hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Dedicated Server : Layeredtech network hacked again, how?
Reply

Dedicated Server Current and past experiences with dedicated server providers, bandwidth, and server performance. Review managed and unmanaged dedicated web servers, discuss both Windows and Unix dedicated server solutions, and discuss dedicated hosting providers. If your service is unavailable, please click here.
Forum Jump

Layeredtech network hacked again, how?

Reply Post New Thread In Dedicated Server Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 10-26-2008, 11:09 AM
mikef374 mikef374 is offline
Junior Guru
 
Join Date: May 2007
Posts: 236
I've been reading that layeredtech's helpdesk or whatever they call there backend has been hacked again just a few days ago and the hackers got the customers root passwords. This happened about a year ago also with them. How does this keep happening?
I thought about not giving my datacenter my password but then if it goes down they can't do anything. What's the best thing to do?

Reply With Quote


Sponsored Links
  #2  
Old 10-26-2008, 11:28 AM
bear bear is offline
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,318
Where did you read this? Have a link?

Reply With Quote
  #3  
Old 10-26-2008, 11:30 AM
woods01 woods01 is offline
relax, im a professional
 
Join Date: Dec 2007
Posts: 1,277
If I recall correctly, when we hosted with LT (little under a year ago) they had the same thing happen. I've never heard of giving LT my passwords though they are unmanaged I believe.

Reply With Quote
Sponsored Links
  #4  
Old 10-26-2008, 11:56 AM
r00ter r00ter is offline
Web Hosting Master
 
Join Date: Feb 2006
Location: New York, NY
Posts: 704
I believe bear is talking about the incident you're referring to right now. You just said, "I've been reading..."

Reply With Quote
  #5  
Old 10-26-2008, 12:13 PM
CretaForce CretaForce is offline
Greece
 
Join Date: Jan 2004
Location: Greece
Posts: 2,039
Why someone will trust a dedicated company's portal with his dedicated server passwords?
I use Limestone's portal (managing a server for a customer) for a while and they have the option to provide the root password, keep it on their database and when you close the ticket the password automatically deleted from the database.

Reply With Quote
  #6  
Old 10-26-2008, 01:12 PM
mikef374 mikef374 is offline
Junior Guru
 
Join Date: May 2007
Posts: 236
Here's one i found on google http://www.stephanmiller.com/bugs-viruses-backups-and-prevedvsem123cn/ for the one that happened a few days ago on 10/20/2008. the one before that i think happened last year on Sep 2007 according to some posts i found.

Reply With Quote
  #7  
Old 10-26-2008, 01:15 PM
RyanD RyanD is offline
COLOCATE LIKE A BOSS
 
Join Date: Feb 2004
Location: Atlanta, GA
Posts: 5,527
Here's one i found on google http://www.stephanmiller.com/bugs-viruses-backups-and-prevedvsem123cn/ for the one that happened a few days ago on 10/20/2008. the one before that i think happened last year on Sep 2007 according to some posts i found.
that has notihng to do with LT, thats someone's individual server and poor security.

Reply With Quote
  #8  
Old 10-26-2008, 01:27 PM
mikef374 mikef374 is offline
Junior Guru
 
Join Date: May 2007
Posts: 236
that has notihng to do with LT, thats someone's individual server and poor security.
If you read the post, it says that every server he saw that happen on was at layered tech only. here's another one on google http://digg.com/security/Layered_Tech_Hacked_and_Affecting_Major_Sites
read the whole thing. here's a quote from that page: "I have contacts that have reported dozens and dozens of servers being affected by this recent exploit--- all at layered tech."

