Login
Forgot Password?

OR

Login with Google Login with Twitter Login with Facebook
  • Join
  • Profiles
  • Groups
  • SuicideGirls
  • Photos
  • Videos
  • Shop
Vital Stats

user4574

Grew up in SFBA - Still in CA but way north of there.

Member Since 2008

Followers 19 Following 41

  • Everything
  • Photos
  • Video
  • Blogs
  • Groups
  • From Others

Wednesday Oct 01, 2008

Sep 30, 2008
0
  • Facebook
  • Tweet
  • Email
Stupid web host

I've got an account on a Linux web host including shell access.
They decided to upgrade the server, a good thing - but the way they did it was horrible.

First - they switched from Gentoo to Debian. I don't mind that change - Debian is much better for production servers than Gentoo. However, Debian uses a different UID/GID for the Apache web server. Thus - my web apps that need write permission to a directory all failed, because they didn't alter the UID/GID of apache.

Then - I could not log in. Connection refused. That's odd - so I went and looked in my mail for the password when I first set up the account three years ago, the password I changed the day I got the account, and son a bitch - it worked.

I bitterly complained about that, and they told me "You must have changed your password in the shell, the supported way is through cpanel, when we set up the new server, we used the password from cpanel"

WHAT THE FREAKING FUCK ???

That means they are storing the passwords for their users in cpanel. That is the stupidest thing they can possibly do. You don't store shell account login passwords in a database that is accessible from web applications.

Ack!

While I guess it is possible they are storing a shadow compatible hash of the password, they probably aren't - it's probably the plain text password. At least my shell account is safe - I changed it in the shell again. I despise CPanel. Webmin is at least a little tolerable, but CPanel just bites.

That's the dumbest thing they could do though, that's just asking to be hacked. Even if they do store a shadow compatible hash, you still don't do it in a database accessible from a web application.

I'm guess going to have to just spend the money and pay for 1U of rack space and admin my own machine. Every freaking web host I've ever used has demonstrated quite clearly that their system administrators aren't even qualified to be junior admins.

It's sickening.

More Blogs

  • 11.06.08
    8

    Thursday Nov 06, 2008

    Prop 8 - It's not the black man's fault San Jose Mercury News, and…
  • 10.28.08
    0

    Tuesday Oct 28, 2008

    Stargate SG1 It took many months - but I did it. Watched the enti…
  • 10.19.08
    5

    Sunday Oct 19, 2008

    Fat Cat ... or why to watch your cats weight Don't read if you are…
  • 10.06.08
    8

    Monday Oct 06, 2008

    Don't Dream It's Over I had a really weird dream. I do a lot of work…
  • 10.01.08
    1

    Thursday Oct 02, 2008

    Read More
  • 09.30.08
    0

    Wednesday Oct 01, 2008

    Stupid web host I've got an account on a Linux web host including …
  • 09.28.08
    1

    Monday Sep 29, 2008

    Three things. 1 - Hopefule review will have to wait until tomorrow. …
  • 09.24.08
    0

    Wednesday Sep 24, 2008

    I'm mother fucking tired of these mother fucking ants in my mother fu…
  • 09.21.08
    1

    Monday Sep 22, 2008

    Hopeful Review I just got this idea today when browsing blogs and sa…
  • 09.19.08
    2

    Friday Sep 19, 2008

    n00b here - so I thought a blog entry saying a little bit about me mi…

We at SuicideGirls have been celebrating alternative pin-up girls for:

23
years
9
months
7
days
  • 5,509,826 fans
  • 41,393 fans
  • 10,327,617 followers
  • 4,593 SuicideGirls
  • 1,120,690 followers
  • 14,920,095 photos
  • 321,315 followers
  • 61,391,142 comments
  • Join
  • Profiles
  • Groups
  • Photos
  • Videos
  • Shop
  • Help
  • About
  • Press
  • LIVE

Legal/Tos | DMCA | Privacy Policy | 18 U.S.C. 2257 Record-Keeping Requirements Compliance Statement | Contact Us | Vendo Payment Support
©SuicideGirls 2001-2025

Press enter to search
Fast Hi-res

Click here to join & see it all...

Crop your photo