Interland's Security Problems Persist
Web host has struggled to address outages related to breach since August
Computerworld - Web hosting provider Interland Inc. is still struggling to fix what appears to be a widespread security problem, months after its customers first informed the company about it.
Some sites hosted by Interland have been infected with malicious code that prevents Web pages from loading properly and as a result causes some sites to become unavailable. In many instances, visitors to the infected sites have been redirected to other malicious sites, where Trojan horses have been downloaded onto their systems.
Atlanta-based Interland manages over 7,000 servers and hosts more than 250,000 Web sites for predominantly small and midsize businesses. Company officials last week refused to respond to requests for comment. But in the past, the company's director of security, Jeff Reich, has acknowledged the problem while downplaying its significance, saying it has been mostly under control .
However, several users last week suggested otherwise.
"I've lost count of the number of times my site has gone down," said Kevin Krajewski, deputy director of management information systems for the city of Rochester Hills, Mich. "We've been dealing with [Interland] since March on this issue," he said, noting that the latest incident occurred Nov. 12.
Customer Angst
So far, the problem doesn't appear to have been resolved, said Krajewski, who noted that his own investigations have revealed that one of the Web sites that victims are being redirected to appears to be hosted by Interland itself. Krajewski's own theory -- based on his investigation of the problem and conversations with Interland staff -- is that the problem may be the result of an insider attack.
"We have seen evidence of two additional breaches at Interland since the initial compromise" in August, said Joe Stewart, a senior security researcher at LURHQ Corp., a managed security services provider in Chicago.
The company, which is not a customer of Interland, discovered the breaches as part of its Internet monitoring services for clients. "We are passing all relevant details along to Interland's security department as soon as we spot these hacked sites," Stewart said.
Most complaints have failed to yield results, said the New York-based owner of a site hosted by Interland who requested anonymity. "So far, I've been down for six days and [the complaint] has been escalated 11 times," the owner said. "Clearly there are things going on at Interland that are beyond their scope to handle."
Another Web site owner, based in Arlington, Va., who also requested anonymity, last week moved his site to another provider because of the problems.
"The servers weregoing down off and on for most of last week," he said. "They said something about having to rebuild their servers." At the point when the site became unavailable for more than 24 hours, the decision was made to move, he said.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Google: Security for Google Apps Messaging & Collaboration
- Content provided by Google
Find out about how Google creates a security-based platform for Google Apps, covering topics like information security, physical security, and... - An Interactive Guide: Bring Your Own Device
- BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
- Fundamental Principles of Network Security
- This paper covers the fundamentals of secure networking systems, including firewalls, network topology and secure protocols. Best practices are also given that introduce...
- Protection Against Modern Cybersecurity Threats
- Download this case study to learn how this accounting and consulting giant uses Bit9's adaptive application whitelisting to offer employees flexibility without jeopardizing...
- A Proactive Approach to Server Security
- Learn why security-conscious organizations are taking a more proactive approach to server security. Download this Spire Research whitepaper to understand how you can...
- Live Webcast
North Pole to South Seas: Overcoming the Pitfalls of remote Performance - In today's always-on world, connectivity is a business requirement. You need the tools that allow you to operate as if you were on...
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...