hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : VPS Hosting : Linode Management console compromised
Reply

VPS Hosting Virtual private server discussion and vps hosting solutions. Review VPS hosting providers and offer advice on virtual web hosting solutions. If your service is unavailable, please click here.
Forum Jump

Linode Management console compromised

Reply Post New Thread In VPS Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-01-2012, 05:21 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49

Linode Management console compromised


Hi Guys,

A very well respected service in the Bitcoin community was hacked today. Lots of money stolen. It appears to be an issue with the Linode management console. This puts all VPS's at risk

Please see:
http://pastebin.com/UW7iT5fj (Title: Linode hack)
https://bitcointalk.org/index.php?topic=66916 (The forum post)

About 25,000 coins were stolen (at current rate thats ~$120k in losses)

Reply With Quote


Sponsored Links
  #2  
Old 03-01-2012, 05:22 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49
PLEASE: check your systems for reboots / changed root passwords ASAP!

Reply With Quote
  #3  
Old 03-01-2012, 05:25 PM
UNIXy UNIXy is offline
Warp Speed!
 
Join Date: Feb 2008
Location: Houston, Texas, USA
Posts: 2,771
I'm curious to know what this means exactly:

Quote:
Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring.
Regards

__________________
|- UNIXY :: Fully Managed Servers and Clusters Since 2006
|- DC POP :: Houston, Los Angeles, Atlanta, & Rotterdam NL
|- Managed Magento Varnish Servers w/ ESI. < 250ms Page Load / TTFB
L- We LOVE helping our clients!

Reply With Quote
Sponsored Links
  #4  
Old 03-01-2012, 05:41 PM
Kaiousama Kaiousama is offline
Newbie
 
Join Date: Sep 2009
Posts: 28
Linode Super Admin Account Hacked!

Today, two Bitcoin related websites (Slush Mining, the 3rd/2nd largest pool, and the Bitcoin Faucet) were hacked. Both of these servers were on Linode.

Unlike most stories though, this one revealed a huge security breech on Linode's side rather than the site owners. A customer/technical support admin account was compromised, and the attacker was then able to modify passwords on customer accounts, giving them complete access to any system that was under Linode's control.

At least 3,000 Bitcoins were stolen in the attack, meaning $12,000 of actual theft took place as a result of the attack, and unknown amounts of data was compromised across Linode servers. The recipient's Bitcoin address had more than that, but whether or not these were all obtained from the attack is unknown.

A copy of the email correspondence with Linode support was posted by the owner of the Slush Bitcion Mining pool on the bitcoin official forums:

http://pastebin.com/UW7iT5fj

Reply With Quote
  #5  
Old 03-01-2012, 05:50 PM
MrLadoodle MrLadoodle is offline
Junior Guru
 
Join Date: Dec 2009
Location: United Kingdom
Posts: 203
My linode dosen't seem to have been compromised,

__________________
NerdyVPS - You Will Be Assimilated
PiePanel

Reply With Quote
  #6  
Old 03-01-2012, 06:54 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49

Reply With Quote
  #7  
Old 03-01-2012, 07:16 PM
Flapadar Flapadar is offline
Premium Member
 
Join Date: Jun 2011
Location: Aberdeen
Posts: 2,130
It's lucky Xen systems aren't as easy to access as OpenVZ. Everyone with password authentication should log in and disable it while Linode carry out their investigation.

Reply With Quote
  #8  
Old 03-01-2012, 07:20 PM
Virtual Rack Host Virtual Rack Host is offline
Junior Guru Wannabe
 
Join Date: Feb 2012
Location: USA
Posts: 33
Wow, we were going to setup VPS using OpenVZ but after this story I think we will stick with Xen. Our purchase for VPS is on hold until this is taken care of. Thank you for the update sellmestuff.

