Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,148,444 members, 7,801,059 topics. Date: Thursday, 18 April 2024 at 10:27 AM

Dreamhost Hacked, Mass Password-reset Issued - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Dreamhost Hacked, Mass Password-reset Issued (5021 Views)

Host Your Site At Dreamhost / Dreamhost $97 Discount Promo Code 2015 / Dreamhost Coupon Codes 2014 (2) (3) (4)

(1) (Reply) (Go Down)

Dreamhost Hacked, Mass Password-reset Issued by Slyr0x: 1:50pm On Jan 23, 2012
According to a blog post at DreamHost Status Blog, the company has detected a security breach at one of their database servers.

In a response to the attack, the company has decided to issue a mass password-reset on all of its customers.

Apparently, the breach occured in November via theone-click install wizard offered by Dreamhost: One click and your wholeWordpress / Drupal web site is installed, ready to use, automatically updatedby the wizard. Apparently, it’s the wizard itself that was compromised andanybody who used it was affected.

DreamHost CEO issued the following statement:

“our systems have stored and used encrypted passwords for a number of years, however the hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted. We’ve now confirmed that there are no more legacy unencrypted passwords in our systems. And we’re investigating further measures to ensure security of passwords including when a customer requests their password by email (this was not the issue here, though).”

Next to shell and FTP passwords, the company is advising its customers to change email passwords as well.

There are not reports of mass abuse of the stolen accounting data so far.


http://packetstormsecurity.org/news/view/20486/DreamHost-Hacked-Mass-Password-Reset-Issued.html
Re: Dreamhost Hacked, Mass Password-reset Issued by Wallie(m): 3:43pm On Jan 23, 2012
Slyr0x:

According to a blog post at DreamHost Status Blog, the company has detected a security breach at one of their database servers.

In a response to the attack, the company has decided to issue a mass password-reset on all of its customers.

Apparently, the breach occured in November via theone-click install wizard offered by Dreamhost: One click and your wholeWordpress / Drupal web site is installed, ready to use, automatically updatedby the wizard. Apparently, it’s the wizard itself that was compromised andanybody who used it was affected.

DreamHost CEO issued the following statement:

“our systems have stored and used encrypted passwords for a number of years, however the hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted. We’ve now confirmed that there are no more legacy unencrypted passwords in our systems. And we’re investigating further measures to ensure security of passwords including when a customer requests their password by email (this was not the issue here, though).”

Next to shell and FTP passwords, the company is advising its customers to change email passwords as well.

There are not reports of mass abuse of the stolen accounting data so far.


http://packetstormsecurity.org/news/view/20486/DreamHost-Hacked-Mass-Password-Reset-Issued.html

To think that I was only notified 2 days ago! The hackers had almost 3 months to go to town!
Re: Dreamhost Hacked, Mass Password-reset Issued by Frosti(m): 3:57pm On Jan 23, 2012
Na wa o. Thank God my site, www.onwaweb.com is hosted on google servers.
Re: Dreamhost Hacked, Mass Password-reset Issued by ogbongzky(m): 4:26pm On Jan 23, 2012
Gosh!
Re: Dreamhost Hacked, Mass Password-reset Issued by omoloba123(m): 4:51pm On Jan 23, 2012
Thank God my site www.cityflavourmagazine.com not hosted on Dreamhost, but to me 3month is too long to notify their customer about the hacking
Re: Dreamhost Hacked, Mass Password-reset Issued by sheyguy: 5:01pm On Jan 23, 2012
Pls can anyone help me with a free(3 months atleast) and reliable host for joomla/drupal out there?
Re: Dreamhost Hacked, Mass Password-reset Issued by Frosti(m): 5:06pm On Jan 23, 2012
sheyguy:

Pls can anyone help me with a free(3 months atleast) and reliable host for joomla/drupal out there?
You use google's blogger.com. But they dont accept joomla sites.
Re: Dreamhost Hacked, Mass Password-reset Issued by Mobinga: 5:30pm On Jan 23, 2012
Slyr0x:

\

    “our systems have stored and used encrypted passwords for a number of years, however the hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted. We’ve now confirmed that there are no more l[b]egacy unencrypted passwords[/b] in our systems. And we’re investigating further measures to ensure security of passwords including when a customer requests their password by email (this was not the issue here, though).”
\

It wasn't even encrypted and you still left it there?  undecided
Re: Dreamhost Hacked, Mass Password-reset Issued by Ymodulus: 8:04pm On Jan 23, 2012
I like something about this guys. They were honest and made the case open. A nigerian host wont do this. Neva! He go tell u say this that
Re: Dreamhost Hacked, Mass Password-reset Issued by denzel2009: 8:59pm On Jan 23, 2012
Ymodulus:

I like something about this guys. They were honest and made the case open. A nigerian host wont do this. Neva! He go tell u say this that


ISO audit standards stipulates they should report every breach on their systems.
Re: Dreamhost Hacked, Mass Password-reset Issued by DualCore1: 9:08pm On Jan 23, 2012
. . . therefore their honesty wasn't put on the table like a choice among other options.

Meanwhile what is it with bashing Nigerian host service providers at every hit. . . and it has to be so generalized?
Re: Dreamhost Hacked, Mass Password-reset Issued by mpmp: 10:05pm On Jan 23, 2012
sheyguy:

Pls can anyone help me with a free(3 months atleast) and reliable host for joomla/drupal out there?

hi there, I can help u out with Joomla(web hosting, template customization), what exactly do you need.
Re: Dreamhost Hacked, Mass Password-reset Issued by Slyr0x: 11:06pm On Jan 23, 2012
denzel2009:


ISO audit standards stipulates they should report every breach on their systems.

One of the ISO 27001 controls also says passwords should be encrypted. . .They goofed up big time. . .It's good they admitted tho
Re: Dreamhost Hacked, Mass Password-reset Issued by abohrandy: 10:09am On Jan 24, 2012
Frosti:

Na wa o. Thank God my site, www.onwaweb.com is hosted on google servers.
___________________________________________________________________________________________________________________________
omoloba123:

Thank God my site www.cityflavourmagazine.com not hosted on Dreamhost, but to me 3month is too long to notify their customer about the hacking


[size=18pt]Nice cheap advert!!!![/size]
Re: Dreamhost Hacked, Mass Password-reset Issued by Frosti(m): 12:03pm On Jan 24, 2012
^^Are you are you just created more awareness for 'the cheap advert? undecided

(1) (Reply)

I Want To Integrate Ecommerce Into My Entertainment Blog. I Need Advice Please / Free Download Naijaloaded Wordpress Theme October 2019 Edition By DMG / 5 Tips To Improve Website Visibility For Better Google Ranking

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 23
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.