbleed" the weakness allows anyone on the Internet to steal information normally protected by SSL/TSL encryption. The bug compromises the secret keys used to identify the provider and encrypt traffic, allowing potential attackers to eavesdrop on communications and impersonate services and users. As soon as our providers became aware of the issue,  they began working to patch it. For more information on the vulnerabilty please visit http://heartbleed.com/   --UPDATE-- This update has now been completed.

Lounge Network are taking NZ Web Hosting to the Next Level with Additional Security

The Lounge Network are protecting your businesses website from attackers.. At the Lounge Network we work hard to ensure your web site loads fast, is reliable and secure. This isn’t easy with more than 7,000 DDoS attacks occurring daily around the globe. To improve our ability to protect customers we have deployed state-of-the-art DDoS mitigation technology on our Auckland Clustered Network; the same technology is used by governments and large service providers around the globe to protect their networks. The Lounge Network is one of only a few Kiwi web hosts to have this technology, and we are using it to protect your web sites and servers at no extra cost to you. Our new technology monitors network traffic, actively identifying attack traffic, allowing us to mitigate it before it reaches you. For example: identifying brute force attempts on your WordPress install, attempts to infect your server with malware, or an all out DDoS attack aimed at taking...

The free Shared Secure Certificate on CPanel servers has been phased out.

This was discussed in an announcement earlier in the week, but may have been overlooked by some users. Due to some security updates on the CPanel servers we will need to cease providing  access to the free shared secure certificate, on all shared CPanel hosting servers, effective immediately. This is due to the way shared secure certificates run on CPanel servers. Unfortunately using a shared secure certificate is now deemed to be too much a of a security problem, and it conflicts with other security protocols which have been introduced with urgency on the servers. This is being done for the security of all users of the shared CPanel servers.  Although we don't know how many people make use of the free shared secure certificate, we don't believe there are very many. If clients do need a secure certificate, we do still allow dedicated certificates to be installed on our CPanel hosting plans. A dedicated secure certificate also offers a far more prof...

Urgent Security Updates to be applied to CPanel servers - Important Changes

All CPanel servers will have security updates applied in the coming days. The server technicians will be enabling the Symlink Patch on the servers as security measure. This patch will ensure that no user can create a link in their account to files under another user, or server configuration files, and thus accessing information from it.  This update will require apache to be recompiled on the server, and means php 5.3 will be enabled by default on the server. If your website is running  very old software that doesn't run under php5.3, we should be able to switch back individual websites back to to PHP 5.2 upon request. Please note that PHP 5.2 is now end of life, and has been replaced by PHP 5.3, so we would recommend updating your website to run under PHP 5.3. The other thing about this update, is that it will mean that we will need to cease providing  shared secure certificate access on all shared CPanel hosting servers, effective immediately. This is ...

Lounge Network Infrastructure Upgrade

During this week and next we will be completing our migration of the system back-end database system to MariaDB. This refers to the infrastructure that runs the controlpanel and hosting systems, and does not affect customer’s hosted databases. MariaDB offers better real-time support and security, and importantly flexibility and a future focus for next generation services. No impact is expected as we have been running MariaDB in parallel for some time in order to check data integrity. However we want to inform our customers of the changeover dates and times which are as follows: Tuesday 11th Feb, 6AM: All DNS and redirects changed so that they read from the new cluster. Tuesday 18th Feb, 6AM: Control Panel changed so that it reads from the new cluster.

Incident Report on the Power Outage at Datacentre on the 4/02/2014

At approximately 11:20AM NZ Time on the 4/02/2014, there was a major electrical surge into the datacentre where all of our CPanel servers are stored. This resulted in the datacentre losing power for approximately 2 seconds.  As this is a normal concern for our industry, our upstream providers have both UPS and generator backups to mitigate any potential effect to clients, and we've never had any issues previously.  The facility has gone on strictly UPS power many times, both for our quarterly/yearly testing, as well as regular power surges. This issue however, proved to be much more problematic, because there was also surge that occurred after, which took out multiple redundant/diverse path breakers in the datacentre.  This resulted in a full scale blackout at the datacentre.  By 11:21AM NZ Time, utility power was restored.  Our upstream providers have UPS systems with multiple battery cabinets to give clean conditioned power to the se...

Incident Report: November Mail Issues on the Auckland Mail Cluster

If you are a user of our Auckland based Email system, you may have noticed over the past few weeks there were a few extended periods of poor performance including an inability to connect to the mailserver to download email during peak times on certain days while emergency maintenance was being carried out. This affected approximately half of users using that network. First and foremost, we would like to apologise for this. We use this platform ourselves, so we know how much of a disruption it is to business and communications. Secondly, we am happy to say as of last week the issues behind this extended poor performance have been fully resolved and you can now expect mail to be back to normal. This issue was limited to our mail platform and had no impact on web sites, servers or other services. So what happened? On the 12th of November, one of our three mail storage zones experienced hardware failure. This is not uncommon in itself, however upon replacing the ha...

Spam from Spark / Telecom / Xtra / Yahoo email accounts

There has been a noticeable increase in spam being received from Telecom / Xtra / Yahoo email NZ email addresses. These include email accounts ending in @xtra.co.nz , yahoo.co.nz etc, and usually includes a link to malware. We suggest deleting these emails immediately, and do not click on any links in the email. Should you click on the email, make sure you do a full malware scan on your PC, as it could potentially cause a compromise on your hosting and email accounts This is not something that is affecting our services, but a general problem that is currently occurring on the Internet at the moment. It appears to be the occurrence of a previous problem that Xtra Yahoo had.  Therefore if you are receiving a lot of spam from email addresses ending in @xtra.co.nz, or @yahoo.co.nz, this will be the reason, and please delete them. Please contact Telecom for more information by googling 'telecom nz'. If you are a Yahoo Xtra user, we suggest ditching your email p...

Spark / Telecom / Xtra / Yahoo to switch off smtp.xtra.co.nz soon.

This announcement only applies if you use Telecom as your ISP. We have read recently in various places on the internet, that Telecom / Xtra / Yahoo maybe switching off their smtp.xtra.co.nz outgoing mailserver (using port 25), in the near future. Most people will now be using the new version which is send.xtra.co.nz, which uses an authenticated connection, and if you are using the old version you should consider switching to their new setting now. If you are not sure on how to do this, please contact your ISP Telecom for support. If you do start to have trouble sending email, this will likely be the reason why. You can also use our outgoing mail server to send out email on most of our hosting plans.