3 ms·
Someone commented on the posted article that the compromise seems to be from Godaddy itself. What I'm thinking is someone used a vulnerable 3rd party script ho
by sev 15y ago
Someone commented on the posted article that the compromise seems to be from Godaddy itself. What I'm thinking is someone used a vulnerable 3rd party script hosted on a shared server, then somehow got root or escalated privileges and compromised all or most of the sites hosted on the shared server. If the issue was Godaddy itself being hacked, I would assume it would affect all servers, not just the shared one(s).
- soult 15y agoIf somebody managed to compromise other customer's accounts via one shared hosting account, even if it is limited to a single server, then I would consider this as Godaddy being hacked.
- dibarra 15y agoYou can do this fairly easily with Apache and symlinks, there's an issue with SymlinksIfOwnerMatch that people can circumvent if they're clever...