3 ms·
To answer some common questions about this article: Yes, I know my setup was very flawed. It was a test machine and in the midst of having automated config sc
by goodwink 14y ago
To answer some common questions about this article:
Yes, I know my setup was very flawed. It was a test machine and in the midst of having automated config scripts written for it which were being tested. This is why the machine was vulnerable to the attack, but this does not diminish the importance of the underlying compromise it exposes in DigitialOcean's setup.
The point of the article is that someone is able to gain access to DigitalOcean password reset emails or a database of root passwords which shouldn't exist, but seems to given that they set your root password back to a previously reset value after you rebuild your server from the base OS image.