Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
Godlike VPS
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ColoCrossing Database Breach

145791039

Comments

  • defaultdefault Veteran
    edited May 2025

    I am so sad I am not a customer of ColoCrossing! Now I don't get to be part of this huge drama!

  • RubbenRubben Member

    @default said:

    I am so sad I am not a customer of ColoCrossing! Now I don't get to be part of this huge drama!

    its okay 50% of this thread is just about my quality website anyway

    Thanked by 2nghialele barbarza
  • mandalamandala Member, Megathread Squad

    @Rubben said:

    @oloke said:
    send it here, rubben will get some coffee or whatever he likes to drink

    YOU DID NOT :sob: wdym whatever i like to drink

    Rubben on his website is "Ruben". Why the extra/lost "b"🤨?

  • RubbenRubben Member
    edited May 2025

    @mandala said:

    @Rubben said:

    @oloke said:
    send it here, rubben will get some coffee or whatever he likes to drink

    YOU DID NOT :sob: wdym whatever i like to drink

    Rubben on his website is "Ruben". Why the extra/lost "b"🤨?

    BWAHAHAHAHAHAHAHAA WHAT IS THIS

    RU Boob Boob EN

  • BlembimBlembim Member

    @oloke said:

    @Rubben said:

    @barbaros said:
    Do you think ColoCrossing's customers would get 10 bucks credit as stfu?

    I mean pay me paypal / revolut and i'll stay silent for $10

    send it here, rubben will get some coffee or whatever he likes to drink

    how much coffee is enough for legal fees against francisco dias? @Rubben

  • RubbenRubben Member

    @Blembim said:

    @oloke said:

    @Rubben said:

    @barbaros said:
    Do you think ColoCrossing's customers would get 10 bucks credit as stfu?

    I mean pay me paypal / revolut and i'll stay silent for $10

    send it here, rubben will get some coffee or whatever he likes to drink

    how much coffee is enough for legal fees against francisco dias? @Rubben

    $3.50

  • mandalamandala Member, Megathread Squad

    @Rubben said:

    @mandala said:

    @Rubben said:

    @oloke said:
    send it here, rubben will get some coffee or whatever he likes to drink

    YOU DID NOT :sob: wdym whatever i like to drink

    Rubben on his website is "Ruben". Why the extra/lost "b"🤨?

    BWAHAHAHAHAHAHAHAA WHAT IS THIS

    RU Boob Boob EN

    On the left is RU (Russian), on the right is EN (English).

  • olokeoloke Member, Host Rep

    @mandala said:

    @Rubben said:

    @oloke said:
    send it here, rubben will get some coffee or whatever he likes to drink

    YOU DID NOT :sob: wdym whatever i like to drink

    Rubben on his website is "Ruben". Why the extra/lost "b"🤨?

    how to unsee this?

    serious

    plz

    my mental state is worsening

    Thanked by 2nghialele mandala
  • defaultdefault Veteran

    WE NEED REFUGEE DEALS

  • RubbenRubben Member

    @mandala said:

    @Rubben said:

    @mandala said:

    @Rubben said:

    @oloke said:
    send it here, rubben will get some coffee or whatever he likes to drink

    YOU DID NOT :sob: wdym whatever i like to drink

    Rubben on his website is "Ruben". Why the extra/lost "b"🤨?

    BWAHAHAHAHAHAHAHAA WHAT IS THIS

    RU Boob Boob EN

    On the left is RU (Russian), on the right is EN (English).

    Alt text

  • TionTion Member

    I'm currently using their atrociously outdated backend for my dedicated server. It looks like only their cloud backend was hacked.

    Thanked by 2oloke wadhah
  • wadhahwadhah Member, Host Rep

    @Tion said:
    I'm currently using their atrociously outdated backend for my dedicated server. It looks like only their cloud backend was hacked.

    The company that refuses to implement ipv6 has an outdated backend?

    Naaaah i don't believe you

    Thanked by 2zed lothos
  • LunarLunar Member
    edited May 2025

    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access.

  • NeoonNeoon Community Contributor, Veteran

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access access.

    Did you leave your VNC password the same?
    Did you change your initial root password?

  • zGatozGato Member
    edited May 2025

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access.

    None of my VMs are actually compromised (or seems like, at least there's not a "Contact us" file), and I have quite a few.

    You probably left the default root password or qemu-guest-agent installed (from which they could've just reset the password and get in).

  • LunarLunar Member

    @Neoon said:

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access access.

    Did you leave your VNC password the same?
    Did you change your initial root password?

    Yes to VNC, and no to root password being the same. It's also possible they brute-forced VNC with the default password, as they set an 8 char password (which is the max surprisingly).

    However, I find this hard to believe, because the Telegram user is the same one claiming to have breached ColoCrossing. I think it's unlikely that they brute-forced VNC only.

