Live data from Hacker News

How we discovered a database leak in one of the biggest Swiss hosting providers

security.infoteam.ch

21–30 of 68 posts

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#21
post #2

The moral of the story should have been -- change your hosting provider the minute they commit such a blunder.

Indeed. Like they say, fool me once, shame on you; fool me twice, shame on me. However how do you go about picking a new provider? How do you know that anyone else is any better?

nine.ch is better (disclaimer - I work for them ;) )

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#22
Security Guardian is not a he/him. It may be a translation issue ... or maybe you've achieved human-level AI and it's become self-aware? In any case, I find it interesting that your first response is that the tool might have a bug ... and the link also on HN at this moment is about the Apollo 13 mission control engineers thinking their telemetry might be at fault. This is an excellent first response and it's important to provide a way to distinguish between the two.

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#23

:s i can't even get my mysql to get me to be allowed to login root without password >. that besides pitching their own product for an issue any similar natured scan would pick up i'd say it smells like marketing department at work more than chinese hackers or shitty service provider.... >.> i doubt they would have left a passwordless root on their mysql, or didnt they check the initial setup they were given by the pr…

If you read the story you would see that the database host is a shared host (as in hundreds of other clients of the Webhost have accounts on it) and that the error is likely the result of a persistent hack. As in there is a vulnerability where someone can get access to the server and create a passwordless root account, so that they can siphon the data out.

Once that account is deleted, a new passwordless root account is created by the attacker in order to continue access.

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#24
post #8

For whoever was wondering who this provider is: according to whois-nslookup-mxtoolbox_arin_lookup, the server hosting infoteam.ch is provided by metanet (metanet.ch) Not trying to ruin their business, but they should consider handling issues like this one properly.

Maybe I’m wrong but the PTR of the IP seems to be in a spam blacklist:

https://apility.io/search?q=infoteam.ch

https://apility.io/search?q=80.74.143.113

https://apility.io/search?q=dynco.ch

This thing happens sometimes, specially if you use a shared hosting. Recently using a well known cloud provider the Public IP address assigned was in a spam blacklist! It’s a good idea to have a look at your IP and domains frequently.

(Disclaimer: I’m the founder of the tool used for the lookup in the blacklists)

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#25
A little update on the service Security Guardian after the publication of this post.

Thanks to Hacker News and its incredible community, there have been a massive number of new users. We are working on adding more resources to the infrastructure to make the scans quicker. For now, it is possible that some of you have to wait some hours before receiving the first results.

Thanks for trying our new product, we hope to improve it with your feedbacks.

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#26
post #8

For whoever was wondering who this provider is: according to whois-nslookup-mxtoolbox_arin_lookup, the server hosting infoteam.ch is provided by metanet (metanet.ch) Not trying to ruin their business, but they should consider handling issues like this one properly.

Sorry, but to avoid problem for now, we prefer to keep the provider anonymous, however we can assure you that it is not metanet.ch.

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#29
> "Hopefully, we had ‘only’ read access and could not write or delete anything"

Sounds a lot like feigned ignorance about the nature of the root user. Not entirely sure if it would help them in a court of law. They should probably anonymized the whole thing better to be completely on the safe side (not a lawyer though).

Re: How we discovered a database leak in one of the biggest Swiss hosting providers

#30
post #25

A little update on the service Security Guardian after the publication of this post. Thanks to Hacker News and its incredible community, there have been a massive number of new users. We are working on adding more resources to the infrastructure to make the scans quicker. For now, it is possible that some of you have to wait some hours before receiving the first results. Thanks for trying our new product, we hope to…

> Then, they blocked the IP address of our scanner so we could not scan their server anymore.

Long time lurker, made an account just to ask this: What are your comments on this unprofessional reaction from the Swiss?

Post reply on HN