Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
Godlike VPS
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Shells Virtual Desktop
Home โ€บ Providers
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ColoCrossing Database Breach

1679111239

Comments

  • No sign of intrusion in my VPS so far, qemu-guest-agent purged and private key only ssh but otherwise a default debian image.
    Going to live dangerously and leave it running, it's only a wireguard server so what's the worst that can happen...

  • In $CURRENT_YEAR any entity that doesn't hash and salt account passwords must obligatory deadpool out of existence from the face of the Earth. Computing power is cheap enough now to run bcrypt or whatever for a few rounds.

  • kuroitkuroit Member, Host Rep, Megathread Squad

    And I was about to sleep! ๐Ÿ˜ตโ€๐Ÿ’ซ

    Just curious, is LET hosted on CC?

  • @kuroit said:
    And I was about to sleep! ๐Ÿ˜ตโ€๐Ÿ’ซ

    Just curious, is LET hosted on CC?

    digitalocean

    Thanked by 1borkedascii
  • kuroitkuroit Member, Host Rep, Megathread Squad

    @fluffernutter said:

    @kuroit said:
    And I was about to sleep! ๐Ÿ˜ตโ€๐Ÿ’ซ

    Just curious, is LET hosted on CC?

    digitalocean

    Pheww!

  • Eh fuck it. Might as well ask. @SolidSeoVPS willing to do dedi refugee offer? I currently have a $100/yr dedi from them. Just in case something happens to colocrossing?
    YABS
    Link to offer

  • wadhahwadhah Member, Host Rep

    If colocrossing start cleaning up and find like half of HBO's tv show collection in my vps it's not me it's the hacker he put it there, he's also seeding it for some reason

  • @Kevinf100 said:
    Eh fuck it. Might as well ask. @SolidSeoVPS willing to do dedi refugee offer? I currently have a $100/yr dedi from them. Just in case something happens to colocrossing?
    YABS
    Link to offer

    +1 save me @SolidSeoVPS

    Thanked by 1PineappleM
  • DecicusDecicus Member

    @sh97 said:

    @Decicus said:

    @zGato said:

    @lirrr said:

    @zGato said:

    If you haven't already (crazy if) please, for the love of god, change your root password. Leak DB contains every single fucking thing. And remove the crap qemu-guest-agent.

    At this point you might as well just wait for official announcement and nuke your vm lol

    did they encrypt the password (account) when storing in db?

    What do you expect from Virtualizor?

    This is just a Virtualizor DB dump, there's literally nothing encrypted for what I can see :joy:

    root passwords for VMs aside, are you telling me Virtualizor doesn't hash control panel login passwords?

    Exactly, not salted or hashed password. Just fucking raw into the DB. Was just telling this to @zGato

    Great, add it to the list of why I don't like Virtualizor.

    It doesn't ultimately matter to me, but just shows the importance of using (randomly) generated passwords. Password re-use is killing

    Thanked by 2lukast__ nghialele
  • yoshikiyoshiki Member
    edited May 2025

    I thought we were all deleting qemu-guest-agent once we got a new machine?

    Thanked by 2nghialele Ed_Chd
  • Do we know what the warning was that was sent? How much time was CC given?

    I have a VPS that is under virtualizor but it's not with CC... (That VPS is also going to be decommed this weekend).

  • emghemgh Member, Megathread Squad

    @barbaros said:
    @wadhah look dis important news

    @emgh suck my willy

    You do it

    Thanked by 2barbaros lukast__
  • zGatozGato Member

    @Decicus said:

    @zGato said:

    @lirrr said:

    @zGato said:

    If you haven't already (crazy if) please, for the love of god, change your root password. Leak DB contains every single fucking thing. And remove the crap qemu-guest-agent.

    At this point you might as well just wait for official announcement and nuke your vm lol

    did they encrypt the password (account) when storing in db?

    What do you expect from Virtualizor?

    This is just a Virtualizor DB dump, there's literally nothing encrypted for what I can see :joy:

    root passwords for VMs aside, are you telling me Virtualizor doesn't hash control panel login passwords?

    Login passwords seem salted, it's just a pure mess, some stuff is, some isn't, ...

  • @emgh said:

    @barbaros said:
    @wadhah look dis important news

    @emgh suck my willy

    You do it

    how did you know?

    Thanked by 1emgh
  • DecicusDecicus Member

    @zGato said:

    @Decicus said:

    @zGato said:

    @lirrr said:

    @zGato said:

    If you haven't already (crazy if) please, for the love of god, change your root password. Leak DB contains every single fucking thing. And remove the crap qemu-guest-agent.

    At this point you might as well just wait for official announcement and nuke your vm lol

    did they encrypt the password (account) when storing in db?

    What do you expect from Virtualizor?

    This is just a Virtualizor DB dump, there's literally nothing encrypted for what I can see :joy:

    root passwords for VMs aside, are you telling me Virtualizor doesn't hash control panel login passwords?

    Login passwords seem salted, it's just a pure mess, some stuff is, some isn't, ...

    Right, okay. That's... something, at least.

