Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


ChicagoVPS database leaked? ChicagoVPS customers - change your root passwords immediately! - Page 3
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ChicagoVPS database leaked? ChicagoVPS customers - change your root passwords immediately!

1356712

Comments

  • RadiRadi Host Rep, Veteran
    edited February 2013

    Can I get the dump? I am a client of them.

  • @fisle said: I just had a quick look at it and the passwords are not stored in cleartext.

    Thank god for that! can you describe the database tables. So we can see what info they have stored and what has been released.

    @liam, not sure if they are still banned but it would be nice to have a cvps rep on this.

  • @Mun said: @liam, not sure if they are still banned but it would be nice to have a cvps rep on this.

    Kevin still has an active account here, its just Chris that was banned.

  • @GetKVM_Ash said: Kevin still has an active account here

    Luc too

  • RadiRadi Host Rep, Veteran

    Why was Chris banned?

  • MunMun Member
    edited February 2013

    @Radi said: Can I get the dump? I am a client of them.

    I as well.

    @GetKVM_Ash said: @Mun said: @liam, not sure if they are still banned but it would be nice to have a cvps rep on this.

    Kevin still has an active account here, its just Chris that was banned.

    Then @CVPS_Kevin can you please give us a heads up on what the hell is going on. Considering @CVPS_Chris stated:


    Hello Everyone,

    I just wanted to give a quick update, since a lot of you are looking for one and had a few questions.

    First off, I want to start out by saying thank you to all of you that have been clam during this event and understand that sometimes things do happen.
    In no way, has WHMCS been effected from this, so no customer personal information such as credit cards, emails, etc. has been stolen. ChicagoVPS will also
    be implementing a regular backup service for all OpenVZ products. We will start out in Chicago and work to Buffalo, then to LA.

    We want to assure you that we are doing everything we can to make sure nothing like this can happen again, and that you can still rely on us for your hosting needs.

    If you have any additional questions, please feel free to open up a support ticket.

    Thank you all again for your business.

    Regards,

    Chris Fabozzi
    Director of Operations
    ChicagoVPS - See more at:


  • RadiRadi Host Rep, Veteran

    I want the dump to see what they store about me?

  • @Mun said: can you describe the database tables. So we can see what info they have stored and what has been released.

    Well there's pretty much everything.. their nodes, backup servers, client info, internal ips, ipv6 addresses, ipv4 addresses, plans, bandwidth usage datas, isos, templates, vzdata, xendata, etc.. like it's their entire database. 26.9MB SQL file. I haven't checked it completely and not sure if I will.

  • At least we can verify whether CVPS are as big as Chris likes to claim they are :P

  • DamianDamian Member
    edited February 2013

    I understand the "neat" factor of "building a tool to see if your name is in the database", but the date of the dump has been established based on the information contained within. Are we not giving enough credit to people that they should know if they were, or were not, a customer of CVPS at that point?

    @GetKVM_Ash said: At least we can verify whether CVPS are as big as Chris likes to claim they are :P

    I feel that most of the "I want the database!" probably stems from this. So....

    @Random_Dude said: Overreacting a bit?

    No.

    ======

    Where's @Spirit?

  • 59 Nodes apparently :-)

  • imperioimperio Member
    edited February 2013

    @Damian I understand the "neat" factor of "building a tool to see if your name is in the database", but the date of the dump has been established based on the information contained within. Are we not giving enough credit to people that they should know if they were, or were not, a customer of CVPS at that point?

    Are you sure they delete old user information from database ?

  • RadiRadi Host Rep, Veteran

    Client info? F**k, my debit card is in it.

  • @imperio said: Are you sure they delete old user information from database ?

    They probably don't (does anyone?), and that's my point: consider that your personal data is already in the database, and so it's now being passed around without consideration.

  • @Radi I don't thnk your Crredit or Debit card are in there.

  • @Radi said: Client info? F**k, my debit card is in it.

    I understand this is a SolusVM dump, not WHMCS (unless I've misinterpreted), and there's no reason for SolusVM to have any billing related information in it, such as your CC info.

  • @Radi said: Client info? F**k, my debit card is in it.

    Why would your debit card info be in the solus database?

  • MunMun Member
    edited February 2013

    @Damian said: They probably don't (does anyone?), and that's my point: consider that your personal data is already in the database, and so it's now being passed around without consideration.

    As a customer of CVPS prior and after the attack I want to see the info of the database so I can confirm what information is there and take actions accordingly. As of the moment I don't give a shit if it is passed around, the damage is done and it is probably on 10 to 20 mirrors by now.

    So thus, I would love to see the mysql database contents for email: (Retracted the email to prevent SPAMMING) if someone could do that for me. (PM it please)

  • @imagine said: I understand this is a SolusVM dump, not WHMCS (unless I've misinterpreted), and there's no reason for SolusVM to have any billing related information in it, such as your CC info.

    Yet another reason to not pass it out.

  • @damian consider that your personal data is already in the database, and so it's now being passed around without consideration.

    Database is already leaked.I was a customer when they claimed there was a solusvm exploit and cancelled account after.So i can not be sure if my personal data is leaked or not.

  • RadiRadi Host Rep, Veteran

    SolusVM passwords are now changed by them.

  • mikhomikho Member, Host Rep
    edited February 2013

    @NickM said: @Damian, there are legitimate reasons for wanting the database. The file is already out there, somewhere. The "bad guys" already have it, so not releasing it isn't really going to help anyone.

    there are NO reasons other then to harm CVPS more then already is done by sending their user db to other people.

    @NickM said: Exactly this. Which is why I'd like to get my hands on it - so that I can put together a page where anyone can easily search for their own name to find out if their info is out there.

    Have you been a customer with CVPS, then probably it is.
    I suggest that you log in and change your password.

  • CVPS customers prepare to be spammed by spammers!

  • RadiRadi Host Rep, Veteran

    Mikho, passwords are changed already.

  • RadiRadi Host Rep, Veteran

    I think I may be cancelling my server.

  • 24khost24khost Member
    edited February 2013

    @Radi why they fixed the problem. So you email leaked, big deal emails can be changed and updated.

    being sarcastic!

  • RadiRadi Host Rep, Veteran

    I can't change it as I registered everywhere with it.

  • hopefully this happens to no other hosts.

  • @24khost said: hopefully this happens to no other hosts.

    You're safe as long as you aren't so sloppy and lacking in security as @CVPS_Chris

  • If this is true,it could explain why my vps with chicagovps was rebuild by some other guy from the control panel.

This discussion has been closed.