Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

41–50 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#41

Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…

I wonder if Linode has a requirement to have their CF admin site accessible outside their network (assuming, of course, that the attacker didn't first gain entry into the corporate network, and then attacked the CF installation)?

As someone who still maintains a very old CF application, I am sure to lock down access to the admin site via IP restrictions.

Re: Linode hacked, CCs and passwords leaked

#42

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not sure how useful that reset was. All I had to do was type in my old password and then choose a new one. No email verification, no reset token, nothing. So if the password was indeed compromised, couldn't the attacker do the same?

Re: Linode hacked, CCs and passwords leaked

#43
post #16

Earlier quoted context omitted.

The hacker claims it to be a CF 0-day vulnerability: > 05:05 manager.linode.com was breached with a coldfusion exploit ... > 05:33 ryan||: give us the link to cold fusion vulnerability that you are talking about > 05:34 Ruchira: 0day > 05:34 linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000

Depending on who you're talking to, an app-level vulnerability in a Linode management console might be called a "0-day". But it's true that a CF stack flaw is not impossible.

"... CF stack flaw is very possible and almost always likely ..."

There, I fixed it for you. Working with ColdFusion is like this: http://25.media.tumblr.com/38d67be62da60b4d3aa1d0ac22e4e314/...

Re: Linode hacked, CCs and passwords leaked

#44
post #13

Earlier quoted context omitted.

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

I've done PCI "audits" for several companies I've worked for; it's a checklist you go down yourself . That's why its called a "pci self assessment".

Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair.

We are not one of those.

Re: Linode hacked, CCs and passwords leaked

#46

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

Don't be so logical please. This can happend to anyone in the industry.

"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security"

That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.

Re: Linode hacked, CCs and passwords leaked

#47
post #16

Earlier quoted context omitted.

Depending on who you're talking to, an app-level vulnerability in a Linode management console might be called a "0-day". But it's true that a CF stack flaw is not impossible.

"... CF stack flaw is very possible and almost always likely ..." There, I fixed it for you. Working with ColdFusion is like this: http://25.media.tumblr.com/38d67be62da60b4d3aa1d0ac22e4e314/...

The problem I have balancing the likelihood of CF stack bugs vs. CF app bugs is that I've had to assess a bunch of CF apps, and they're uniformly coded to mid-1990s best practices. No matter how many bugs have been announced in the CF stack, as a betting man my money would always be on CF app bugs.

Re: Linode hacked, CCs and passwords leaked

#48

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill.

I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.

Re: Linode hacked, CCs and passwords leaked

#49

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Switched to https://www.digitalocean.com/ last week. Excellent service and pricing.

Re: Linode hacked, CCs and passwords leaked

#50

The chatlog does provide some evidence that it is indeed the hacker, but does little to convince me that he got CC info and Linode is not telling us the whole truth. The evidence he provides is just simple source code snips and the directory listing, which would be expected based on what Linode has told us. This could very well be the hackers own submission to /. trying to get more attention for his hack by claiming…

Doubting the claims of a hacker after it's known that they compromised a system is really bad OpSec. Consider everything burned.

That's a fair point. I'm speaking more as a judge/jury view on the situation though. I don't think Linode users should panic and run for the hills just yet based off this alone.
Post reply on HN