Slicehost Forum User database compromised
11–16 of 16 posts
Re: Slicehost Forum User database compromised
#12Just logged in but was not prompted to reset my password. Re-read the statement a couple times, but its pretty clear this should have happened.
To the forum, or to their management site? Only the forum was compromised, and heading to http://forum.slicehost.com/ takes you here: http://www.rackspace.com/knowledge_center/content/slicehost-...
Re: Slicehost Forum User database compromised
#13Just logged in but was not prompted to reset my password. Re-read the statement a couple times, but its pretty clear this should have happened.
> Just logged in but was not prompted to reset my password. Re-read the statement a couple times, but its pretty clear this should have happened. To the forum, or to their management site? Only the forum was compromised, and heading to http://forum.slicehost.com/ takes you here: http://www.rackspace.com/knowledge_center/content/slicehost-...
However, if you used your Slicehost forum I.D. and password in other places, including any Rackspace account, we recommend that you change those I.D.s and passwords. In fact, the next time you attempt to access the Slice Manager, you will be required to change your password. If you use the same password for the forum and for your Slicehost account, and you also use an API key, we recommend that you consider changing the API key as well.
Re: Slicehost Forum User database compromised
#14First Linode and now Slicehost. What's happening to quality VPS these days? Just a wild guess here, but perhaps the same person who compromised Linode's customer service portal was also trying to see if any of his targets were reusing their Slicehost account credentials in the forum?
Re: Slicehost Forum User database compromised
#15Re: Slicehost Forum User database compromised
#16First Linode and now Slicehost. What's happening to quality VPS these days? Just a wild guess here, but perhaps the same person who compromised Linode's customer service portal was also trying to see if any of his targets were reusing their Slicehost account credentials in the forum?
A support forum being compromised is much different than using the company's internal tools to root systems. I'm guessing they use a 3rd party support forum (eg vBulletin). Maybe a vulnerability in it lead to the breach?