4 ms·
A customer warned Linode team about the exposed CF folder. CEO aggressively shrugged it off. "That doesn't matter, it's nothing, that's a non issue." Dev who wa
by throway-not-909 11y ago
A customer warned Linode team about the exposed CF folder. CEO aggressively shrugged it off. "That doesn't matter, it's nothing, that's a non issue." Dev who was a bit of a suck up parroted the same telling support to shut up about it. This was six months before HTP happened.
- ryanlol 11y agoWe were aware of it for probably an year before anyone bothered to spend 10 minutes looking at coldfusion source. That's all the time it took.
- mapgrep 11y agoV interesting. Do any of the other VPS providers strike you as more secure alternatives?
- ryanlol 11y agoI'd avoid VPS providers in general, but AWS is on a whole different level than linode. They actually understand what they're doing well enough to do live xen patching etc. But yeah, people get hacked through their hosts all the time. Best approach is colo with minimum access for the dc staff.
- nickpsecurity 11y agoThat's been my recommend for a long time. Plus, I liked obfuscating with unusual CPU choices and network guards (esp for protocol layers). Worked wonders with about no effort outside setting up guards. Opponents throw so much x86 shellcode at your Alpha, etc boxes while never quite getting stuff to run.