Live data from Hacker News

Hetzner Servers Compromised

wiki.hetzner.de

41–50 of 133 posts

Re: Hetzner Servers Compromised

#41
Things seem to be getting worse there. A server we have there just went offline, and their management servers are not responding. I wonder it's part of the exploit or as a result of attempts to "fix" the problem

Re: Hetzner Servers Compromised

#42
post #28

Earlier quoted context omitted.

Hetzner provide a lot of physical machines too, I believe this is what the other poster was talking about.

Physical machines don't prevent keys from leaking out. A physical attacker can analyze power usage usage patterns to extract the encryption key. :)

I don't think you have that sidechannel with AES-NI. Besides, as a physical attacker cold boot attack would be much easier Or if the server has any interfaces with DMA, like PCI or something, that's even easier.

Re: Hetzner Servers Compromised

#43
post #18

Earlier quoted context omitted.

What types of hacks does that protect you from exactly, considering you don't have physical access and can't even see the hardware?

It protects against hackers that compromise the provider's administration interface, and then use that interface to reboot the server to single user mode or a rescue system. Upon reboot, the attacker will encounter an unusable blob as filesystem because he doesn't have the encryption key. It also protects against hosting provider employees that detach the hard disk and attach it onto another machine to copy data off…

Very good point about single user/rescue, thanks.

Re: Hetzner Servers Compromised

#44
post #38
post #29

Earlier quoted context omitted.

Do you have link to their previous hack?

In October 2011, unfortunately these links are in German only: http://www.heise.de/security/meldung/Web-Hoster-Hetzner-geha... http://www.heise.de/ix/meldung/Datenleck-bei-Hetzner-1356468... http://www.heise.de/security/meldung/Passwortklau-bei-Hetzne... There was unauthorized access to customer data, even passwords. Someone claims to have accessed it via an FTP-server where he found a root password to a management s…

Thanks for posting the links, I've forgot to mention it in all my wisdom, duh..

Re: Hetzner Servers Compromised

#45
post #2

Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…

I am not a Hetzner customer, but the comment about Nagios perked up my ears. I work with some clients who have Nagios running in their environment, and I'm wondering if there is an exploit in Nagios or if it's just a coincidence that this was where they noticed the infection?

I suspect it's simply out of date. Nagios does have a large surface area, but from what I've seen in the past, monitoring systems are very difficult for sysadmins to want to upgrade. :)

Re: Hetzner Servers Compromised

#46
Something was happening with their routers, too. Using PingPlotter to one of my servers shows severe packet loss on the hos-bb2.juniper2.rz19.hetzner.de router.

I see it just cleared up for now. Still, I'm moving my traffic to other locations till this blows over.

Re: Hetzner Servers Compromised

#47

Sigh, another hosting provider hack. As if Linode and OVH are not enough. This is the reason why we use full disk encryption, where we enter the key manually during boot. This way we're protected against many types of hosting provider hacks.

What if attacker infects unencrypted part used for booting? Do you have protection against that? It's relatively easy on Linux, where /boot is usually not encrypted.

Agreed, but typically /boot isn't automounted when it's a separate partition, which means they would need a root-access compromise already.

Re: Hetzner Servers Compromised

#48
Their SSL certificate is fucked for their security page... oh dear.

https://wiki.hetzner.de/index.php/Security_Issue/en

Hope everyone has fun with their identity theft cleanups. They ask people for ID scans.

Bank details are compromised.

boo!

This was announced AFTER the German work day was done. Really nice for admins. Thanks.

Re: Hetzner Servers Compromised

#49
post #14

Several events with Linode, now Hetzner. These are relatively "premier," high-quality hosting companies, you can count on thousands and thousands of companies to pay even less attention. Yet every time, the discussion is only about one specific company, without seeing any broader pattern. When are we ever going to draw the conclusion that popular hosting companies (and, actually related, facilities like RubyGems) are…

Assuming that the exploit really is unknown, what better security could they have done to prevent it, without severely impacting usability?

Compromises will happen sooner or later when running a large number of public facing services. With good policy, the breaches will be well contained, which seems to be the case here. What more can be expected out of a premier hosting company, let alone Hetzner which is very cheap budget provider?

Re: Hetzner Servers Compromised

#50
post #4
post #2

Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…

Have all Hetzner customers received this mail? I currently have a couple of servers with them and have received nothing yet.

I did not get it yet. Perhaps they are only sending to those who might be affected?
Post reply on HN