Security Notification and Linode Manager Password Reset
81–90 of 173 posts
Re: Security Notification and Linode Manager Password Reset
#82I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…
I honestly don't understand why anyone would be stupid enough to use Linode.
They continue to (a) have incidents and (b) fail to disclose them in a timely and transparent manner.
Re: Security Notification and Linode Manager Password Reset
#83Re: Security Notification and Linode Manager Password Reset
#84Glad they posted it. I just logged into one of my linode boxes that I don't use for very much but keep around, and it was rooted... doh.
Re: Security Notification and Linode Manager Password Reset
#85Re: Security Notification and Linode Manager Password Reset
#86I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…
If the Linode Manager database only stores the hash, how would they know the password? How did you find out about the illicit login?
In fact, depending on how the sessions are managed the attacker might just need read access to log in without a password.
Re: Security Notification and Linode Manager Password Reset
#87Re: Security Notification and Linode Manager Password Reset
#88Re: Security Notification and Linode Manager Password Reset
#89So, outside of the major cloud providers, what are the good alternatives?