Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


SolusVM vulnerability - Page 4
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

SolusVM vulnerability

1246

Comments

  • Good job today @SkylarM in staying on top of it and reaching out to clients with an extra email.

  • @sleddog said:
    Good job today SkylarM in staying on top of it and reaching out to clients with an extra email.

    Always find it worthwhile to email clients anyways. Doesn't hurt to change passwords. Gonna take this as an opportunity to re-secure everything with new passwords just for the hell of it.

    Best wishes to Nick @ Ramnode. Hopefully not much damage was done.

  • rds100rds100 Member

    @Jack i doubt it, if it was the same exploit and it was known for more than a year i bet @CVPS_Chris would be hacked over and over again, many times until today. And not just him.

  • wdqwdq Member

    This is from his last offer, it's kind of ironic now. "Robert is not one to mess around,"

  • @Zen said:
    You realize that he has admitted it to Nick? ...

    He's claiming on Twitter now that the accusations are false https://twitter.com/RobertJFClarke

    He also posted a link on Twitter earlier this week to a repo on his site that Apple wouldn't be too happy to hear about http://ios.servercrate.com/ios/

  • @DomainBop said:
    He also posted a link on Twitter earlier this week to a repo on his site that Apple wouldn't be too happy to hear about http://ios.servercrate.com/ios/

    Should we all send abuse mails to his provider for distributing copyrighted stuff?

  • KrisKris Member

    @gsrdgrdghd said:
    Should we all send abuse mails to his provider for distributing copyrighted stuff?

    Apple would love to know I'm sure.

  • ChrisKChrisK Member

    Wrong, abuse reports are and will be taken seriously.

    @Jack said:
    Avante won't give a shit, he pays too much.

  • @gsrdgrdghd said:
    Should we all send abuse mails to his provider for distributing copyrighted stuff?

    All else aside, I would personally think reporting someone for beta files is just looking for a light in a dark hole. It isn't like he is hosting software the would never be free otherwise. You have to have your UDID on their list (developer added) to even install it so the files are useless without having your devices added.

  • DomainBopDomainBop Member
    edited June 2013

    Should we all send abuse mails to his provider for distributing copyrighted stuff?

    Abuse reports (to any host) for copyright violations need to be filed by the copyright owners.

    Apple has been going after people who distribute its IOS betas for free because only developers who join Apple's developer program and pay the $99 annual fee are supposed to have access to them. Last year they went after people who distributed IOS6 betas (blog article)

  • @DomainBop said:
    Last year they went after people who distributed IOS6 betas

    The main thing they did was deactivate developer accounts who were charging to add your UDID to their list of "beta testers"/"development devices". People were getting rich off of it because for 99.00 you got 100 slots and with 100 slots at between 3-5 dollars each, you made your investment back fairly quick.

  • ChrisKChrisK Member

    @Jack
    You may send an abuse report to [email protected]

  • DomainBopDomainBop Member
    edited June 2013

    @ChrisK said:
    Jack
    You may send an abuse report to [email protected]

    It would be far more effective to report it here --> http://www.apple.com/legal/contact/ :)

  • Apple legal team will SWAT him in his sleep

  • @Holoshed said:
    All else aside, I would personally think reporting someone for beta files is just looking for a light in a dark hole. It isn't like he is hosting software the would never be free otherwise. You have to have your UDID on their list (developer added) to even install it so the files are useless without having your devices added.

    Not fully true, you can install it w/o a developer account and w/o your UDID being on the dev. list. Google my friend :)

  • @NickPerk I know that generally some method comes out every time, but I will be honest I had not read up on iOS 7 yet since I am keeping my jailbreaks. It seems this time if you just do an update it works fine, which I did not check into until I saw your post.

  • @Holoshed said:
    NickPerk I know that generally some method comes out every time, but I will be honest I had not read up on iOS 7 yet since I am keeping my jailbreaks. It seems this time if you just do an update it works fine, which I did not check into until I saw your post.

    Yeah Robert ran into the problem with his UDID not being active via on his Twitter, which he seems to have made it private.

  • jarjar Patron Provider, Top Host, Veteran

    @NickPerk said:

    Don't do this. Those articles are all wrong. The people who have it working forgot they paid last year and they weren't removed from the person's developer account. It's one thing to install it, another to activate it.

  • @jarland said:

    Lol, that's why I don't have a developer account nor an activated UDID, but I'm running iOS7... At least know facts before posting.

  • @Maounique said:
    If Jack could get his skype ip, everyone could.

    True. Just search "Skype Resolver" on google and the entire first page there are public one's.

  • vemacsvemacs Member

    Reposting for entertainment

  • jarjar Patron Provider, Top Host, Veteran
    edited June 2013

    @NickPerk I do. Been a developer for years and read the comments on those articles. You caught luck at best. Those articles are responsible for more than just a few bricked phones. Do your research if you're going to be a jerk about it. Don't encourage people to brick their phones.

  • KoreyKorey Member

    I feel for nick.. Whoever did this (Apparently Robert) I hope nick takes his ass to court.

  • DavidxDavidx Member

    I'm gone for one day & this happens.. lol

    Wish the best for RamNode :( what a Father's Day. Hope whoever did it gets justice.

  • DewlanceVPSDewlanceVPS Member, Patron Provider

    It can run a command on all nodes, show decrypted passwords for all the users, etc.

    sucks!! :(

    Do we need to reset password of customers?

  • @DewlanceVPS said:
    Do we need to reset password of customers?

    Yes Kunnu, you have to!

  • @Korey said:
    I feel for nick.. Whoever did this (Apparently Robert) I hope nick takes his ass to court.

    With what money? Lawsuits cost buckets full of money, always remember that before you threaten to drag someone in court...

    (I feel like quoting @William)

  • Yea, civil lawsuits are even more expensive (EXTREME expensive in the US) and criminal charges would likely be dropped (or labour, or house arrest, state matter) based on age and intelligence (this works for both, very intelligent and very dumb persons)

  • AnthonySmithAnthonySmith Member, Patron Provider

    Just a quick FYI, when looking through 'cat /var/log/lighttpd/access.log | grep centralbackup.php' I found around 40 - 50 attempts to get to centralbackup.php within 3 hours of the exploit being released, luckily none before I had taken the appropriate action.

    I am going through the IP's now to see if they match up to users, any that do will be terminated and get a FraudRecord record created for Criminal Intent.

Sign In or Register to comment.