Live data from Hacker News

Ramnode down after SolusVM vulnerability exposed

ramnode.com

1–10 of 16 posts

Re: Ramnode down after SolusVM vulnerability exposed

#2
Ramnode's SolusVM was hacked earlier and attempting to log in gave you a list of every single subsciber's email address, name, and root password (plain text) to their VPS as well as IP address. Source: http://www.reddit.com/r/webdev/comments/1gga3n/ramnode_hacke...

http://localhost.re/p/solusvm-11303-vulnerabilities

http://www.webhostingtalk.com/showthread.php?t=1276286

If you use SolusVM: http://blog.soluslabs.com/2013/06/16/important-security-aler...

"We are working to get things back online. We were hit with a SolusVM exploit late last night." (https://twitter.com/RamNode)

Happy Father's Day!

Re: Ramnode down after SolusVM vulnerability exposed

#3
post #2

Ramnode's SolusVM was hacked earlier and attempting to log in gave you a list of every single subsciber's email address, name, and root password (plain text) to their VPS as well as IP address. Source: http://www.reddit.com/r/webdev/comments/1gga3n/ramnode_hacke... http://localhost.re/p/solusvm-11303-vulnerabilities http://www.webhostingtalk.com/showthread.php?t=1276286 If you use SolusVM: http://blog.soluslabs.com/2…

Confirmation from Ramnode twitter "We are working to get things back online. We were hit with a SolusVM exploit late last night."

Re: Ramnode down after SolusVM vulnerability exposed

#5
post #4

Sigh. I'm glad I didn't give them any billing information (monthly invoice paid each time via Paypal). It's not clear to me how/why root passwords are compromised by this exploit; anyone care to elaborate?

Stupidity, or appalling ignorance on the part of the SolusVM developers.

Re: Ramnode down after SolusVM vulnerability exposed

#7
post #4

Sigh. I'm glad I didn't give them any billing information (monthly invoice paid each time via Paypal). It's not clear to me how/why root passwords are compromised by this exploit; anyone care to elaborate?

It's talking about the auto-generated root password that gets emailed to you upon creation of your VM initially. Most everyone would, hopefully, have changed his/her root password manually, upon receiving it in email via cleartext.

Re: Ramnode down after SolusVM vulnerability exposed

#10
post #2

Ramnode's SolusVM was hacked earlier and attempting to log in gave you a list of every single subsciber's email address, name, and root password (plain text) to their VPS as well as IP address. Source: http://www.reddit.com/r/webdev/comments/1gga3n/ramnode_hacke... http://localhost.re/p/solusvm-11303-vulnerabilities http://www.webhostingtalk.com/showthread.php?t=1276286 If you use SolusVM: http://blog.soluslabs.com/2…

Is this known to only affect authorised users in Solus?
Post reply on HN