Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Spent a whole day searching the leaked Colocrossing database, found a possible hacker’s email

6wvy5ipw6wvy5ipw Member
edited May 2025 in General

Spent a whole day searching the leaked Colocrossing database, found a possible hacker’s email

So, on 2025-05-24 around 11:25 AM (UTC+8), someone added an admin account with a QQ.com email [adduser].
Then, less than half an hour later at 11:47 AM, all the admin users got deleted from the backend [deluser].

I was digging through the leaked Colocrossing database and this caught my eye. Looks pretty sketchy and might be linked to the hacker — but I’m not sure if this actually caused the hack or if the hacker even left their real email.

Thanked by 1lowendclient

Comments

  • qq? chinese?

    so whats the story

  • 6wvy5ipw6wvy5ipw Member
    edited May 2025

    @cybertech said:
    qq? chinese?

    so whats the story

    I'm not sure about the exact situation, and I don't know why this email address was added as a backend administrator. Maybe this person joined CCS, or there might be a security loophole?
    This is how it appears in the database, and it feels like a suspicious situation, so I didn't share the full email address.

  • or there might be a security loophole?

  • You're missing the full context.

    (8,0,11250,'adduser','<u1>@gmail.com',1748030021,1,'192.3.154.82')
    (9,0,14890647,'create_vps','14890647',1748030058,1,'192.3.154.82')
    (10,0,14890647,'addvs','v27613',1748030073,1,'192.3.154.82')
    (11,0,14890647,'editvs','v27613',1748030214,1,'192.3.154.82')
    (16,0,14890649,'create_vps','14890649',1748031717,1,'192.3.154.82')
    (17,0,14890649,'addvs','v27615',1748031735,1,'192.3.154.82')
    (21,0,11251,'adduser','<u2>@gmail.com',1748035955,1,'192.3.154.82')
    (22,0,14890650,'create_vps','14890650',1748036017,1,'192.3.154.82')
    (23,0,14890650,'addvs','v27616',1748036032,1,'192.3.154.82')
    (25,0,14890242,'editvs','v27211',1748039908,1,'192.3.154.82')
    (26,0,14890242,'editvs','v27211',1748039950,1,'192.3.154.82')
    (27,0,14890242,'editvs','v27211',1748039992,1,'192.3.154.82')
    (37,0,11252,'adduser','<u3>@qq.com',1748057145,1,'192.3.154.82')
    (38,0,14890652,'create_vps','14890652',1748057198,1,'192.3.154.82')
    (39,0,14890652,'addvs','v27618',1748057212,1,'192.3.154.82')
    

    The same IP added 2 more admins before the @qq guy.

  • @sillycat said:
    You're missing the full context.

    (8,0,11250,'adduser','<u1>@gmail.com',1748030021,1,'192.3.154.82')
    (9,0,14890647,'create_vps','14890647',1748030058,1,'192.3.154.82')
    (10,0,14890647,'addvs','v27613',1748030073,1,'192.3.154.82')
    (11,0,14890647,'editvs','v27613',1748030214,1,'192.3.154.82')
    (16,0,14890649,'create_vps','14890649',1748031717,1,'192.3.154.82')
    (17,0,14890649,'addvs','v27615',1748031735,1,'192.3.154.82')
    (21,0,11251,'adduser','<u2>@gmail.com',1748035955,1,'192.3.154.82')
    (22,0,14890650,'create_vps','14890650',1748036017,1,'192.3.154.82')
    (23,0,14890650,'addvs','v27616',1748036032,1,'192.3.154.82')
    (25,0,14890242,'editvs','v27211',1748039908,1,'192.3.154.82')
    (26,0,14890242,'editvs','v27211',1748039950,1,'192.3.154.82')
    (27,0,14890242,'editvs','v27211',1748039992,1,'192.3.154.82')
    (37,0,11252,'adduser','<u3>@qq.com',1748057145,1,'192.3.154.82')
    (38,0,14890652,'create_vps','14890652',1748057198,1,'192.3.154.82')
    (39,0,14890652,'addvs','v27618',1748057212,1,'192.3.154.82')
    

    The same IP added 2 more admins before the @qq guy.

    You can see that this IP belongs to CCS. You can verify this by running dig cloudmain.colocrossing.com. So, I don't think this IP belongs to a hacker.

    Thanked by 2nghialele mandala
  • @6wvy5ipw said:

    @sillycat said:
    You're missing the full context.

    (8,0,11250,'adduser','<u1>@gmail.com',1748030021,1,'192.3.154.82')
    (9,0,14890647,'create_vps','14890647',1748030058,1,'192.3.154.82')
    (10,0,14890647,'addvs','v27613',1748030073,1,'192.3.154.82')
    (11,0,14890647,'editvs','v27613',1748030214,1,'192.3.154.82')
    (16,0,14890649,'create_vps','14890649',1748031717,1,'192.3.154.82')
    (17,0,14890649,'addvs','v27615',1748031735,1,'192.3.154.82')
    (21,0,11251,'adduser','<u2>@gmail.com',1748035955,1,'192.3.154.82')
    (22,0,14890650,'create_vps','14890650',1748036017,1,'192.3.154.82')
    (23,0,14890650,'addvs','v27616',1748036032,1,'192.3.154.82')
    (25,0,14890242,'editvs','v27211',1748039908,1,'192.3.154.82')
    (26,0,14890242,'editvs','v27211',1748039950,1,'192.3.154.82')
    (27,0,14890242,'editvs','v27211',1748039992,1,'192.3.154.82')
    (37,0,11252,'adduser','<u3>@qq.com',1748057145,1,'192.3.154.82')
    (38,0,14890652,'create_vps','14890652',1748057198,1,'192.3.154.82')
    (39,0,14890652,'addvs','v27618',1748057212,1,'192.3.154.82')
    

    The same IP added 2 more admins before the @qq guy.

