The moral of the story should have been -- change your hosting provider the minute they commit such a blunder.
Indeed. Like they say, fool me once, shame on you; fool me twice, shame on me. However how do you go about picking a new provider? How do you know that anyone else is any better?
How we discovered a database leak in one of the biggest Swiss hosting providers
21–30 of 68 posts
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#22Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#23:s i can't even get my mysql to get me to be allowed to login root without password >. that besides pitching their own product for an issue any similar natured scan would pick up i'd say it smells like marketing department at work more than chinese hackers or shitty service provider.... >.> i doubt they would have left a passwordless root on their mysql, or didnt they check the initial setup they were given by the pr…
Once that account is deleted, a new passwordless root account is created by the attacker in order to continue access.
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#24For whoever was wondering who this provider is: according to whois-nslookup-mxtoolbox_arin_lookup, the server hosting infoteam.ch is provided by metanet (metanet.ch) Not trying to ruin their business, but they should consider handling issues like this one properly.
https://apility.io/search?q=infoteam.ch
https://apility.io/search?q=80.74.143.113
https://apility.io/search?q=dynco.ch
This thing happens sometimes, specially if you use a shared hosting. Recently using a well known cloud provider the Public IP address assigned was in a spam blacklist! It’s a good idea to have a look at your IP and domains frequently.
(Disclaimer: I’m the founder of the tool used for the lookup in the blacklists)
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#25Thanks to Hacker News and its incredible community, there have been a massive number of new users. We are working on adding more resources to the infrastructure to make the scans quicker. For now, it is possible that some of you have to wait some hours before receiving the first results.
Thanks for trying our new product, we hope to improve it with your feedbacks.
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#26For whoever was wondering who this provider is: according to whois-nslookup-mxtoolbox_arin_lookup, the server hosting infoteam.ch is provided by metanet (metanet.ch) Not trying to ruin their business, but they should consider handling issues like this one properly.
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#27Their vulnerability scanner is basically an on-demand DOS attack. Tried it on my site and almost brought it down
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#28tl;dr, portscanned a server, found an open MySQL port with a weak password.
And the problem returned a week after the 'fixed' it.
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#29Sounds a lot like feigned ignorance about the nature of the root user. Not entirely sure if it would help them in a court of law. They should probably anonymized the whole thing better to be completely on the safe side (not a lawyer though).
Re: How we discovered a database leak in one of the biggest Swiss hosting providers
#30A little update on the service Security Guardian after the publication of this post. Thanks to Hacker News and its incredible community, there have been a massive number of new users. We are working on adding more resources to the infrastructure to make the scans quicker. For now, it is possible that some of you have to wait some hours before receiving the first results. Thanks for trying our new product, we hope to…
Long time lurker, made an account just to ask this: What are your comments on this unprofessional reaction from the Swiss?