<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission</title>
	<atom:link href="http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Experiences with using GoDaddy, Linux Web Hosting &#124; The (Unorganized) Musings of a Computer Scientist</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-3025</link>
		<dc:creator>Experiences with using GoDaddy, Linux Web Hosting &#124; The (Unorganized) Musings of a Computer Scientist</dc:creator>
		<pubDate>Sun, 15 Jan 2012 05:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-3025</guid>
		<description>[...] I first tried to accomplish goal #2 &#8212; the first thing I learned was that SSH functionality is an &#8216;opt-in&#8217; program. In other words, you have to explicitly &#8216;activate&#8217; the feature (instructions on how to do this are here: How to Enable SSH Access to your GoDaddy Hosting Account). Before I went ahead and pushed the Button, I did a Google search on any security implications of allowing SSH access (sorry, it&#8217;s the Computer Security in me!). Luckily, nothing glaring popped out in the search results &#8212; though, the following article did provide an amusing read: GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission. [...]</description>
		<content:encoded><![CDATA[<p>[...] I first tried to accomplish goal #2 &#8212; the first thing I learned was that SSH functionality is an &#8216;opt-in&#8217; program. In other words, you have to explicitly &#8216;activate&#8217; the feature (instructions on how to do this are here: How to Enable SSH Access to your GoDaddy Hosting Account). Before I went ahead and pushed the Button, I did a Google search on any security implications of allowing SSH access (sorry, it&#8217;s the Computer Security in me!). Luckily, nothing glaring popped out in the search results &#8212; though, the following article did provide an amusing read: GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 文件同步让生活更轻松(1) &#124; 坚果铺子博客</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-2586</link>
		<dc:creator>文件同步让生活更轻松(1) &#124; 坚果铺子博客</dc:creator>
		<pubDate>Fri, 22 Apr 2011 14:46:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-2586</guid>
		<description>[...] 最简单的办法是使用同样的账户和密码, 但是, 这可是个坏主意.  因为, 有很多网站并没有对密码进行安全的存储和管理,  一旦出现问题,  黑客能够很容易的恢复出你的密码. 犯下这种错误的甚至包括很多知名网站, 例如Apache,  Plenty Of Fish 和 GoDaddy. [...]</description>
		<content:encoded><![CDATA[<p>[...] 最简单的办法是使用同样的账户和密码, 但是, 这可是个坏主意.  因为, 有很多网站并没有对密码进行安全的存储和管理,  一旦出现问题,  黑客能够很容易的恢复出你的密码. 犯下这种错误的甚至包括很多知名网站, 例如Apache,  Plenty Of Fish 和 GoDaddy. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-2033</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Mon, 06 Sep 2010 13:57:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-2033</guid>
		<description>I&#039;m thinking that too. But if it was NOT in the contract, it&#039;s basically breaking and entering. </description>
		<content:encoded><![CDATA[<p>I&#039;m thinking that too. But if it was NOT in the contract, it&#039;s basically breaking and entering.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-2032</link>
		<dc:creator>Adrian</dc:creator>
		<pubDate>Mon, 06 Sep 2010 13:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-2032</guid>
		<description>From your logic, a landlord has the right to barge in to your rented home at any time. </description>
		<content:encoded><![CDATA[<p>From your logic, a landlord has the right to barge in to your rented home at any time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-719</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 16 Apr 2010 09:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-719</guid>
		<description>http://tools.softsutra.com/locip/index.php  &gt;&gt;  Get Ip Address &amp; Location Of A Person....Best Tool I Found To Get  Some One&#039;s Computer Information... X</description>
		<content:encoded><![CDATA[<p><a href="http://tools.softsutra.com/locip/index.php" rel="nofollow">http://tools.softsutra.com/locip/index.php</a>  >>  Get Ip Address &#038; Location Of A Person&#8230;.Best Tool I Found To Get  Some One&#39;s Computer Information&#8230; X</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: paul</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-720</link>
		<dc:creator>paul</dc:creator>
		<pubDate>Thu, 25 Mar 2010 16:20:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-720</guid>
		<description>i moved to gandi since i discover bad issues from godaddy reading one day in nmap.org, after this i think i was totally righ migrating from then</description>
		<content:encoded><![CDATA[<p>i moved to gandi since i discover bad issues from godaddy reading one day in nmap.org, after this i think i was totally righ migrating from then</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-721</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 09 Mar 2010 23:36:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-721</guid>
