Interland's Security Problems Persist
Web host has struggled to address outages related to breach since August
Computerworld - Web hosting provider Interland Inc. is still struggling to fix what appears to be a widespread security problem, months after its customers first informed the company about it.
Some sites hosted by Interland have been infected with malicious code that prevents Web pages from loading properly and as a result causes some sites to become unavailable. In many instances, visitors to the infected sites have been redirected to other malicious sites, where Trojan horses have been downloaded onto their systems.
Atlanta-based Interland manages over 7,000 servers and hosts more than 250,000 Web sites for predominantly small and midsize businesses. Company officials last week refused to respond to requests for comment. But in the past, the company's director of security, Jeff Reich, has acknowledged the problem while downplaying its significance, saying it has been mostly under control .
However, several users last week suggested otherwise.
"I've lost count of the number of times my site has gone down," said Kevin Krajewski, deputy director of management information systems for the city of Rochester Hills, Mich. "We've been dealing with [Interland] since March on this issue," he said, noting that the latest incident occurred Nov. 12.
Customer Angst
So far, the problem doesn't appear to have been resolved, said Krajewski, who noted that his own investigations have revealed that one of the Web sites that victims are being redirected to appears to be hosted by Interland itself. Krajewski's own theory -- based on his investigation of the problem and conversations with Interland staff -- is that the problem may be the result of an insider attack.
"We have seen evidence of two additional breaches at Interland since the initial compromise" in August, said Joe Stewart, a senior security researcher at LURHQ Corp., a managed security services provider in Chicago.
The company, which is not a customer of Interland, discovered the breaches as part of its Internet monitoring services for clients. "We are passing all relevant details along to Interland's security department as soon as we spot these hacked sites," Stewart said.
Most complaints have failed to yield results, said the New York-based owner of a site hosted by Interland who requested anonymity. "So far, I've been down for six days and [the complaint] has been escalated 11 times," the owner said. "Clearly there are things going on at Interland that are beyond their scope to handle."
Another Web site owner, based in Arlington, Va., who also requested anonymity, last week moved his site to another provider because of the problems.
"The servers weregoing down off and on for most of last week," he said. "They said something about having to rebuild their servers." At the point when the site became unavailable for more than 24 hours, the decision was made to move, he said.
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts