Register 365 – fail

Today I got a email from Register365, saying that for security reason they are disabling the online web folder manager. The sneakily make it sound like they are just disabling it until it’s fixed. But in reading this it also sounds strange that they don’t disable it straight away if it is such a threat. Here is the email I just got :

Dear paul savage,

Thank you for choosing Register365 as your hosting provider of choice.

IMPORTANT SERVICE NOTICE

At Register365 we take the security of our customers’ hosting services
very seriously and as such we would like to inform you that our
engineers have discovered a potential security flaw in the WebShell file
manager. In order to preempt any risk of a security breach that may
affect our customers’ websites the WebShell feature will be turned off
as of Midday on Tuesday 9th February 2010 .

Please note this is a precautionary measure and FTP will continue to
work as normal and your websites should not be affected in any way by
this action.

If you need any support on how to use FTP clients to upload files to
your site please refer to our knowledge base articles located at
http://www.register365.com/knowledge/view_folder.php5?section_id=312

At Register365 we strive to provide the best quality of service and
infrastructure to all our customers and as you may already know, we have
been working hard to deploy a new shared hosting cluster based on state
of the art technology and delivering the most stable and secure hosting
environment on the Irish market. If you would like to find out more
about the new hosting cluster available with Register365 and how you
could migrate to the new platform for FREE, please contact
support@register365.com.

If you have any further questions, please do not hesitate to contact our
support teams through the usual channels.

Kind regards

Namesco Ireland Limited (trading as Register365)

To that I submitted a support case as the service email came from “noreply@register365.com” .

You are disabling it indefinitely ? or just until you can patch the service ?
This is unclear in the email I got from you.

and to that I got the updated report that they are not fixing it, with some extra padding about saying it’s too difficult.

Good afternoon Paul,

Thank you for your email.

It’s being disabled indefinitely I’m afraid as it would be too prohibitive to have a patch developed, tested and deployed at this late stage in our H-Sphere platform’s life cycle.

We haven’t taken this decision lightly but the issue that has been identified could potentially be quite serious so urgent pre-emptive action was needed. Disabling the webshell feature for the foreseeable future seemed the most expeditious and safest solution.

We apologise again for any inconvenience caused.
Kind Regards,

Nathan P.
Support Team
Namesco Ireland Limited

An unconvinced customer

Somehow I am not convinced here, if it’s a security issue why not disable straight away, and why no provide an alternative ? It really doesn’t sound like any level of customer support or attention to security. If it’s a security hole, disable straight away. You are now suddenly not providing a method for people to edit their files outside FTP’ing them, this for many people is not an option because of company firewalls. All in all it seems like Namesco Ireland Limited / Register365 couldn’t give a toss about their customers.

4 thoughts on “Register 365 – fail

  1. Hi Paul

    I too am on reg365 and have had terrible service from them as half the time some feature doesn’t work ,mail,webshell,stats,etc. However i stayed with them because of convenience and the webshell product. Ftp is a time consuming and terrible way of making changes. But now thats gone i think ppl will leave in droves.

    1. Hi Paul, thanks for the comment.

      I have urged a few clients to use http://www.webftp.co.uk/ which is not as nice, but at least they will be able to use it to get around their work firewalls. If you are worried about security you can also install it on your sever and protect it with a password.

  2. Pingback: File Manager
  3. They said the same thing about the xml protocol. there was a security issue with it a few years ago, but that has long since been solved. yet they refuse to switch it on.

    They don’t let you use pretty permalinks? who wants a url that says http://www.mydomain.com/post.php?-10??/. stupid.

    i ring their support from time to time because i find their interface really unfriendly and go round and round in circles half the time. During the recorded message “we are experiencing unusual amount of demand” or whatever ,which seems to happen when ever you ring them at any time, they mention, “our award winning customer support service”!!!!! I nearly fell of my chair laughging. Any time I ring them there is a very minimum of 15-20 mins wait for support.

    their support might as well be non existent.

Comments are closed.