  • barbarosbarbaros Member
    edited May 2025

    @Neoon said:

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access access.

    Did you leave your VNC password the same?
    Did you change your initial root password?

    This is just a guess but probably they breached the node and accessed each VM on it. Considering the dude's name is ransombot, he could just use a ransomware to modify files in each VPS instead of encrypting everything like a usual ransom bot does.

    So probably their nodes are breached also, and they would scan all the files and collect the good shit. Only missing part is whole data getting ransomwared, but probably thats next.

    Thanked by 1nghialele
  • LunarLunar Member

    @zGato said:

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access.

    None of my VMs are actually compromised (or seems like, at least there's not a "Contact us" file), and I have quite a few.

    You probably left the default root password or qemu-guest-agent installed (from which they could've just reset the password and get in).

    This would suggest they do actually have access to their systems, either WHMCS or Virtualizor, or both. The breacher logged in directly through VNC.

  • zGatozGato Member
    edited May 2025

    @Lunar said:

    @zGato said:

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access.

    None of my VMs are actually compromised (or seems like, at least there's not a "Contact us" file), and I have quite a few.

    You probably left the default root password or qemu-guest-agent installed (from which they could've just reset the password and get in).

    This would suggest they do actually have access to their systems, either WHMCS or Virtualizor, or both. The breacher logged in directly through VNC.

    They do have access, I've said that multiple times. I've asked the guy several times about node info and all the IPs matched the VNC IP node.

    I'm 99% sure what simply happened on your case is that you haven't removed qemu-guest-agent and prevented it from being installed again, and so they did reset your password and simply VNCd in.

  • LunarLunar Member

    @zGato said:

    @Lunar said:

    @zGato said:

    @Lunar said:
    For all those that are saying there was no breach, you're wrong.

    All 3 of our ColoCrossing VMs (with no important or sensitive data) were breached.

    We take several measures to secure our infra, and SSH access was completely disabled externally and only accessible via a WG tunnel. They appeared to actually login to the servers through VNC, as they were already logged in via the VNC tty.

    This is not just a spoof or breach of their email system, they have full access.

    None of my VMs are actually compromised (or seems like, at least there's not a "Contact us" file), and I have quite a few.

    You probably left the default root password or qemu-guest-agent installed (from which they could've just reset the password and get in).

    This would suggest they do actually have access to their systems, either WHMCS or Virtualizor, or both. The breacher logged in directly through VNC.

    They do have access, I've said that multiple times. I've asked the guy several times about node info and all of the IPs matched the VNC IP node.

    You are right. I didn't read your previous messages.

    Thanked by 2zGato nghialele
  • Can anyone access the Virtualizor? It seems like I can no longer access it...

  • NJa64FNJa64F Barred

    so TLDR. I did see if mr Biloh commented on this thread and he hasnt , which to me leads credibility to the issue. I have Racknerd VPS. Does racknerd use CC (ATlanta) ? Can racknerd be affected by this ?

  • I thought I was the only one who received it!!!

  • allthemtingsallthemtings Member, Megathread Squad
    edited May 2025

    Everyone charge back yesterday

    Not financial advice

  • It’s Memorial Day Weekend in the USA now so it will be interesting to see whether ColoCrossing will be out of office until Tuesday to see the carnage…

  • NeoonNeoon Community Contributor, Veteran
  • allthemtingsallthemtings Member, Megathread Squad

    @PineappleM said:
    It’s Memorial Day Weekend in the USA now so it will be interesting to see whether ColoCrossing will be out of office until Tuesday to see the carnage…

    Thanked by 2PineappleM nghialele
  • dustincdustinc Member, Patron Provider, Top Host

    @jperkins said:
    so TLDR. I did see if mr Biloh commented on this thread and he hasnt , which to me leads credibility to the issue. I have Racknerd VPS. Does racknerd use CC (ATlanta) ? Can racknerd be affected by this ?

    RackNerd is not affected by this breach, it’s worth noting that there have been several Virtualizor vulnerabilities floating around as of late (even affecting other providers here, some who haven’t even made statements) - one more recent one being Virtualizor’s support/live chat system being compromised.

    For the record, we do not use Virtualizor. Additionally, all of our infrastructure and control panels are managed by us directly, and not by any of our datacenter providers/vendors.

    I would likely expect ColoCrossing to release a statement here soon, I can only imagine it must be all hands on deck at the moment to determine and mitigate the cause, etc. Wishing them the best with their recovery and mitigation efforts.

  • yoursunnyyoursunny Member, IPv6 Advocate

    @oloke said:

    @wadhah said:

    @yoshiki said:
    These were posted on NS, they contacted the hacker apparently


    0 ipv6, yep it's real

    Lack of ipv6 was probably the attack vector.
    Important lesson for other providers from @yoursunny 's no-ipv6 list.

    Virtualizor Hall of Vulnerability

Sign In or Register to comment.