Ramnode down after SolusVM vulnerability exposed
11–16 of 16 posts
Re: Ramnode down after SolusVM vulnerability exposed
#12Sigh. I'm glad I didn't give them any billing information (monthly invoice paid each time via Paypal). It's not clear to me how/why root passwords are compromised by this exploit; anyone care to elaborate?
It's talking about the auto-generated root password that gets emailed to you upon creation of your VM initially. Most everyone would, hopefully, have changed his/her root password manually, upon receiving it in email via cleartext.
Re: Ramnode down after SolusVM vulnerability exposed
#13Apparently there are allegation going around that it was done by a competitor, servercrate. http://lowendtalk.com/discussion/comment/284016/#Comment_284...
Re: Ramnode down after SolusVM vulnerability exposed
#14We need more things like OpenStack out there -- competently designed and implemented toolstacks that actually work correctly and have a remotely acceptable security model.
Re: Ramnode down after SolusVM vulnerability exposed
#15It was ridiculously fast for a vm (>700MB/s with vpsbench, all tests), but the $5/mo Digital Ocean instances were fast enough with PostgreSQL/Sphinx that none of my (free) users were complaining. I like Digital Ocean, I'm keeping some stuff over there, but I appreciate Ramnode's transparency & dedication during this. It doesn't hurt that they're probably going to be constructively paranoid now that they've gotten burned. This is one of those things my partner saw all the time running a restaurant - screwups are unavoidable, but handling them well can actually get you a loyal customer.
Re: Ramnode down after SolusVM vulnerability exposed
#16Apparently there are allegation going around that it was done by a competitor, servercrate. http://lowendtalk.com/discussion/comment/284016/#Comment_284...
there's apparently a running joke for the less ethical types on lowendtalk to go around pwning people's sites and pretending to be robertclarke. He even got swat'ed the other day. Having read robertclarke's previous posts and knowing his ignorance of even basic Linux system administration, pretty sure he's just on the unfortunate end of an immature joke.