Reply With Quote
  #9  
Old 10-26-2008, 02:36 PM
jonsimmonds
Guest
 
Posts: n/a
Dear Layered Tech Customer ~
As a result of a routine internal security analysis, a vulnerability was detected which allowed certain communications between the Layered Tech help desk and clients to be vulnerable to interception. While normal help desk communications are not a source of concern, occasionally LT clients submit unencrypted passwords via e-mail or the help desk ticketing system which could result in unauthorized system access by 3rd parties.
As a result, we strongly advise all customers to take proactive measures and change user and system credentials.
Given the overall industry rise in security issues, it is best to err on the side of caution and maintain robust security procedures. Layered Tech also recommends the following security practices:
1) Always change passwords after sharing them via e-mail, or upon receipt of new system login details.
2) Ensure that you have a defined interval for password changes (every 30, 60, or 90 days)
3) Disable/remove non-essential applications, services, and user accounts
4) Set regular maintenance intervals to update core applications and kernels, to address known security issues
5) Change default ports for administration and remote access to non-standard so they are not easily identifiable
We value your business, and will continue working diligently to safeguard against any future vulnerabilities. Please note that SSL is now required to access the LT help desk system. Clients who are unable to gain access to the system should contact our Client Services team.
Should further information become available following our extensive security review and analysis, we will update you.
Thank you,
Received by email on 24 OCT
I am with LT and have had no issues, though direct root access is disabled, ssh is on a different port etc, basic server security stuff.

Reply With Quote
  #10  
Old 10-26-2008, 02:43 PM
bear bear is offline
Community Leader
 
Join Date: Oct 2002
Location: cognito
Posts: 17,318
I didn't get this email.
But it doesn't state there was a compromise, just that the possibility existed. Still not very comforting, however.

Reply With Quote
  #11  
Old 10-26-2008, 02:54 PM
Jame$ Jame$ is offline
Community Guide
 
Join Date: Sep 2004
Location: London, UK
Posts: 1,663
a vulnerability was detected which allowed certain communications between the Layered Tech help desk and clients to be vulnerable to interception.
Seems it's pretty clearly explained where the problem was. I think it's always good when providers come clean with these sort of things. They could just be silent.

Reply With Quote
  #12  
Old 10-26-2008, 03:28 PM
123finder.com 123finder.com is offline
WHT Addict
 
Join Date: Dec 2000
Posts: 124
I didn't see this thread when posted so I had a new topic, if mod could merge, thanks.
There is a law in California that REQUIRES businesses (who have clients in California, and I'm sure all major hosts do) to disclose these incidents.
So don't say that they're being nice or upfront. They have to do this to avoid possible legal consequences.

Reply With Quote
  #13  
Old 10-26-2008, 07:18 PM
Fudevs Fudevs is offline
Web Hosting Guru
 
Join Date: Sep 2005
Location: EGYPT
Posts: 256
thats really big problem when DC like LayeredTech can't protect themselves..... who can trust them

Reply With Quote
  #14  
Old 10-26-2008, 07:54 PM
scoopy scoopy is offline
Junior Guru Wannabe
 
Join Date: Jul 2005
Location: /home
Posts: 79
Here's a good thread I found on this situation:
This was done above any security any individual webhost could provide... Someone logged in as root on my box on the first try (even with a special SSH port enabled and a secure password).
Changing root passwords then or now (as LT suggests in that email) did NOT and ain't gonna do any good... as I hear this intruder has his backdoors set up to email any password changes right to him. He does not need to log in any more.
I had reported this to LT on Oct. 8/9. Their pathetic response was to check [u]MY security and left us all to find our boxes filled with these iframe injections 2-3 weeks later.

Reply With Quote
  #15  
Old 10-27-2008, 12:55 AM
peruviantalk peruviantalk is offline
Web Hosting Master
 
Join Date: Oct 2005
Posts: 1,634
Good for LT.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
50ec8a2c-6240-4366-afe7-0e9845a79943 Listing 2013-03-05 18:25:10
50ec8a2c-4abc-4977-b761-0e9d45a79943 Listing 2013-03-05 18:25:11
50ec8a2c-8980-42b3-b06c-0ea145a79943 Listing 2013-03-05 18:25:12
50ec8a2c-ed98-4b1b-b1f1-0ea645a79943 Listing 2013-03-05 18:25:13
50ec8a2c-c19c-42c6-b584-0eac45a79943 Listing 2013-03-05 18:25:13


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?