Linode hacked, CCs and passwords leaked
11–20 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#12Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…
It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.
> 05:05 manager.linode.com was breached with a coldfusion exploit
...
> 05:33 ryan||: give us the link to cold fusion vulnerability that you are talking about
> 05:34 Ruchira: 0day
> 05:34 linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000
Re: Linode hacked, CCs and passwords leaked
#13From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Re: Linode hacked, CCs and passwords leaked
#14From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.
Re: Linode hacked, CCs and passwords leaked
#15Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
--------- 05:43 Well linode also had terribly configured coldfusion
05:57
05:57 this code
05:57 It's so dirty I feel bad reading it
Re: Linode hacked, CCs and passwords leaked
#16Earlier quoted context omitted.
It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.
The hacker claims it to be a CF 0-day vulnerability: > 05:05 manager.linode.com was breached with a coldfusion exploit ... > 05:33 ryan||: give us the link to cold fusion vulnerability that you are talking about > 05:34 Ruchira: 0day > 05:34 linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000
Re: Linode hacked, CCs and passwords leaked
#17From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
The paste-bin link he provided seems to time out for me. But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.
Re: Linode hacked, CCs and passwords leaked
#18From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?
Re: Linode hacked, CCs and passwords leaked
#19From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Its also why we invoice and take wire payments rather than storing CC details. There's just so much to go wrong.
Also PKI is shit for this sort of thing. As demonstrated, the moment that public key is gone, then the whole system falls like a house of cards. For the non believers of this fact, why else would there be a certificate revocation list and root CA updates for windows periodically...
Re: Linode hacked, CCs and passwords leaked
#20From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
The paste-bin link he provided seems to time out for me. But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.