Reply With Quote
  #9  
Old 03-01-2012, 07:22 PM
Flapadar Flapadar is offline
Premium Member
 
Join Date: Jun 2011
Location: Aberdeen
Posts: 2,130
Quote:
Originally Posted by Virtual Rack Host View Post
Wow, we were going to setup VPS using OpenVZ but after this story I think we will stick with Xen. Our purchase for VPS is on hold until this is taken care of. Thank you for the update sellmestuff.
OpenVZ will only be less secure if the intruder managed to gain access to Linode's nodes. (vzctl enter or /vz/private). Of course when it comes to vulnerable data... you can't assume the intruder didn't get access until after an investigation.

Reply With Quote
  #10  
Old 03-01-2012, 07:29 PM
Virtual Rack Host Virtual Rack Host is offline
Junior Guru Wannabe
 
Join Date: Feb 2012
Location: USA
Posts: 33
Thanks Flapadar. When would be a good time to grab the VPS using Xen?

Reply With Quote
  #11  
Old 03-01-2012, 07:32 PM
Flapadar Flapadar is offline
Premium Member
 
Join Date: Jun 2011
Location: Aberdeen
Posts: 2,130
Quote:
Originally Posted by Virtual Rack Host View Post
Thanks Flapadar. When would be a good time to grab the VPS using Xen?
Now that they're aware of the hack, it's probably safe. It will be remnants from the hack that will cause problems (Customers with changed root pw etc) If you were planning a Xen VPS from Linode, I'd personally get it now and just spend a little extra time securing it (SSH keys, disable password login, perhaps even block SSH from any IPs that aren't in your ISP's range)

Reply With Quote
  #12  
Old 03-01-2012, 07:38 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49
Quote:
Originally Posted by Flapadar View Post
Now that they're aware of the hack, it's probably safe. It will be remnants from the hack that will cause problems (Customers with changed root pw etc) If you were planning a Xen VPS from Linode, I'd personally get it now and just spend a little extra time securing it (SSH keys, disable password login, perhaps even block SSH from any IPs that aren't in your ISP's range)
Didn't you read the post at all?

If the management console was seized, it'd be just as easy to reboot your server into single user mode and do whatever you want. Regardless of SSH keys or anything.

Reply With Quote
  #13  
Old 03-01-2012, 07:39 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49
It has nothing to do with OpenVZ or Xen.. It's Linode's management console which allows access to the server from the panel. jeez guys, come on. At least read before you post.

Reply With Quote
  #14  
Old 03-01-2012, 08:48 PM
subigo subigo is offline
Web Hosting Master
 
Join Date: Dec 2001
Location: MO
Posts: 629
Quote:
Originally Posted by Flapadar View Post
It's lucky Xen systems aren't as easy to access as OpenVZ. Everyone with password authentication should log in and disable it while Linode carry out their investigation.
Read before you post, cowboy.

Reply With Quote
  #15  
Old 03-01-2012, 11:06 PM
sellmestuff sellmestuff is offline
Junior Guru Wannabe
 
Join Date: Jan 2010
Posts: 49

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
FSCKVPS Management Console turlockaviator VPS Hosting 9 08-17-2009 12:30 PM
New VPS Management Console - Review stuartornum Other Reviews 28 04-17-2009 12:30 AM
Best Server Management Console? LoganNZ Dedicated Server 3 04-07-2008 01:03 PM
virtuozzo4 and new management console (Stephen) VPS Hosting 0 03-03-2008 12:48 PM
server management via serial console superman_1972 Colocation and Data Centers 18 02-14-2005 09:16 PM

Related posts from TheWhir.com
Title Type Date Posted
Name.com Resets Customer Passwords After Security Breach Web Hosting News 2013-05-13 14:43:19
Unpatched Adobe ColdFusion Vulnerability Made Linode Hack Possible Web Hosting News 2013-04-16 16:16:35
Linode Resets Passwords After Discovering Customer Hacking Attempt Web Hosting News 2013-04-15 13:25:41
Hackers Break Into Web Host Linode, Steal $228K in Bitcoins from Customers Web Hosting News 2012-03-02 10:35:36
Cloud Infrastructure Firm Linode Launches Load Balancer as a Service Web Hosting News 2011-07-15 19:05:12


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?