Hosting r/Hosting is a community for discussion of web hosting services and providers. Shared hosting, WordPress , VPS, dedicated servers, cloud infrastructure, and anything else hosting related is welcome here.

  • A problem with a hosting company
    by /u/DisasterBeautiful444 on September 15, 2026 at 10:58 am

    I have a question for people who work with hosting, WordPress, and server administration. After a security incident, a hosting company in Serbia told me that my website had been compromised through an administrator account. However, while investigating the incident myself, I noticed several things that I don’t fully understand, and I would really appreciate the opinion of people with server administration experience. According to the logs, someone accessed the website at around 8:30 in the morning and then appeared again later, before the end of the working day. So, I assume this was not just a single isolated access by their “remote” technician who was supposed to help clean the infected files. I found the following on the website: infected .htaccess files; files that appeared to be images (.png), but actually contained PHP/malicious code; I deliberately left one folder containing known malicious content untouched, to see whether it would be detected or removed during their security check; the folder was neither removed nor flagged as problematic; afterwards, I was told that they had not found anything during their investigation. There is another thing that I find particularly strange: one www file and an access log have permissions set to 0777. When I manually change the permissions, they are later changed back again. What I don’t know is whether such a change could be caused by: the hosting system or an automated script, the website configuration, WordPress/a plugin, or malicious code that is setting the permissions again. So I would like to know how you would investigate this and where you would look for evidence of what is changing the permissions. Also, the hosting company told me yesterday that they would send me a response after carrying out some additional checks, but I haven’t received anything. This has never happened with them before. The biggest problem is that I recently paid for a hosting package, so I really don’t want to move to a VPS, but it looks like I may have to. I thought I could leave this part of the job to them so I wouldn’t have to deal with it myself, but apparently I was wrong. This hosting account has serious problems, and the server hosting the website was going down every week. They themselves admitted that there was a problem with the server. I don’t want to jump to the conclusion that the hosting company is responsible for the incident. I’m trying to understand the technical situation: Can repeated access from the same day indicate an active compromise? Is it normal for infected .htaccess files to remain after a “security check”? How serious is it if files with a .png extension actually contain PHP code? Is 0777 normal for files like these, or does it represent a serious security issue? If permissions are changed back to 0777 after I manually change them, how can I determine what is changing them? Which server-side logs would you check to determine whether the change was made by the system, a hosting script, or a malicious process? I would particularly appreciate technical opinions from people who administer Linux/Apache/PHP servers. submitted by /u/DisasterBeautiful444 [link] [comments]

  • The hosting company in Serbia
    by /u/DisasterBeautiful444 on September 15, 2026 at 8:15 am

    I would like a technical opinion from Linux/server administrators. My hosting provider told me that a www entry in my hosting account is a symbolic link to public_html, and that it is normal for it to have permissions displayed as 0777. Their explanation was: I understand that symlinks are displayed differently from regular files/directories, and that the permissions shown for a symlink may not have the same meaning as the permissions of its target. What I would like to understand is: Is lrwxrwxrwx / 0777 on a symbolic link pointing to a website’s document root completely normal? Does the 0777 displayed for the symlink have any security implications? Which permissions should I actually check on the target directory (public_html)? Could a symlink such as www -> public_html create any security risk if the target directory or files underneath it have incorrect permissions? Is there any situation where a hosting provider should restrict or change the permissions displayed for the symlink itself? For context, this question came up during an investigation of a compromised website. The hosting provider also told me not to delete any “system files”, so I am trying to understand the technical distinction between the symlink itself and the actual website directory before changing anything. It is not even possible (all the changes go back to previous). I am not asking whether my hosting provider is responsible for the compromise. I only want to establish what is technically normal and what permissions actually matter from a security perspective. submitted by /u/DisasterBeautiful444 [link] [comments]

  • Best domain registrars for buying and managing domains, what are people using lately?
    by /u/Commo-ztwhrpfKnee824 on September 15, 2026 at 7:02 am

    Hey, been looking at domain registrars for a few names I want to pick up and I’m kinda over the random fee games and clunky dashboards. I just want something that’s easy to buy through, manage renewals, DNS, maybe transfer stuff later without feeling like a headache. What are people actually using these days for this? I know there’s a bunch of big names but I’d rather hear what feels solid in real use. thanks in advance submitted by /u/Commo-ztwhrpfKnee824 [link] [comments]

  • Leaving my current host after a massive outage. Need a truly reliable VPS hosting UK host.
    by /u/seowithumang on September 14, 2026 at 1:43 pm

    My current VPS provider had a pretty serious outage recently, and it made me realise how much I’ve been taking uptime for granted. The server was unavailable for hours, and unfortunately there wasn’t much useful communication during the incident. I can accept occasional maintenance, but when a VPS is running websites and applications that people actually use, reliability matters more than saving a few pounds each month. I’m now looking for a reliable UK VPS hosting provider. Ideally, I want UK based infrastructure, NVMe storage, proper backups, root access, and responsive support. I’m also trying to understand whether an advertised 99.9% uptime SLA actually means anything in practice. I’ve come across Fast Panda while comparing UK VPS options, but I’d rather hear from actual users before making a decision. Has anyone here used them for a production VPS? How has the uptime been over several months? submitted by /u/seowithumang [link] [comments]

  • What’s better for website hosting? VPS or dedicated server?
    by /u/Zahreddine-Issayas on September 14, 2026 at 10:37 am

    I’ve been using a basic hosting plan for a couple of sites, but I’m starting to run into some limits. Now I’m looking at VPS hosting and dedicated servers, mostly because I want a bit more room to grow, and I don’t think I need anything massive yet. Would a VPS be enough for this, or is there a good reason to go dedicated sooner? submitted by /u/Zahreddine-Issayas [link] [comments]

Leave a Reply

Your email address will not be published. Required fields are marked *