    You can see that this IP belongs to CCS. You can verify this by running dig cloudmain.colocrossing.com. So, I don't think this IP belongs to a hacker.

    Could it be a Hypervisor escape? As in the attacker got a VM like any normal customer and then used it to breach the Virtualizor instance?

  • LeviLevi Member

    @CloudHopper said:
    Could it be a Hypervisor escape? As in the attacker got a VM like any normal customer and then used it to breach the Virtualizor instance?

    Here is images which came from the smokah. It clearly show database dump AND admin screenshot of virtualizor. Fully blown crack. This is massive breach.

  • CalinCalin Member

    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

  • RubbenRubben Member

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    A great fix is not using Virtualizor

  • xHostsxHosts Member, Patron Provider

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    I have spoken to virtualizor, it appears to have been human error not a software issue

    Thanked by 3Calin beanman109 mrTom
  • @xHosts said:

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    I have spoken to virtualizor, it appears to have been human error not a software issue

    1. that's obviously what virtualizor would say
    2. if true thats even worse
  • zGatozGato Member

    @xHosts said:

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    I have spoken to virtualizor, it appears to have been human error not a software issue

    But exposing raw passwords is also a human error, right? Or a best practice I haven't been aware of?

    Avoid Virtualizor at all costs.

    ColoCrossing also hasn't stated it, but full names are also in the db, unless you manually changed it in Virtualizor.

  • xHostsxHosts Member, Patron Provider

    @zGato said:

    @xHosts said:

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    I have spoken to virtualizor, it appears to have been human error not a software issue

    But exposing raw passwords is also a human error, right? Or a best practice I haven't been aware of?

    Avoid Virtualizor at all costs.

    ColoCrossing also hasn't stated it, but full names are also in the db, unless you manually changed it in Virtualizor.

    Where do you see the passwords ?

  • zGatozGato Member

    @xHosts said:

    @zGato said:

    @xHosts said:

    @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    I have spoken to virtualizor, it appears to have been human error not a software issue

    But exposing raw passwords is also a human error, right? Or a best practice I haven't been aware of?

    Avoid Virtualizor at all costs.

    ColoCrossing also hasn't stated it, but full names are also in the db, unless you manually changed it in Virtualizor.

    Where do you see the passwords ?

    In the tasks table.

    Thanked by 1siemens
  • So maybe I’m totally dumb or lost track of the story on this, but if the database dump is now out in the wild, what kind of ransom exactly can the hacker extort? Isn’t there no incentive now to pay their extortion?

    Thanked by 1tentor
  • VoidVoid Member

    So what tools do you use in Mac/Windows to view the db data in a clean format? Other than text editors. I tried a few like DBeaver, but it won’t load because the file size is 2GB. Not even after tweaking the .ini file to set a higher memory limit.

  • VoidVoid Member

    @PineappleM said:
    So maybe I’m totally dumb or lost track of the story on this, but if the database dump is now out in the wild, what kind of ransom exactly can the hacker extort? Isn’t there no incentive now to pay their extortion?

    “We warned ColoCrossing, but they decided to restore the email, we came up with the choice to start leaking the database, and once we get access to the new data from the email back - we'll send everything out to the emails. Link to database: “

    I think the db was leaked after CC did not comply with whatever the hackers demanded.

  • @Void said:
    So what tools do you use in Mac/Windows to view the db data in a clean format? Other than text editors. I tried a few like DBeaver, but it won’t load because the file size is 2GB. Not even after tweaking the .ini file to set a higher memory limit.

    https://github.com/mysql2sqlite/mysql2sqlite

  • @Calin said:
    Anyone from here know what cause this?For fix at our end?What virtualizor version etc...

    paying back 20k would deffo help

  • Can someone ping me link to DB exposed so I can see if I’m impacted

  • @6wvy5ipw said: So, on 2025-05-24 around 11:25 AM (UTC+8), someone added an admin account with a QQ.com email

    To be honest I don't believe the hacker is dumb enough to use QQ as their email...

  • Kevinf100Kevinf100 Member
    edited May 2025

    @dedipromo said:

    @6wvy5ipw said: So, on 2025-05-24 around 11:25 AM (UTC+8), someone added an admin account with a QQ.com email

    To be honest I don't believe the hacker is dumb enough to use QQ as their email...

    could be a stolen or just fake email? Even harder to trace if email is just stolen or something bs.

    Thanked by 1dedipromo
  • db link?

  • beanman109beanman109 Member, Host Rep, Megathread Squad
  • It might be the official administrator of ColoCloud.
    Seems their sales and PM are Chinese.

Sign In or Register to comment.