Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

11–20 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#12
post #10

Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…

It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.

The hacker claims it to be a CF 0-day vulnerability:

> 05:05 manager.linode.com was breached with a coldfusion exploit

...

> 05:33 ryan||: give us the link to cold fusion vulnerability that you are talking about

> 05:34 Ruchira: 0day

> 05:34 linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000

Re: Linode hacked, CCs and passwords leaked

#13
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

Re: Linode hacked, CCs and passwords leaked

#14
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

The paste-bin link he provided seems to time out for me.

But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.

Re: Linode hacked, CCs and passwords leaked

#15

Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…

Was it a 0-day? The purported linode chatlog makes it sound like poorly configured CF:

http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

--------- 05:43 Well linode also had terribly configured coldfusion

05:57

05:57 this code

05:57 It's so dirty I feel bad reading it

Re: Linode hacked, CCs and passwords leaked

#16
post #10

Earlier quoted context omitted.

It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.

The hacker claims it to be a CF 0-day vulnerability: > 05:05 manager.linode.com was breached with a coldfusion exploit ... > 05:33 ryan||: give us the link to cold fusion vulnerability that you are talking about > 05:34 Ruchira: 0day > 05:34 linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000

Depending on who you're talking to, an app-level vulnerability in a Linode management console might be called a "0-day". But it's true that a CF stack flaw is not impossible.

Re: Linode hacked, CCs and passwords leaked

#17
post #14
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

The paste-bin link he provided seems to time out for me. But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.

pastebin is a directory listing of linode.com - trying out a few of the files checks out, including very difficult to guess file names such as:

http://www.linode.com/y_key_57284cb2de704e02.html

Re: Linode hacked, CCs and passwords leaked

#18
post #13
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

Extensive PCI audits. Heh.

Re: Linode hacked, CCs and passwords leaked

#19
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

That's totally shit.

Its also why we invoice and take wire payments rather than storing CC details. There's just so much to go wrong.

Also PKI is shit for this sort of thing. As demonstrated, the moment that public key is gone, then the whole system falls like a house of cards. For the non believers of this fact, why else would there be a certificate revocation list and root CA updates for windows periodically...

Re: Linode hacked, CCs and passwords leaked

#20
post #14
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

The paste-bin link he provided seems to time out for me. But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.

[deleted]
Post reply on HN