ChicagoVPS被人脱裤了

2013-06-18 17:19:35 +08:00
 vibbow
所有VPS全部挂了,所用用户资料 + VPS资料全部泄露(还把下载地址挂到官网上了...)

总共9403个VM,109个节点
3736 次点击
所在节点    VPS
57 条回复
princeofwales
2013-06-18 21:15:57 +08:00
假的,我的VPS今天没有停啊

top - 21:15:39 up 31 days, 18:39
darkbill
2013-06-18 21:19:22 +08:00
@vibbow 一早就禁止了root登录,问题不是独立密码,现在在废除旧密码中。。。不过还好,这个密码用的地方不多。。。
chainkhoo
2013-06-18 21:47:34 +08:00
=.-还好早就撤离了chicagovps 之前觉得他家超售太严重了 就闪人了
likuku
2013-06-18 22:15:22 +08:00
ssh 必须 only public_key 认证啊...
vibbow
2013-06-19 02:35:03 +08:00
@princeofwales 敢报上你的邮箱么?
我当时正在winscp传数据呢,突然就断了,然后就第一时间看到了被脱裤了。
于是也第一时间下载了...
vibbow
2013-06-19 03:27:50 +08:00
ChicagoVPS的官方说明出来了:

Around 3am Eastern Standat Time (EST) today, there was a security breach, due to a vulnerability in SolusVM that allowed a command line to be run to dump the ChicagoVPS SolusVM client database and attempt to delete all data from our nodes. Our staff is working tirelessly to get everything back online, along working with SolusVM to address the root issue and no furthur impact is expected.

Now what does this mean for the customer? All passwords should be changed, this includes passwords for SolusVM control panel and your VPS. This data leak does not include billing information or credit card information. Thus far we are having great success in getting nodes back online with no data loss, however, there are a few that were not recoverable and will be restored using our offsite backups.

Once the situation is 100% complete and back to normal we will send another email out. We understand the sevarity and importance to get everything back online quickly. With that in mind, please try to refrain from opening a ticket or replying to an old one as it only slows us down even more. We are doing our best, and hope to have this fully resolved within 24 hours.

Thank you for your patience and understanding.

Regards

Your ChicagoVPS Team
wenbinwu
2013-06-19 03:37:47 +08:00
@vibbow Firefox的就算泄露了别人拿了也没办法解密,因为连Firefox的人都没法读。。。
lll9p
2013-06-19 07:32:40 +08:00
SolusVM漏洞,貌似影响很大啊,host1free的vps也被一撸到底。。。
yylzcom
2013-06-19 09:14:24 +08:00
完了,是真的,我今天早上收到邮件了,速度去改密码
sdysj
2013-06-19 09:33:09 +08:00
chicagoVPS早给人拖好几次库了,还在混?
FanError
2013-06-19 09:37:06 +08:00
BuyVM好像也是SolusVM呀,没影响?
tititake
2013-06-19 09:48:23 +08:00
中招,到现在还是没法管理vps。
Virtual Server Control
Status: Unavailable
webflier
2013-06-19 10:11:11 +08:00
@FanError BuyVM不是SolusVM,他们自己in house开发的
webflier
2013-06-19 10:14:22 +08:00
RamNode和ChicagoVPS都有我的vps。
其中RamNode挂了8个VPS,点背到极点~~~
jqw1992
2013-06-19 19:07:20 +08:00
我的也是...网站主题被人删了...
manoon
2013-06-19 22:55:59 +08:00
压力不大。。。很庆幸,上周有把所有VPS上面的数据备份了一下。哈哈。
dearroy
2013-06-20 09:20:18 +08:00
@webflier 你是说的Stallion吧,Stallion也是SolusVM的二次开发。
sopato
2013-06-20 09:44:16 +08:00
哗~~~看来是大时间,强烈关注。
wzxjohn
2013-06-20 10:08:13 +08:00
@vibbow 求裤子下载。。。
ibudao
2013-06-20 15:07:36 +08:00
应该是solusvm面板的0day漏洞引起。今天折腾起我在123systems上的vps,突然发现控制面板上不去了,于是发了个ticket过去,得到如下回复:
The exploit from 6/16/2013 has been patched by the software distributor, however, numerous reports are still stating that there are several other zero day exploits currently unknown to the software distributor and are still unpatched.
详见:https://www.123systems.net/policy.html

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/72800

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX