Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

1–10 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#3
Is there any confirmation on this?

[edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500

But it may just be random coincidence.

[edit again]

Links from slashdot article:

IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc

Re: Linode hacked, CCs and passwords leaked

#5

Is there any confirmation on this? [edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500 But it may just be random coincidence. [edit again] Links from slashdot article: IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg... Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc

That tweet would suggest to me that someone's credit card was stolen via another method and used to purchase Linode services, rather than the other way around. Ie, I don't think that was related to Linode breach.

Re: Linode hacked, CCs and passwords leaked

#6
From a purported abridged chatlog with the alleged hacker:

> 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security

> 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory

http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Re: Linode hacked, CCs and passwords leaked

#7
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

[deleted]

Re: Linode hacked, CCs and passwords leaked

#8
Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day.

If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web server.

Re: Linode hacked, CCs and passwords leaked

#9
My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015

Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it was leaked through Linode other than the compromise happening at the same time these supposed leaks happened).

Re: Linode hacked, CCs and passwords leaked

#10

Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…

It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.
Post reply on HN