		<description>Former GoDaddy Investigator here.  Did you read your Terms of Service. GoDaddy reserves the right to access your dedicated hosting box at any time for any reason and yes they do encrypt customer passwords.  What you experienced is not out of the norm.  They&#039;ve got thousands of dedicated hosts all crammed together on the same network and are charging you a fraction of what it would cost for you to have your own truly private box on your own truly private network.  The reason they wanted to investigate your box is because it strange or large amounts of traffic was detected to or from you box.  Granted, it&#039;s legitimate... but they won&#039;t know that without investigating.  &lt;br /&gt;&lt;br /&gt;There are a lot of bad people out there who use stolen credit card numbers to get dedicated hosting boxes and use them for malicious purposes.  Any not having any right to investigate, would result in absolute chaos. Imagine if they didn&#039;t investigate anything.  I can guarantee your box would be under a DoS attack from another dedicated host right now, or the network would be completely congested with port scan, or your box could be infected or compromised leading to other customers getting infected or compromised.  It&#039;s for the greater good my friend.  A word to the wise, be nice to them and explain what the traffic is...  There are no-name hosting providers that don&#039;t give a ****.  Those hosting providers typically can&#039;t brag about 99.9% uptime because so often they have botnets and infections running wild.  Think on that a bit...</description>
		<content:encoded><![CDATA[<p>Former GoDaddy Investigator here.  Did you read your Terms of Service. GoDaddy reserves the right to access your dedicated hosting box at any time for any reason and yes they do encrypt customer passwords.  What you experienced is not out of the norm.  They&#39;ve got thousands of dedicated hosts all crammed together on the same network and are charging you a fraction of what it would cost for you to have your own truly private box on your own truly private network.  The reason they wanted to investigate your box is because it strange or large amounts of traffic was detected to or from you box.  Granted, it&#39;s legitimate&#8230; but they won&#39;t know that without investigating.  </p>
<p>There are a lot of bad people out there who use stolen credit card numbers to get dedicated hosting boxes and use them for malicious purposes.  Any not having any right to investigate, would result in absolute chaos. Imagine if they didn&#39;t investigate anything.  I can guarantee your box would be under a DoS attack from another dedicated host right now, or the network would be completely congested with port scan, or your box could be infected or compromised leading to other customers getting infected or compromised.  It&#39;s for the greater good my friend.  A word to the wise, be nice to them and explain what the traffic is&#8230;  There are no-name hosting providers that don&#39;t give a ****.  Those hosting providers typically can&#39;t brag about 99.9% uptime because so often they have botnets and infections running wild.  Think on that a bit&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-722</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 04 Mar 2010 03:57:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-722</guid>
		<description>Switch to Linode :D.</description>
		<content:encoded><![CDATA[<p>Switch to Linode <img src='http://blog.sucuri.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> .</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-723</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 26 Feb 2010 09:45:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-723</guid>
		<description>I have never had a problem with linode.com doing anything like this. I&#039;m not sure if your VPS is considered managed or not, but if not, I would drop them like a hot potato.&lt;br /&gt;&lt;br /&gt;As it is Godaddy lost me as a customer several years ago due to their abusive customer service reps.</description>
		<content:encoded><![CDATA[<p>I have never had a problem with linode.com doing anything like this. I&#39;m not sure if your VPS is considered managed or not, but if not, I would drop them like a hot potato.</p>
<p>As it is Godaddy lost me as a customer several years ago due to their abusive customer service reps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-724</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 26 Feb 2010 06:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-724</guid>
		<description>Someone got first but I&#039;ll say it again:&lt;br /&gt;&lt;br /&gt;linode.com</description>
		<content:encoded><![CDATA[<p>Someone got first but I&#39;ll say it again:</p>
<p>linode.com</p>
]]></content:encoded>
	</item>
</channel>
</rss>

