Hetzner поломали. - Форум успешных вебмастеров - GoFuckBiz.com
 
 
Форум успешных вебмастеров - GoFuckBiz.com

  Форум успешных вебмастеров - GoFuckBiz.com > Бизнес-решения > Хостинг и железо
Дата
USD/RUB93.4409
BTC/USD61497.2445
Хостинг и железо Обсуждаем вопросы хостинга и железа.

Закрытая тема
Опции темы Опции просмотра
Старый 06.06.2013, 21:11   #1
buhhu
мёдвед
 
Регистрация: 03.09.2007
Сообщений: 131
Бабло: $33254
По умолчанию Hetzner поломали.

пришло письмо:
"Dear Client

At the end of last week, Hetzner technicians discovered a "backdoor" in one
of our internal monitoring systems (Nagios).

An investigation was launched immediately and showed that the administration
interface for dedicated root servers (Robot) had also been affected. Current
findings would suggest that fragments of our client database had been copied
externally.

As a result, we currently have to consider the client data stored in our Robot
as compromised.

To our knowledge, the malicious program that we have discovered is as yet
unknown and has never appeared before.

The malicious code used in the "backdoor" exclusively infects the RAM. First
analysis suggests that the malicious code directly infiltrates running Apache
and sshd processes. Here, the infection neither modifies the binaries of the
service which has been compromised, nor does it restart the service which has
been affected.

The standard techniques used for analysis such as the examination of checksum
or tools such as "rkhunter" are therefore not able to track down the malicious
code.

We have commissioned an external security company with a detailed analysis of
the incident to support our in-house administrators. At this stage, analysis
of the incident has not yet been completed.

The access passwords for your Robot client account are stored in our database
as Hash (SHA256) with salt. As a precaution, we recommend that you change your
client passwords in the Robot.

With credit cards, only the last three digits of the card number, the card type
and the expiry date are saved in our systems. All other card data is saved
solely by our payment service provider and referenced via a pseudo card number.
Therefore, as far as we are aware, credit card data has not been compromised.

Hetzner technicians are permanently working on localising and preventing possible
security vulnerabilities as well as ensuring that our systems and infrastructure
are kept as safe as possible. Data security is a very high priority for us. To
expedite clarification further, we have reported this incident to the data
security authority concerned.

Furthermore, we are in contact with the Federal Criminal Police Office (BKA) in
regard to this incident.

Naturally, we shall inform you of new developments immediately.

We very much regret this incident and thank you for your understanding and
trust in us."
buhhu вне форума  
Старый 06.06.2013, 22:06   #2
t1esto
Senior Member
 
Регистрация: 13.08.2007
Сообщений: 632
Бабло: $167274
По умолчанию

тоже пришло. слили их базу с главной панели ((
t1esto вне форума  
Старый 06.06.2013, 22:39   #3
Strikelol
Senior Member
 
Регистрация: 31.03.2011
Сообщений: 3,360
Бабло: $669045
По умолчанию

я палкой платил. А насчет пасса, так 10 символов с солью не сильно сбрутишь
Strikelol вне форума  
Старый 06.06.2013, 23:08   #4
mirikas
Senior Member
 
Аватар для mirikas
 
Регистрация: 25.12.2008
Сообщений: 1,099
Бабло: $272735
По умолчанию

жаль клиентов но хетзнер пидарасы дох-я серваков перелокали))
mirikas вне форума  
Старый 07.06.2013, 01:03   #5
tmp
Ебланнед
 
Регистрация: 27.11.2012
Сообщений: 223
Бабло: $43064
По умолчанию

Цитата:
Сообщение от mirikas
жаль клиентов но хетзнер пидарасы дох-я серваков перелокали))
+1
Поменял все пасы на всяк случай
tmp вне форума  
Старый 07.06.2013, 10:12   #6
qvent
Сеньйор Помидор
 
Аватар для qvent
 
Регистрация: 28.08.2007
Сообщений: 2,008
Бабло: $421625
Отправить сообщение для qvent с помощью ICQ
По умолчанию

Я так понял что доступ тока к роботу получили, к серверам нет?
qvent вне форума  
Старый 08.06.2013, 14:17   #7
Somat
Senior Member
 
Аватар для Somat
 
Регистрация: 06.05.2013
Сообщений: 569
Бабло: $99835
По умолчанию

а разве они скажут... тоже пришло письмецо
Somat вне форума  
Старый 08.06.2013, 14:39   #8
NTллигент
Senior Member
 
Аватар для NTллигент
 
Регистрация: 23.04.2007
Адрес: Leopolis
Сообщений: 359
Бабло: $71530
По умолчанию

Тоже самое, пароли на робота сменил
__________________
#StandWithUkraine
NTллигент вне форума