New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
Softaculous also got new SSL certs at the exact same time as this happened. All of these products received new SAN certs around the same time that don't match the previous issuance patterns:
https://www.certkit.io/tools/ct-logs/?query=softaculous.com
https://www.certkit.io/tools/ct-logs/?query=webuzo.com
https://www.certkit.io/tools/ct-logs/?query=virtualizor.com
So my worry is that other services were impacted.
This is why it takes time to thoroughly test each step, ensuring perfection without any hanging tasks like Virtualizor does.
Looking Glass? Speed test files?
(emphasis mine)
Yeah, sakkurity at work:
host -t caa virtualizor.comResult:
virtualizor.com has no CAA recordIf that was just a BGP hijack and not a total data breach, then I wonder: how could someone log in into their softaculous.com/clients zone; provided your panel/database is not available to a 3rd party that could spin up a fake client zone?
To be able to replicate your client zone, a BGP hijack is not enough.
@Andreix As I understand, the login form was there, but the panel itself wasn't.
We are generally focusing on Virtualizor, but the main issue for me is that is possible to hijack Hetzner's IP addressing without much trouble...
You probably have not had too much to work with T1 providers.
They simply don't give a f*ck most of them. Since 2019 till today, I still have issues for my customers with T1s or providers with immediate T1 access, that simply accept stuff from downstream, with no IRR or ROA check.
And once a T1 accepts such a prefix (and believe me, it's not so rare), it doesnt matter if it's Hetzner, OVH, ServerSpan or any other. It will propagate to all it's downstreams (or a majority of them) and create a beautiful hijack.
After this happens, you basically try to find every connection you have, that may have a connection who may have a connection that may know someone from that T1 NOC. Because mails and tickets are basically "we're T1, f*ck off!". And most of the time, even if the request was clearly a malicious one, T1s accept a simple: sorry, we made a mistake from their clients.
So, yeah, internet as it is today, is one small T1 ignorance away.
If the user tried to login, they put their password on the malicious site. No DB was leaked.
So was basically a pishing to store user password...
Agreed. @DP what do you think?
With AI auto-feed fetched from known blackhat forums or CVE DBs?
Since working with lots of hypervisor.io users, I can tell that it has "Native virtualizor Importer", its supported from hypervisor beta 2.2.6 release, you may consider peeking into that and give your views.
It sounds stupid, but It seems the solution to hijack is to hijack the hijack?
Incident Response over at https://www.virtualizor.com/blog/security-incident-bgp-hijacking/