I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…
Security Notification and Linode Manager Password Reset
71–80 of 173 posts
Re: Security Notification and Linode Manager Password Reset
#72Earlier quoted context omitted.
So, what happened during the AWS outage this past Fall? Or did you restructure to provide failover beyond just moving platforms?
Well, at linode you can't have a structure that is immune to failover, as they have single points of failure within their infrastructure, apart from anything else - all their London kit for instance lives in Telehouse East, in a few adjacent racks. Once we'd done the initial up sticks and move to AWS, our first priority was to use their redundancy and failover to the fullest (six months of sleepless nights due to lin…
Unless they've moved?
Re: Security Notification and Linode Manager Password Reset
#73Earlier quoted context omitted.
A customer warned Linode team about the exposed CF folder. CEO aggressively shrugged it off. "That doesn't matter, it's nothing, that's a non issue." Dev who was a bit of a suck up parroted the same telling support to shut up about it. This was six months before HTP happened.
We were aware of it for probably an year before anyone bothered to spend 10 minutes looking at coldfusion source. That's all the time it took.
Re: Security Notification and Linode Manager Password Reset
#74I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…
Unless, of course, the group involved in the breach are also the ones unleashing the DDoS attacks. Which would also make me think there has been communication between the group and Linode, in contrary to what Linode stated.
Re: Security Notification and Linode Manager Password Reset
#75I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…
I find this very interesting because I think it brings up a specific question. If this is actually from July, and they knew about it, why would Linode choose this specific time to announce the breach publicly? It seems very curious being that they are already getting punished from the DDoS attack and if they waited 6 months they could have waited until the dust settles a little bit. Unless, of course, the group invol…
Re: Security Notification and Linode Manager Password Reset
#76Earlier quoted context omitted.
I find this very interesting because I think it brings up a specific question. If this is actually from July, and they knew about it, why would Linode choose this specific time to announce the breach publicly? It seems very curious being that they are already getting punished from the DDoS attack and if they waited 6 months they could have waited until the dust settles a little bit. Unless, of course, the group invol…
I think since multiple customers were hit by this and are presumably all putting pressure on them about it, their hand may have been forced.
Re: Security Notification and Linode Manager Password Reset
#77Earlier quoted context omitted.
Well, at linode you can't have a structure that is immune to failover, as they have single points of failure within their infrastructure, apart from anything else - all their London kit for instance lives in Telehouse East, in a few adjacent racks. Once we'd done the initial up sticks and move to AWS, our first priority was to use their redundancy and failover to the fullest (six months of sleepless nights due to lin…
I don't think Telehouse East is correct. They're with Telecity, and in their PowerGate facility, i.e. out in Acton: http://www.telecitygroup.com/our-company/news/2010/linode-ex... Unless they've moved?
Re: Security Notification and Linode Manager Password Reset
#78Earlier quoted context omitted.
Difficult question to answer. There was a complete lack of "technical" evidence against me (e.g .bash_history files, wiretaps). The only evidence the prosecution had against me were a list of compromised sites and several coldfusion 0days I had in my possession. They could never prove that I generated the list of compromised sites, but the judges felt that the possession of said list was enough evidence to convict me…
> We would've appealed but there was no point as the sentence was essentially nothing. But you do end up with a record, which is not 'essentially nothing'.
Re: Security Notification and Linode Manager Password Reset
#79Earlier quoted context omitted.
We were aware of it for probably an year before anyone bothered to spend 10 minutes looking at coldfusion source. That's all the time it took.
V interesting. Do any of the other VPS providers strike you as more secure alternatives?
But yeah, people get hacked through their hosts all the time. Best approach is colo with minimum access for the dc staff.
Re: Security Notification and Linode Manager Password Reset
#80Earlier quoted context omitted.
Difficult question to answer. There was a complete lack of "technical" evidence against me (e.g .bash_history files, wiretaps). The only evidence the prosecution had against me were a list of compromised sites and several coldfusion 0days I had in my possession. They could never prove that I generated the list of compromised sites, but the judges felt that the possession of said list was enough evidence to convict me…
> We would've appealed but there was no point as the sentence was essentially nothing. But you do end up with a record, which is not 'essentially nothing'.