Live data from Hacker News

Linode hacked again?

vpsboard.com

21–30 of 52 posts

Re: Linode hacked again?

#22
post #10

It looks like this is the same password from the last hack. Did they really not change their passwords?

Same mysql server also appeared to accept * as the password for the root user.

That doesn't really make any sense. That's not a MySQL default, so you're saying they intentionally set the root user password to '*'? I'm not sure I buy that.

Re: Linode hacked again?

#23
The mysql dump indicates the mysql server version they are running is 3.23.49 which was released in February of 2002. I guess if it works...

Re: Linode hacked again?

#25
post #24

Linode publishes logs of their IRC channel at https://www.linode.com/irc/logs/ , but it's currently returning "504 Gateway Time-out". Does anyone know offhand if that URL had previously been broken, or if Linode has taken the logs offline following the attack?

Logs are in the same network as the breached mysql server.

Re: Linode hacked again?

#27
I call bullshit.

These things are happening often enough for them to be a competitive strategy between rival VPS hosting companies.

(I happen to have servers hosted at Linode, Digital Ocean and a local provider, and always find it amusing to tally the amount of "happy customers" that pop up in comment threads like this)

Re: Linode hacked again?

#28
post #16

So I switched to Digital Ocean after the last Linode security fiasco and I can't say I regret it. Should you decide to switch to another VPS provider I strongly recommend you cite the security problems when they ask you why you're closing your account. The only reliable way to get the security message across to technical managers and business people alike is to make it about money. That said the fact that this has ha…

the security hack was always on back of my mind.

what really made me move away from linode is really their inability to accept paypal.

Luckily, digitalocean accepted paypal. Also their $5 servers cannot be beat.

Sure, linode has some good panels but it was more than I can chew and more than I needed. Digitalocean also had a good amount of docmentation to do everything I needed without filing a ticket.

Re: Linode hacked again?

#29
post #24

Linode publishes logs of their IRC channel at https://www.linode.com/irc/logs/ , but it's currently returning "504 Gateway Time-out". Does anyone know offhand if that URL had previously been broken, or if Linode has taken the logs offline following the attack?

http://thegrebs.com/irc/linode/2014/01/19 (Ads possibly NSFW)

Seems to have some logs of the linode channel today.

Re: Linode hacked again?

#30
post #16

So I switched to Digital Ocean after the last Linode security fiasco and I can't say I regret it. Should you decide to switch to another VPS provider I strongly recommend you cite the security problems when they ask you why you're closing your account. The only reliable way to get the security message across to technical managers and business people alike is to make it about money. That said the fact that this has ha…

Stop acting so dramatic. There's no evidence that there was any security breach. People on IRC are saying this is FUD.

zectorpt: no

zectorpt: nothing was "hacked", but old stuff got posted

again

Post reply on HN