It looks like you're new here. If you want to get involved, click one of these buttons!
Got an email 2+ hours ago directly from ChicagoVPS (am a customer):
[CRITICAL UPDATE]
re: Chicago VPS11, Chicago VPS12, Chicago VPS14, Chicago VPS16, Chicago VPS17, Chicago VPS26, Chicago VPS28, Chicago VPS29, Chicago VPS30, Chicago VPS31
ChicagoVPS experienced a brute force on the SolusVM API for the administrative section. This caused the above affected nodes to become compromised before we were able to stop the attack.
What does this mean? Currently the VM's on these nodes are being recovered to the fullest ability of Chicago VPS staff from the incomplete data destruction process and from central backups. Any VM's unable to be recreated from the remaining data or from backups will be created fresh.
ChicagoVPS is committed to customer satisfaction and any way in our ability will do what we can to get everyone back up and going as fast and as best as we can.
We will post additional updates on twitter and facebook and from time to time send out an email regarding the current status of the progress.
If you have any questions in the mean time, feel free to directly email me at jshinkle@chicagovps.net
Sincerely,
Jeremiah L. Shinkle Chief Networking Officer ChicagoVPS
@CVPS_Chris loves --> http://www.hawkhost.com/
Comments
Thats a pretty crappy thing to happen for both client and provider. Is this an exploit in SolusVM or something not locked down correctly?
Shardhost 1GB KVM $7/mo | 2GB OpenVZ $7/mo
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksKarma is a bitch. Hope it is not too bad and they can recover.
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAnyone have a working theory that immediately comes to mind as to what happened here? Admin API would be the API used to connect billing software would it not? Is it not restricted by IP?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksKarma aside, I am wondering where the exploit is and if it's a SolusVM issue. An exploit in SolusVM could impact tons of folks.
@CVPS_Chris loves --> http://www.hawkhost.com/
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksEven if their.. marketing, I guess, ruffled some feathers, I don't think it deserves one node getting nearly-trashed, let alone ten.
With that said, still up over in LA.
how did this get here i am not good with computer
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@Liam @infinity please remove /hide ths thread. If this is a solusvm exploit, this can have hugee affect.
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@Taz Nope. If there's an exploit and someone is targeting LEB providers this is the place it should be exposed.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksBut before solus releases a patch, you are welcoming more skiddies.
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksYour problem, should probably go deal with that.
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksNope, you're warning LEB providers to watch their butts. Otherwise you're keeping the info from them to let them get targeted if this is going to continue through the night.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksNot an exploit (according to ChicagoVPS):
"ChicagoVPS experienced a brute force on the SolusVM API for the administrative section. This caused the above affected nodes to become compromised before we were able to stop the attack."
Thanked by (1): NateN34.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksBut isn't that API locked to IP?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksIt should be yes.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI know ours is, or at least SolusVM tells us it is, which is why I am asking about exploit ;)
Shardhost 1GB KVM $7/mo | 2GB OpenVZ $7/mo
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAPI can only be accessed from whmcs IP I assume . Since someone was able to.bruteforce, something might not be right?
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI'm sure when @CVPS_Chris gets this mess sorted he'll fill us in on whether the rest of us should be worried about it. Gonna be a long night for those guys.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksConfirmed that another host had the same issue. Everyone should be concerned.
Dont ask who, it is up to them to release it and not my job to tell.
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksLuckily my VPS with them are not affected. But this is real scary! Backup, backup, backup guys!
http://seikan.me
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWhich version of SolusVM are we talking about? The latest?
Internap VPS, Web Hosting and more - Cloud Shards | Need a VPS Upgrade?
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@CVPS_Chris
Ego aside, I hope you are being serious about what you have just posted?
https://nodedeploy.com | Premium VPS Solutions | Managed
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksJesus Just spoke to Jeremiah via email this sounds nasty.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSerious. I guess I can do one nice thing.
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWhat are your preliminary thoughts on the effect of revoking the API keys used for billing software? Assuming he explained more detail to you than we know. That's what I've done, as well as reduced stock to 0. I don't take chances.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksDisabling the API's would be best yes.
However I wasn't 100% sure what was going on so I Just did :
:)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI think you'd be safe selling stock, just revoke terminations and do those manually if there are any after the cron run
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThough I'm wondering if an actual exploit occurred and if it's not say some kind of hardware failure at fault? I mean a brute force attack? Didn't have something as simple as Fail2Ban installed? Just curious cuz it doesn't seem to be adding up.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksYeah i have also followed up on this... This is BADD NEWS right now!
Crystal - ugvps
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks? You are the other host or what?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI don't know if fail2ban or LFD would cover SolusVM API access without some tweaks that most people would probably consider overkill prior to knowledge of such an exploit.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks