3 ms·
> Somehow, the attacker got KVM access credentials for the server. [...] After he got KVM access, the attacker convinced NFOrce that he was me (using his KVM ac
by CyberShadow 11y ago
> Somehow, the attacker got KVM access credentials for the server. [...] After he got KVM access, the attacker convinced NFOrce that he was me (using his KVM access as part of his evidence) and said that he had locked himself out of the server. So NFOrce reset the server's root password for him, giving him complete access to the server and bypassing most of our carefully-designed security measures...
Ugh. We need to remember that social engineering your ISP, hosting provider, etc. is a very real attack vector. Do not trust them.
Reminds me of the "N" twitter username story:
https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
- h1fra 11y agoStrangely, the N username now look likes a legit account. Or is it the same guy? https://twitter.com/n https://twitter.com/n
- jimlei 11y agoHe got it back like a month later. Just browse back in N's twitter feed (late february 2014)
- nadams 11y ago> convinced NFOrce that he was me > So NFOrce reset the server's root password for him So a couple of things: I do my hosting with gandi (moving away from self hosting as Comcast business is...well anyways...). I had setup TOTP with their service and my phone died and I lost my OTP key (lesson learned - always backup OTP keys - hint gitlab developers...). I had submitted a ticket and they called the number that was on the account and had me answer a few questions. I don't remember what the questions were - but they weren't certainly "can you reboot this server?". The simple fact that the company used that as verification should be a red flag. Here is another red flag - why does the hosting provider have the ability to reset a VM's root password? Gandi states that in their FAQ that they won't reset the root password - though they give you instructions on how to do that. Though if he had access to KVM (through virtsh or virt-manager ?) he could have easily reset it himself (which would require a reboot). Perhaps he wanted to be discrete as possible?
- sytse 11y agoGitLab CEO here, I don't understand the hint, when you set up 2FA on GitLab we give you backup codes to recover, but that might not be what you mean.