5 ms·
I was just thinking the same thing. I've been a customer for >10 years but this is getting ridiculous. First 2013 attack was apparently exacerbated by cleartex
by mapgrep 11y ago
I was just thinking the same thing. I've been a customer for >10 years but this is getting ridiculous.
First 2013 attack was apparently exacerbated by cleartext password storage for LISH (their management shell) and API tokens https://marco.org/2013/04/16/linode-hacked https://marco.org/2013/04/16/linode-hacked
The 2012 Bitcoin attack involved a breach of Linode's customer service portal
http://arstechnica.com/business/2012/03/bitcoins-worth-228000-stolen-from-customers-of-hacked-webhost/ http://arstechnica.com/business/2012/03/bitcoins-worth-22800...
Today's attack is some kind of unspecified or unknown breach involving Linode manager.
I guess the obvious commonality here is that all the attacks target the "soft" Linode layers AROUND managing deploys of Linux and Xen/KVM/UML rather than the "hard" targets of those widely used systems. This also happens to be the layer where Linode should be adding value (as opposed to the cheaper VPS providers out there) and I think it's increasingly troublesome that they continue to have such severe security issues.
Is this company (CEO - Christopher Aker) not investing in security staff, security training, best practices etc, or are they investing tons and just getting breached because they host so many sites? Unclear. But it's easy to imagine it's the former, from the outside, given all these incidents.
- ryanlol 11y agoActually the 2013 hack was caused by linode running blatantly misconfigured CF installations, like doing stuff that the manual has big warnings about.
- sarciszewski 11y agoFor those not in the know, ryanlol was one of the people on the team involved in the 2013 hacks.
- throway-not-909 11y agoReally? Thomas Asaro told us they were all in jail.
- ryanlol 11y agoNobody went to jail, I'm the only person being prosecuted. I won't go to jail.
- sarciszewski 11y agoI know of at least one other of the alleged HTP members who is not only not arrested, but still actively involved in the information security community. Then there are other personalities that went dark, whom are presumably also not arrested. Unless Thomas Asaro can name names, that was a bluff.
- throway-not-909 11y agoA customer warned Linode team about the exposed CF folder. CEO aggressively shrugged it off. "That doesn't matter, it's nothing, that's a non issue." Dev who was a bit of a suck up parroted the same telling support to shut up about it. This was six months before HTP happened.
- ryanlol 11y agoWe were aware of it for probably an year before anyone bothered to spend 10 minutes looking at coldfusion source. That's all the time it took.
- mapgrep 11y agoV interesting. Do any of the other VPS providers strike you as more secure alternatives?
- ryanlol 11y agoI'd avoid VPS providers in general, but AWS is on a whole different level than linode. They actually understand what they're doing well enough to do live xen patching etc. But yeah, people get hacked through their hosts all the time. Best approach is colo with minimum access for the dc staff.
- nickpsecurity 11y agoThat's been my recommend for a long time. Plus, I liked obfuscating with unusual CPU choices and network guards (esp for protocol layers). Worked wonders with about no effort outside setting up guards. Opponents throw so much x86 shellcode at your Alpha, etc boxes while never quite getting stuff to run.
- threeseed 11y agoThe best thing about the 2013 hack was that news of it was on Slashdot days before it was mentioned to customers. I've been consistently saying this for years. Linode is a joke and you would be crazy to use them for anything other than toy/non-critical use cases.