{"id":2756,"date":"2016-08-09T13:06:18","date_gmt":"2016-08-09T19:06:18","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2756"},"modified":"2016-08-09T13:06:18","modified_gmt":"2016-08-09T19:06:18","slug":"godaddys-managed-wordpress-hosting-fails-to-provide-important-security-feature","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/08\/09\/godaddys-managed-wordpress-hosting-fails-to-provide-important-security-feature\/","title":{"rendered":"GoDaddy&#8217;s Managed WordPress Hosting Fails to Provide Important Security Feature"},"content":{"rendered":"<p>We were recently brought in to deal with a WordPress website that had been hacked multiple times and just re-hacked. In that type of situation one of the first things that should be done is to review the log files available for the website, since those are likely to provide evidence on how the website is being re-hacked and depending on how far the logs go back, how the website was originally hacked.<\/p>\n<p>One of the big problems we find in being able to review the log files of a hacked website, is that often times web hosts only store the log of HTTP activity for a short period, in some cases less than a days worth of logging is available. One of the better web hosts when it comes to this is GoDaddy. With their standard web hosting accounts using their own control panel, they store about a months worth of logging. When using the cPanel control panel instead, the log is stored for a shorter time period by default, but you can enable archiving, so we can at least make sure it stored for a longer period once we get started on the cleanup.<\/p>\n<p>The website we are\u00a0dealing with in this case though was in <a href=\"https:\/\/www.godaddy.com\/hosting\/wordpress-hosting\">GoDaddy&#8217;s Managed WordPress hosting<\/a>\u00a0account, which we would find out when the client tried to get access to the log files, does not provide any access to the log files. We are puzzled that they manage to provide that in the standard web hosting accounts, but not not in what would seem to us to be a higher end type of account. The explanation for why they can not provide it, is also\u00a0puzzling, as they say they can&#8217;t provide it because the website is hosted in a shared environment. The other web hosting accounts are also on shared environment and yet they manage to provide them there.<\/p>\n<p>If you are concerned about security we would recommend that you not use their Managed WordPress hosting until they resolve this, since if you were to get hacked, you are going to be missing important information needed to properly clean it up (is worth mentioning that many companies that do hack cleanups either don&#8217;t know how to do things properly or are cutting corners and don&#8217;t review the log files like they should).<\/p>\n<p>While we were looking over the marketing materials for the service we noticed some security claims that are also worth mentioning. One of the &#8220;key features&#8221; of the service is that they &#8220;keep the bad guys away&#8221;:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-2759 size-full\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-keep-bad-guys-at-bay.png\" alt=\"Keep bad guys at bay Your site gets the personal bodyguard treatment, 24\/7. Our security team monitors, thwarts, and deflects so you can rest easy.\" width=\"280\" height=\"350\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-keep-bad-guys-at-bay.png 280w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-keep-bad-guys-at-bay-240x300.png 240w\" sizes=\"auto, (max-width: 280px) 85vw, 280px\" \/><\/p>\n<p>Seeing as the website we are dealing with got hit multiple times while using this hosting service, their ability to actually protect the websites is is at least limited.<\/p>\n<p>The ability to protect the website is also contradicted by another feature available in one level of account, which removes malware from the website:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2760\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-malware-scan-and-removal.png\" alt=\"Malware scan &amp; removal Hackers can inject malicious code\u2014malware--into your site to steal info or deface your site. With SiteLock Professional Malware scan (included with Ultimate plan), malware\u2019s found and destroyed before it harms you or your customers.\" width=\"350\" height=\"350\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-malware-scan-and-removal.png 350w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-malware-scan-and-removal-150x150.png 150w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/08\/go-daddy-managed-wordpress-hosting-malware-scan-and-removal-300x300.png 300w\" sizes=\"auto, (max-width: 350px) 85vw, 350px\" \/><\/p>\n<p>If they were actually\u00a0able to protect the websites, as they advertise, then there shouldn&#8217;t be any malware getting on the website that needs to be removed.<\/p>\n<p>We\u00a0would also have wondered about the fact that the company SiteLock would be involved in doing hack cleanups on this service, when they can&#8217;t do things properly because the logs are not available,\u00a0if not for the fact that we have seen that SiteLock doesn&#8217;t seem to <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2015\/06\/03\/sitelock-also-managed-to-break-a-website\/\">seem to be interested<\/a> in <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/25\/sitelock-doesnt-do-basic-part-of-proper-hack-cleanup\/\">properly cleaning up websites<\/a> and is <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/05\/03\/it-looks-like-sitelock-is-scamming-people\/\">known for taking advantage of their customers<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We were recently brought in to deal with a WordPress website that had been hacked multiple times and just re-hacked. In that type of situation one of the first things that should be done is to review the log files available for the website, since those are likely to provide evidence on how the website &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/08\/09\/godaddys-managed-wordpress-hosting-fails-to-provide-important-security-feature\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GoDaddy&#8217;s Managed WordPress Hosting Fails to Provide Important Security Feature&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,3],"tags":[63,64,39],"class_list":["post-2756","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-wordpress","tag-godaddy","tag-godaddy-managed-wordpress","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2756"}],"version-history":[{"count":6,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2756\/revisions"}],"predecessor-version":[{"id":2764,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2756\/revisions\/2764"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}