感谢 @anon 提供消息。
我在“穷逼建站”里推荐过的免费主机商 Daniel's Hosting 今日发布公告:
I have some sad news. On March 10th at around 03:30 AM UTC all databases related to my hosting were deleted from the database server. There was a new database user with full permissions. But given that my hosting database is gone, I can't associate it with an account to look deeper into how it got full permissions. As of now, it is not clear how or when the hack happened. If you have an idea, feature requests for future versions or maybe a fix for the vulnerability, please consider contributing to my open source project at https://github.com/DanWin/hosting.
Although this so far looks like a database only hack, similar to the November 2018 hack, you should treat all data as leaked and change your passwords on other sites, should you be using the same one elsewhere as on any of the sites I hosted.
There are roughly 390 GB of user data from 7595 user accounts on the server. I will keep the server active until 25th March so that everyone has a chance to download their current files (without database) via FTP or SFTP.
Being a darknet hoster has taught me many things. However, this is a free time project I do next to my full time job and it's very time consuming to try and keep the server clean from illegal and scammy sites. I spend 10 times more time on deleting accounts than I can find time to continue development. At this time I do not plan on continuing the hosting project, but this doesn't have to be the end. There are other hosting providers like Freedom Hosting Reloaded or OneHost and my project is available for download, which should enable anyone willing to become the next darknet shared hosting provider to start where I left of.
If you would like to show your support, you can donate BTC via 17EH5c3zfzw8ictPxEujhuoULV4QZ4Stt7
百度翻译:
我有个不幸的消息。3月10日凌晨03:30左右,UTC从数据库服务器上删除了与我的主机相关的所有数据库。有一个具有完全权限的新数据库用户。但考虑到我的托管数据库已经不存在了,我无法将它与一个帐户关联起来,以便更深入地了解它是如何获得完全权限的。到目前为止,还不清楚黑客是如何或何时发生的。如果您有想法、对未来版本的功能请求或修复漏洞,请考虑参与我的开源项目:https://github.com/DanWin/hosting。
尽管这看起来像是一个只使用数据库的黑客攻击,类似于2018年11月的黑客攻击,但你应该将所有数据视为泄露,并在其他网站上更改密码,如果你在其他地方使用的密码与我托管的任何网站上的密码相同。
服务器上的7595个用户帐户中大约有390 GB的用户数据。我将保持服务器的活动状态,直到3月25日,这样每个人都有机会通过FTP或SFTP下载他们当前的文件(没有数据库)。
做一个黑暗的旅店教会了我很多东西。然而,这是一个自由时间的项目,我做下我的全职工作,这是非常耗时的尝试,保持服务器从非法和诈骗网站干净。我花在删除帐户上的时间是花在继续开发上的时间的10倍。目前我不打算继续托管项目,但这不一定是结束。还有其他托管提供商,如自由托管重新加载或一个主机和我的项目是可供下载的,这应使任何人愿意成为下一个黑暗共享托管提供商开始我离开。
如果您愿意支持,可以通过17eh5c3zfzw8ictpxeeujhuoulv4qz4stt7捐赠BTC
和2018年的事件非常类似:https://www.sohu.com/a/276867266_99938933/
只不过这次被删的只有数据库,直到3月25日,他服务器的FTP依然能访问下载,希望有重要资料的尽快下载!
再次证明一件事就是免费的基本不靠谱,当然也不是说收费的一定靠谱,只是安全系数相对大一些。
穷逼建站也因此少了一个好用的免费主机商,且用且珍惜吧!