5 ms·
Edited version of the Linode log file for April 15th
- ZeroCoin 13y agoIf you're wondering, I stumbled upon that text file while reading the official company response to the recent hack here: http://blog.linode.com/2013/04/16/security-incident-update/ http://blog.linode.com/2013/04/16/security-incident-update/ I was interested in setting up a Linode account but I think it's best to wait for some more information at this point. Thoughts?
- turboroot 13y agoI signed up for Joyent yesterday, and was quite impressed with the performance. It's probably on par with Linode. The price is reasonable: $21/month for a 512 MB instance, and free 20,000 GB bandwidth! In addition, they offer freaking 2-factor authentication! That says a lot when the only ones I know of offering such are AWS and SoftLayer.
- orangethirty 13y agoYou created an account to post this on a thread about a competitor to Joyent? Funny.
- turboroot 13y agoWhy? Is it not appropriate? I assumed I could offer hosting alternatives since my post's parent author was asking for "thoughts". I don't work for Joyent, and I just signed up for them 2 days ago. Apologies if my post seemed like blatant advertising.
- magic_haze 13y ago> 06:00 < AlexC_> ryann: So, are you saying CC details have also been compromised? > 06:00 < ryann> Yep > 06:00 < AlexC_> ryann: And you plan on releasing these? > 06:00 < ryann> They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory Jesus Christ. I agree, there is something very wrong with how Linode is treating this situation. Cperciva's comment a couple of days back about the doubletalk in the official statement seems especially precinct, and the new claim about both the private and public keys for the credit card info being stored in the same place... appallingly incompetent if true.
- scraplab 13y agoThe CEO has already stated that the private key had passphrase encryption, which is strong, and only stored in their heads. You have to take their word on that, but I don't see any proof of CCs being decrypted.
- leeoniya 13y agoi cannot imagine that a remembered passphrase would take too long to brute-force on a few multi-GPU setups. unless they did something meaningful like making it a long sentence rather than some short-but-complex-for-humans 15 char string. http://xkcd.com/936/ http://xkcd.com/936/
- eridius 13y agoSpecifically what they said is it isn't stored digitally. So maybe they have it written down on a piece of paper.
- threeseed 13y agoBased on what we've seen before I wouldn't give Linode the benefit of the doubt. The password is most likely cracked by now.
- nodata 13y agoIt's a passphrase, not a password.
- err_badprocrast 13y ago07:52 < HTP> the CCrypter class of the linode application context was accessable from outside the wwwroot using undocumented ColdFusion methods. i was fully able to decrypt the ccs using the in-memory privkey that they supplied the password for. From the 2nd pastebin'd IRC log, http://pastebin.com/7WXRDyAg http://pastebin.com/7WXRDyAg Note that he states all information was deleted. They had claimed earlier that CC info would be released on May 1st. note: temp account because I accidentally set noprocrast delay to 1 week. Whoops!
- 13y ago
- threeseed 13y agoWow. I didn't realise just how incompetent Linode actually is. Not only terrible security at a coding level but completely non existent audits. I wonder what they were after if not money. What are people hosting ?
- err_badprocrast 13y agoNotably seclists/nmap is (was?) hosted on Linode and was tampered with in this attack. Apparently, the hackers looked up a Quora list of notable sites hosted on Linode and went after those [2], suggesting that the attackers wanted to burn a 0day for some notoriety or to damage Linode/Coldfusion reputation. 1. Technical info: http://arstechnica.com/security/2013/04/coldfusion-hack-used-to-steal-hosting-providers-customer-data/ http://arstechnica.com/security/2013/04/coldfusion-hack-used... 2. http://seclists.org/nmap-dev/2013/q2/40 http://seclists.org/nmap-dev/2013/q2/40
- TikiTDO 13y ago05:21 -!- mode/#linode [+b !ryan@54.228.197.*] by akerl 05:24 -!- ryan| [~violator@37.235.49.168] has joined #linode 05:24 < ryan|> quite rude of you 05:25 -!- ryan| was kicked from #linode by akerl [ryan|] 05:27 -!- root__ [~h@vmx13318.hosting24.com.au] has joined #linode 05:27 -!- root__ is now known as ryan|| 05:27 < ryan||> Quite rude out of you 05:27 < ryan||> To ban me like that Really puts into perspective the difference in the levels of skill involved. When dealing with someone of this level, they really should have just notified everyone immediately. There's no telling what info these people have now.
- InclinedPlane 13y agoUh, why? Because they have access to different IPs? That's trivial.
- TikiTDO 13y agoThe speed at which he switches hosts implies he's got quite a sophisticated tool chain set up for this. The level of skill really becomes parent if you read the rest of the log though.
- InclinedPlane 13y agoThere are several minutes of delay in there. I could just about set up a brand new VPS, ssh to it, install irssi and connect within that amount of time. Let alone logging into a system I already had set up. It does not impress me in the slightest bit.
- D9u 13y agoI agree... Then the skid chose the nick "root_" in an attempt at appearing to have "rooted" some box... It's no difficult task to ssh into another server and reconnect, and if "ryan" is who I think it is, he's a bot herder who enjoys DDoS attacks on those who upset his false sense of superiority. He's well versed in server management, but exploiting other's servers is what he's working towards, and he failed to crack a server belonging to some friends of mine, so his only recourse was a DDoS.