Let's talk about Flex, AIR, ActionScript, ColdFusion and more    

Charge for restoring site which had been altered by recent injection attack


My site had been altered TWICE by recent injection attacks.
I'm using a shared hosting and it's CF7. I believe the user of ColdFusion instance is same as other users. I don't believe only my site was altered by the injection attack.

Potential ColdFusion security issu

And I restore my site from backup TWICE. Then they charged $10 as each restoration fee. The total is $20. I couldn't approve this charge. So I replied to the email, "Why should I pay for your service issue".

Then they said "contact our Billing department" for this "dispute".

I don't believe this.

If you were me, do you pay for this?


Related Blog Entries

Comments
JesterXL's Gravatar I once had some important files deleted by me. They wanted to charge me $200. I told them to f off.
# Posted By JesterXL | 7/5/09 3:17 AM
James Brown's Gravatar I wouldn't pay it and I would change hosts a quickly as possible.
# Posted By James Brown | 7/6/09 4:50 AM
Russ S.'s Gravatar Are you using cfqueryparam for ALL user-input in ALL of your queries? It only takes one unprotected variable in one query to open your DB to an injection attack.
# Posted By Russ S. | 8/7/09 6:52 PM
Shigeru's Gravatar This attack was not caused by query thing, it was caused by a security hole of ColdFusion. see following URL.

http://www.adobe.com/support/security/bulletins/ap...

# I wonder why you don't know about this...
# Posted By Shigeru | 8/7/09 10:23 PM
BlogCFC was created by Raymond Camden. This blog is running version 5.5.005.