Forum Search:
HyperVM & Kloxo Support

Home » HyperVM » HyperVM Technical Help » Is LxLabs going crazy or it a 1st of april joke.
Is LxLabs going crazy or it a 1st of april joke. [message #60825] Wed, 01 April 2009 17:58 Go to next message
piplite  is currently offline piplite
Messages: 513
Registered: February 2008
Location: Boston, MA, USA
Masters
So i submitted a question to helpdesk on 30th of march. I figured out the answer to my problem later on the 30th of march too.

But take a look what kind of answer i just recieved

I asked:
Could you please take a look at this problem:
One of vps servers auth log shows that each minute it receives ssh connections from hypervm master server.
auth.log:Mar 30 13:54:49 mano sshd[13575]: Did not receive identification string from x.x.x.x
auth.log:Mar 30 13:55:50 mano sshd[13701]: Did not receive identification string from x.x.x.x

http://forum.lxlabs.com/index.php?t=msg&th=10952&start=0&


And the answer is:
That's just me logging in and raping your entire box. 


Something is really wrong.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60827 is a reply to message #60825] Wed, 01 April 2009 18:10 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
I suspect they have been hacked, we received a similar abusive message via a ticket reply.


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60828 is a reply to message #60825] Wed, 01 April 2009 18:15 Go to previous messageGo to next message
ctaborda  is currently offline ctaborda
Messages: 64
Registered: April 2008
Location: Miami, FL
Valuable Member
Developer
same here. Remember, they have your master IP.. and hopefully they dont have a ssh key to your box, I recall Ligesh storing them.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60829 is a reply to message #60828] Wed, 01 April 2009 18:25 Go to previous messageGo to next message
kingbette  is currently offline kingbette
Messages: 71
Registered: February 2009
Valuable Member
Same here too.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60831 is a reply to message #60825] Wed, 01 April 2009 18:43 Go to previous messageGo to next message
brwatters  is currently offline brwatters  United States
Messages: 18
Registered: March 2009
Member
Sure hope someone of lxlabs has some input FAST as we are concerned that in some way we are now exposed to this hack ..

lxlabs you need to update your customers with a statement ASAP

BRW
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60832 is a reply to message #60825] Wed, 01 April 2009 18:46 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
I'd recommend changing all your passwords, regenerating all SSH keys, and locking down (firewall) access to your server.


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60833 is a reply to message #60825] Wed, 01 April 2009 18:48 Go to previous messageGo to next message
Starteck2002  is currently offline Starteck2002
Messages: 13
Registered: October 2008
Member
Damn hackers didn't respond to my URGENT ticket from 26th February - thought i might have stood more chance of getting a reply from them than LXLabs Sad

Seriously though, are we going to see a statement from LxLabs?
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60835 is a reply to message #60833] Wed, 01 April 2009 18:59 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator


We are investigating this. Piplite, can you please contact live support directly.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60837 is a reply to message #60835] Wed, 01 April 2009 19:08 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator

Actually, the problem was that our admin password was the same as the one we used for our password at webhostingtalk.com, and so somebody figured out our admin password.

There is no other issue here.

thanks.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60838 is a reply to message #60825] Wed, 01 April 2009 19:09 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
What did they get access to ?


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60839 is a reply to message #60825] Wed, 01 April 2009 19:09 Go to previous messageGo to next message
piplite  is currently offline piplite
Messages: 513
Registered: February 2008
Location: Boston, MA, USA
Masters
How do i do that? there is no link to live supprt on lxlabs.com main page anymore.

Thanks.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60840 is a reply to message #60825] Wed, 01 April 2009 19:11 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
The passwords on WHT were encrypted, so unless you had a very short and easy password it would have been near impossible, or would have taken a long time to crack?


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60844 is a reply to message #60825] Wed, 01 April 2009 19:36 Go to previous messageGo to next message
clyphox  is currently offline clyphox
Messages: 1
Registered: April 2009
Member
piplite

Apart from the obvious hilarity of this could I suggest that you install DenyHosts on ALL linux/bsd/*nix boxes.. at least any with ssh..

Think of it this way... unless u have SSH limited by KEY and IP with a good firewall behind it... DenyHosts is essential (and recommended anyway)

its a elegant and 100% essential script that does a damn fine job of watching the logs for attempted brute forcing on ssh.

I would have done that LONG before opening a ticket :p

All my machines probably deny aprox 20-40 attempts daily... Its hillarious reviewing my daily log... i used to run ssh on all sorts of fancy ports and stuff before i discovered DenyHosts... anyway, who'd expect it from an internal IP? I dont wanna imagine what the admin password was on this thing roflsticks...

[Updated on: Wed, 01 April 2009 19:41]

Re: Is LxLabs going crazy or it a 1st of april joke. [message #60845 is a reply to message #60840] Wed, 01 April 2009 19:40 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator
aaron wrote on Wed, 01 April 2009 19:11
The passwords on WHT were encrypted, so unless you had a very short and easy password it would have been near impossible, or would have taken a long time to crack?



Yes, it was not a really a complex password. I didn't think lxlabs ticketing system would be anyone's concern.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60846 is a reply to message #60825] Wed, 01 April 2009 19:42 Go to previous messageGo to next message
a2b2-rus  is currently offline a2b2-rus
Messages: 53
Registered: June 2007
Valuable Member
SO is it safe to use HyperVM and are there guarentees no passwords etc for HyperVM masters have been comprimised? Do you have a trusted login to all HyperVM masters which could be exploited?


