Got this email at about 2 AM:
My question is, is it right that they acted as judge and jury and shut down my server with no warning on a mere "hunch" that something might be wrong? I am wondering how many other users woke up to the same message. Should I be concerned that this would happen again, and should I look for a different provider?
I thought this was a phishing attempt at first - who really asks their users for their root password? I am very meticulous about checking my logs daily, and I am the only one that has access to my VPS via ssh keys - all password authentication is disabled. My server was shut down for 12 hours yesterday with no warning to me and no chance to log in to my server to inspect any potential damage or secure my files. This is a production server that hosts multiple websites. They finally restored my access after 12 hours and multiple tickets and finding nothing malicious on the server, saying that they made a mistake by saying it had been infected.As indicated in an earlier message, we have uncovered malicious / illicit software running on several VPS and other server related products. This malicious software can allow a remote attacker partial or complete control over your environment. There is a risk that the issue may propagate to adjacent systems if it is not immediately quarantined.
Unfortunately, your system bearing IP Address: XXX.XXX.XXX.XXX has been identified as one of the affected servers and will need to be quarantined. We have prepared a temporary platform for you to access while we attempt to remediate the issue.
Since you may have critical data files on the affected system, we are prepared to migrate any important data as you require to get you operational on the new platform.
Please review and proceed with the following actions;
To facilitate this process, please provide a list files/directories that you need migrated and your system (administrator) login password, so that we may access the server and recover your files.
Login to your 247Rack customer profile and locate the replacement platform DEDICATED IP address and new system PASSWORD
Update your Remote Desktop or other RDP Client tools to reflect the new DEDICATED IP address and verify connectivity to the server.
Once you are on the new server, you may apply any changes and install applications as needed to support your VPS purpose
We are here to support you if you need help. Please feel free to contact us to guide you through the setup process.
We ask for your patients & cooperation to prevent further system impact while we assess the problem and re-mediate the underlying cause.
Regards,
247Rack Support
Note: If for any reason we are not able to provide the service you have come to expect - our leadership would like to hear from you. - e-mail : [email protected]
My question is, is it right that they acted as judge and jury and shut down my server with no warning on a mere "hunch" that something might be wrong? I am wondering how many other users woke up to the same message. Should I be concerned that this would happen again, and should I look for a different provider?