Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
Hetzner Servers Compromised
21–30 of 133 posts
Re: Hetzner Servers Compromised
#22Earlier quoted context omitted.
They're a German Server/Webspace ISP - see www.hetzner.de/en
Not just German actually, they (Hetzner Online AG) have also got a subsidiary in South Africa ... http://www.hetzner.co.za/
But since this seems to be affecting only the main/german division, i didn't bother to mention them.
Re: Hetzner Servers Compromised
#23Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
Re: Hetzner Servers Compromised
#24Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
What types of hacks does that protect you from exactly, considering you don't have physical access and can't even see the hardware?
It also protects against hosting provider employees that detach the hard disk and attach it onto another machine to copy data off it.
If the server is virtualized, then in theory it's still possible that the attacker hacks into the hypervisor, and then through modifications in the hypervisor's RAM gains access to the guest kernel, and thus the guest system. However the skill that is required for this is an a whole new level compared to "regular" hacks.
If the attacker has physical access then it's still possible that he uses electromagnetic emissions from the hardware or power supply patterns to obtain information about it to hack the system. But again, this requires skills on a whole new level.
Re: Hetzner Servers Compromised
#25Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…
I am not a Hetzner customer, but the comment about Nagios perked up my ears. I work with some clients who have Nagios running in their environment, and I'm wondering if there is an exploit in Nagios or if it's just a coincidence that this was where they noticed the infection?
Re: Hetzner Servers Compromised
#26Considering https://twitter.com/omgtbh/status/337567604887658496 I can't say I'm surprised... (tweet text reproduced here: "I asked Hetzner if they plan to support 2 factor auth & was told that they already do - they require a username and a password. Seriously.")
Re: Hetzner Servers Compromised
#27Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
How does this help? The key is still stored in memory which I assume the hypervisor has access to.
Re: Hetzner Servers Compromised
#28Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
How does this help? The key is still stored in memory which I assume the hypervisor has access to.
Re: Hetzner Servers Compromised
#29Seriously, again?? I think such a fauxpas shouldn't be tolerated twice.
Re: Hetzner Servers Compromised
#30Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.
Do you have a very small number of servers? Requiring manual steps to boot is not very scalable--if there is an event that requires all your servers to reboot (power outage, mandatory upgrade, etc) you would be in quite a tough spot.