LXHelp: rus@lxlabs.com | Want to buy? http://www.Cheapvps.co.uk
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60847 is a reply to message #60825] Wed, 01 April 2009 19:43 Go to previous messageGo to next message
piplite  is currently offline piplite
Messages: 513
Registered: February 2008
Location: Boston, MA, USA
Masters
The hackers words were a joke. I was not hacked. All the topic is about the helpdesk answer.

Thanks.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60849 is a reply to message #60845] Wed, 01 April 2009 19:46 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
adminmaster wrote on Thu, 02 April 2009 10:40
Yes, it was not a really a complex password. I didn't think lxlabs ticketing system would be anyone's concern.


I would think it would be a high target, especially considering the sort of information people provide via the ticketing system (such as IPs, passwords, etc).

Did they get access to anything else?


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60850 is a reply to message #60846] Wed, 01 April 2009 19:48 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator
a2b2-rus wrote on Wed, 01 April 2009 19:42
SO is it safe to use HyperVM and are there guarentees no passwords etc for HyperVM masters have been comprimised? Do you have a trusted login to all HyperVM masters which could be exploited?



We have absolutely no access to anywhere. Lxadmin vpses have ssh key from my personal machine, but other than that there are no accesses.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60853 is a reply to message #60849] Wed, 01 April 2009 19:51 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator

We normally do not ask for passwords. We ask them to add lxlabs ssh key, and send the IP of the server.

If you had posted both the IP and password, it is best you change the password.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60855 is a reply to message #60853] Wed, 01 April 2009 19:57 Go to previous messageGo to next message
adminmaster  is currently offline adminmaster
Messages: 103
Registered: July 2005
Valuable Member
Administrator

We have a very conventional view of security. For everything, we use completely random password. The ticketing system password was set a bit long ago, and wasn't changed after that.

That was actually a mistake.

Thanks.
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60862 is a reply to message #60840] Wed, 01 April 2009 20:12 Go to previous messageGo to next message
Lxhelp
Messages: 23701
Registered: July 2006
Masters
The wht passwords have been going around for a week or so now.


On Wed, Apr 01, 2009 at 11:11:11PM -0000, aaron@crucialp.com wrote:
>
>
> The passwords on WHT were encrypted, so unless you had a very short and easy password it would have been near impossible, or would have taken a long time to crack?


Re: Is LxLabs going crazy or it a 1st of april joke. [message #60865 is a reply to message #60844] Wed, 01 April 2009 20:17 Go to previous messageGo to next message
Lxhelp
Messages: 23701
Registered: July 2006
Masters
There was no real hack at all actually.

Somebody logged in via our ticket system, and posted rude messages.

But absolutely nothing else.


On Wed, Apr 01, 2009 at 11:36:31PM -0000, David wrote:
>
>
> piplite
>
> Apart from the obvious hilarity of this could I suggest that you install DenyHosts on ALL linux/bsd/*nix boxes..
>
> its a elegant and 100% essential script that does a damn fine job of watching the logs for attempted brute forcing on ssh.
>
> I would have done that LONG before opening a ticket :p


Re: Is LxLabs going crazy or it a 1st of april joke. [message #60877 is a reply to message #60865] Wed, 01 April 2009 20:48 Go to previous messageGo to next message
aaron  is currently offline aaron  Australia
Messages: 178
Registered: May 2007
Valuable Member
Lxhelp wrote on Thu, 02 April 2009 11:17
There was no real hack at all actually.

Somebody logged in via our ticket system, and posted rude messages.

But absolutely nothing else.



Whether a password is cracked, or they find a back door - that is considered hacked.

Did not they not have access to your entire support desk? I.e. meaning quite a bit of information?


crucialparadigm
Re: Is LxLabs going crazy or it a 1st of april joke. [message #60878 is a reply to message #60877] Wed, 01 April 2009 20:52 Go to previous messageGo to next message
Lxhelp
Messages: 23701
Registered: July 2006
Masters
They had access to the tickets. Yes.

Yes, I am not trying to trivialize the issue. Merely stating that the problem has been properly solved.

thanks.


On Thu, Apr 02, 2009 at 12:48:37AM -0000, aaron@crucialp.com wrote:
>
>
> Lxhelp wrote on Thu, 02 April 2009 11:17
> > There was no real hack at all actually.
> >
> > Somebody logged in via our ticket system, and posted rude messages.
> >
> > But absolutely nothing else.
>
>
> Whether a password is cracked, or they find a back door - that is considered hacked.
>
> Did not they not have access to your entire support desk? I.e. meaning quite a bit of information?


Re: Is LxLabs going crazy or it a 1st of april joke. [message #60881 is a reply to message #60878] Wed, 01 April 2009 20:53 Go to previous messageGo to next message
Lxhelp
Messages: 23701
Registered: July 2006
Masters
If you had posted both your login and password via the ticket system, you have to absolutely change it. But that has happened very rarely in our case.

I will send a mass email to everyone.

thanks.


On Thu, Apr 02, 2009 at 11:48:13AM +0530, Lxhelp wrote:
> They had access to the tickets. Yes.
>
> Yes, I am not trying to trivialize the issue. Merely stating that the problem has been properly solved.
>


Re: Is LxLabs going crazy or it a 1st of april joke. [message #60946 is a reply to message #60825] Thu, 02 April 2009 13:07 Go to previous message
iceuk  is currently offline iceuk
Messages: 49
Registered: September 2008
Member
Well its good to see the ticket system being used at last!
Previous Topic:one linux vps can not boot up
Next Topic:Could Not start VPS error
Goto Forum:
  


Current Time: Fri Sep 3 14:15:17 EDT 2010

Total time taken to generate the page: 0.01610 seconds
.:: Contact :: Home ::.

Powered by: FUDforum 3.0.1.
Copyright ©2001-2009 FUDforum Bulletin Board Software