  • @sh97 said:

    @Decicus said:

    @zGato said:

    @lirrr said:

    @zGato said:

    If you haven't already (crazy if) please, for the love of god, change your root password. Leak DB contains every single fucking thing. And remove the crap qemu-guest-agent.

    At this point you might as well just wait for official announcement and nuke your vm lol

    did they encrypt the password (account) when storing in db?

    What do you expect from Virtualizor?

    This is just a Virtualizor DB dump, there's literally nothing encrypted for what I can see :joy:

    root passwords for VMs aside, are you telling me Virtualizor doesn't hash control panel login passwords?

    Exactly, not salted or hashed password. Just fucking raw into the DB. Was just telling this to @zGato

    and where us softaculous based out of lmao? what a surprise

    Thanked by 1fluffernutter
  • Does it touch ColoCrossing resellers?

  • NeoonNeoon Community Contributor, Veteran

    @wholecake said:
    Does it touch ColoCrossing resellers?

    The entire DB is touched, so yes, they are touched too.

    Thanked by 2admax PineappleM
  • RubbenRubben Member

    @zed said:
    happy birthday @beanman109

    thanks

    Thanked by 2admax Blembim
  • Why does this always happens to me... I bough a VPS on OVH a couple of weeks before their datacenter burned down a few years ago. I bought a domain on Epik and they got breached a month after that. I buy a VPS on CC literally three days ago and now this... I think I'm cursed...

    @MaxTakeba said:
    I have a VPS that is under virtualizor but it's not with CC...

    Is there a way to tell if a VPS is under virtualizor? I have a couple more with other providers and now I'm starting to worry they might also get breached if they use virtualizor...

  • olokeoloke Member, Host Rep

    @gruhpndo said:
    Why does this always happens to me... I bough a VPS on OVH a couple of weeks before their datacenter burned down a few years ago. I bought a domain on Epik and they got breached a month after that. I buy a VPS on CC literally three days ago and now this... I think I'm cursed...

    Please buy iHostART. Verry god servic.

  • zGatozGato Member

    @Calin when migrating off Virtualizor?

    Thanked by 1lukast__
  • @gruhpndo said:
    Why does this always happens to me... I bough a VPS on OVH a couple of weeks before their datacenter burned down a few years ago. I bought a domain on Epik and they got breached a month after that. I buy a VPS on CC literally three days ago and now this... I think I'm cursed...

    stop buying vps!! you're dooming all the normal users

  • zGatozGato Member
    edited May 2025

    @Neoon said:

    @wholecake said:
    Does it touch ColoCrossing resellers?

    The entire DB is touched, so yes, they are touched too.

    Not really. Only if you were a "HostPapa" affiliated company (e.g HudsonValleyHost) customer.
    (basically, if your Virtualizor domain points to portal.allsitecontrol.com you're fucked.

    RackNerd, ServerHost, ... are CC resellers and they're fine

  • FreekFreek Member

    @Neoon said:

    @wholecake said:
    Does it touch ColoCrossing resellers?

    The entire DB is touched, so yes, they are touched too.

    Please stop touching me

  • NeoonNeoon Community Contributor, Veteran
    edited May 2025

    @zGato said:

    @Neoon said:

    @wholecake said:
    Does it touch ColoCrossing resellers?

    The entire DB is touched, so yes, they are touched too.

    Not really. Only if you were a "HostPapa" affiliated company (e.g HudsonValleyHost) customer.
    (basically, if your Virtualizor domain points to portal.allsitecontrol.com you're fucked.

    RackNerd, ServerHost, ... are CC resellers and they're fine

    Probably if they run on the dedi portal.
    However maybe Colocrossing may also given out reseller accounts.

    Thanked by 2zGato admax
  • zGatozGato Member

    @Ernie can we get an update on this?

  • jsgjsg Member, Resident Benchmarker
    edited May 2025

    @skyandy said:

    @Teko said:

    @zed said:

    @zed said: Not even a customer, my point was your confirmation isn't confirming anything, help us out here.

    Fair enough.

    Even if I provided the chat screenshot and proof from the hacker compared to my panel data, you can still say it is fake as I'm nobody.
    So, whether you trust me or not depends on you.

    Those who come to waste our time, don't even try. You're only wasting your own time. Please write on the matter at hand.

    Also, please, ColoCrossing users, write to the tickets in billing with a request to the administration to contact us at the following contacts: [no profit for thugs!]

    And those who want to support us, here are our crypto wallets:
    [no profit for thugs!]
    [no profit for thugs!]
    [no profit for thugs!]

    From my point of view, you and other thug scum like you can - and should - get a bullet to the head, problem solved. Simple as that.

    But there's one single good thing, this heinous crime brings: a severe warning shot at all providers.
    Providers, remember: major parts if not all of your software is based on crappy code in a crappy language. So you'd better at least do anything possible to tighten your ship as best can be done!

    @jbiloh a lot of us, and especially your customers, are waiting for a clear, transparent, and honest statement!

    Thanked by 2PineappleM nghialele
Sign In or Register to comment.