The chatlog does provide some evidence that it is indeed the hacker, but does little to convince me that he got CC info and Linode is not telling us the whole truth. The evidence he provides is just simple source code snips and the directory listing, which would be expected based on what Linode has told us. This could very well be the hackers own submission to /. trying to get more attention for his hack by claiming…
Linode hacked, CCs and passwords leaked
31–40 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#32Earlier quoted context omitted.
It wouldn't take a zero-day flaw in the Coldfusion stack for a CF application to have an undocumented vulnerability; in fact, it's much more likely that the vulnerability is in the application code than in the stack itself.
A patch has recently been issued (09 APR 2013) by Adobe for the various versions of ColdFusion: "This hotfix resolves a vulnerability that could be exploited to impersonate an authenticated user (CVE-2013-1387). "This hotfix resolves a vulnerability that could be exploited by an unauthorized user to gain access to the ColdFusion administrator console (CVE-2013-1388)." http://www.adobe.com/support/security/bulletins/a…
Re: Linode hacked, CCs and passwords leaked
#33Re: Linode hacked, CCs and passwords leaked
#34I think that Linode did a big mistake here. Let's wait for a formal communication.
But this is the moment to support them. Yes, maybe sounds crazy.
When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work, and this guys do great work in the hosting business. Just my opinion.
Re: Linode hacked, CCs and passwords leaked
#35The chatlog does provide some evidence that it is indeed the hacker, but does little to convince me that he got CC info and Linode is not telling us the whole truth. The evidence he provides is just simple source code snips and the directory listing, which would be expected based on what Linode has told us. This could very well be the hackers own submission to /. trying to get more attention for his hack by claiming…
Re: Linode hacked, CCs and passwords leaked
#36From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Hello,
Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation.
We have no comment regarding ryan*'s comments in #linode. You are of course free to take any steps you deem prudent or necessary to ensure the integrity of your online presence.
I am sorry that we cannot provide more information at this time. As always feel free to contact us at any time with any future concerns.
Regards,
QuintinRe: Linode hacked, CCs and passwords leaked
#3706:07 They say there's no 'central weak point'
06:07 Yeah there is, there's the developers
06:08 There's been bugs in the client that have allowed the blockchain to split previously
06:08 One could just backdoor the bitcoin client binaries, not the source.
06:08 Nobody would figure it out until it's too late
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Re: Linode hacked, CCs and passwords leaked
#38Re: Linode hacked, CCs and passwords leaked
#39If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…
Re: Linode hacked, CCs and passwords leaked
#40From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?
The 'lower' your level, the easier the PCI audits are. If you are level 1 you have mandatory external audits. If you are level 2 you have a 'self assessment' which is basically a checklist which says "Yes, I promise I'm in compliance".
If you have a confirmed breach, you are upgraded to Level 1 merchant audit requirements. This is generally quite costly as the external audit is extensive and must be paid for.