WordPress.com’s Dedicated Web Hosting Provider LayeredTech User Accounts Compromised wordpress.com奇摩專用Web託管服務提供商layeredtech用戶帳戶妥協
Automattic hosts WordPress.com using dedicated servers from LayeredTech. automattic主機wordpress.com使用專用服務器從layeredtech 。 According to Todd Abrams, President & COO of Layered Technologies:據托德艾布拉姆斯,總裁暨營運長分層技術:
"The Layered Technologies support database was a target of malicious activity on the evening of 9/17/2007 that may have involved the illegal downloading of information such as names, addresses, phone numbers, email addresses and server login details for 5 to 6,000 of our clients." “分層技術支持數據庫是一個目標的惡意活動對2007年9月17日傍晚可能涉及非法下載的資料,例如姓名,地址,電話號碼,電子郵件地址和服務器登錄的細節, 5日至6000的我們的客戶“ 。
"Due to the significant amount of uncertainty in determining which accounts may have been impacted, Layered Technologies felt that it was in your best interest to take the precautionary steps of reaching out to you and all clients regarding this issue. In addition, we are asking all of our clients to change the login credentials for all host details they have submitted in the past 2 years. This includes any login credentials for the following: Cerberus, Modernbill, Encompass, and all servers you own and operate with LT, all services that may have submitted passwords in the past for such as Webmail, Remote Desktop, SSH, MySQL, cPanel WHM, FTP Backup storage or similar services. Please utilize the ‘reset password' features on all of our tools to reset and send a new random password. Any LT customers needing assistance with resetting passwords should contact our technical support team via our ticketing system for methods for how we can assist with resetting them and not providing the updated passwords in the tickets." “由於大量的不確定性,決定哪些帳戶可能已衝擊,分層技術,認為這是在您的最佳利益採取的預防措施達成了向你和所有的客戶在這方面的問題。此外,我們所要求的我們所有的客戶改變登錄憑證,為所有主機的細節,他們提交了在過去的2年。這包括任何的登錄憑證,用於以下各項:地獄犬, modernbill ,涵蓋了,和所有服務器,你擁有並經營與勞資審裁處,所有的服務5月提交的密碼,在過去,如網絡郵件,遠程桌面, SSH的, MySQL和的cPanel的WHM ,備份存儲的FTP或類似的服務,請利用'重設密碼'的特點對我們所有的工具,以重置和發送一個新的隨機密碼任何勞資審裁處的顧客需要援助的重設密碼應該聯繫我們的技術支持小組通過我們的票務系統,為方法,我們如何能夠協助他們與重置,而不是提供更新密碼,在門票“ 。
I cannot imagine the impact on big clients like Automattic, which has hundreds of servers from LayeredTech.我不能想像的影響,對大客戶一樣, automattic ,其中有數百個服務器從layeredtech 。 I too use one of the servers from LayeredTech and just finished changing my passwords.我也使用其中一個服務器從layeredtech和剛剛結束的改變我的密碼。 Imagine the effort for Matt & Co. Don't be surprised if your wordpress.com accounts are compromised too.試想,努力為馬特公司並不感到驚訝,如果您的wordpress.com的帳目太妥協。 If hackers have root access to WordPress.com servers, which they will have as root access is required to be provided for many support requests, then they are free to change all your account details, delete them or post on your behalf.如果黑客已經根獲得wordpress.com服務器,他們將有root身份訪問是須提供許多支援的要求,然後他們可以自由更改您的所有帳戶的詳細資料,刪除它們或張貼在您的代表。 So in summary there is a full possibility of major disruption of service.因此,在簡易程序是有充分的可能性,主要的服務中斷。 Looking forward to hear from期待著聽到來自 Matt馬特 & Co. about the impact on WordPress.com.公司有關的影響wordpress.com 。
I think LayeredTech handled user accounts negligently in the first place.我認為layeredtech處理用戶帳戶疏忽擺在首位。 This is inexcusable.這是不可原諒的。 LayeredTech have opened on us the floodgates for spam and more probably much more. layeredtech開放對我們的大量垃圾郵件和更多的可能是更多的工作。 At least I didn't have my credit card details with them.至少我沒有我的信用卡資料與他們。
Filed under提起下 Computer Security計算機安全 , , Headline News頭條新聞 , , Pro Blogging贊成Blogging , , Web網頁 , , Web 2.0 Web 2.0的 , , Web Hosting虛擬主機 , , Web Services Web服務 , , WordPress在WordPress | |
| |
RSS 2.0 2.0 | |
Trackback Trackback跟踪 this Article |此文章|
Email this Article電子郵件此文章
You may also like to read您也可以想讀 |




































September 19th, 2007 at 1:53 am 2007年9月19日在上午01時53分
None of our servers allow password logins, so there was no immediate threat, however we did take the opportunity to review our systems and security.沒有我們的服務器允許密碼登錄,所以沒有立即的威脅,但是我們沒有藉此機會檢討我們的系統和安全。 Despite this horrible problem, LT has still been a great long-term partner for us and I would be surprised if something like this happened again.儘管這個可怕的問題,勞資審裁處,仍是一個偉大的長期合作夥伴,我們和我會感到十分驚訝,如果是這樣的再次發生。
September 19th, 2007 at 6:12 am 2007年9月19日在上午06時12分
Thanks for the update.感謝更新。 It is a relief.這是一個救濟。
I hope not.我希望不是。
My experiences so far with LayeredTech:我的經驗,到目前為止,與layeredtech :
1. 1 。 Nice value for price nice值為價格
2. 2 。 Strongly protects against spam sites堅決防止垃圾郵件的網站
3. 3 。 Was slow in responding to my requests for site inaccessibility from certain locations; it was finally resolved緩慢,在回應我的要求,為網站不便,從某些地點,這是最終解決
However I am sure they will have much better service for a big customer like Automattic不過我相信他們將有很多更好的服務的大客戶,像automattic
Their home-brewed user interface did look much flimsy to me than other dedicated service providers say like EasySpeedy for example.他們的家中自釀製的用戶界面卻看得多站不住腳的,我比其他專責服務供應商說,像easyspeedy例如。 While that doesn’t really indicate their underlying security code in-place, unless we get more details, I suspect it was breached from the UI.而並不真正顯示其潛在的安全守則,在地方,除非我們了解更多詳情,我懷疑這是違反了從用戶界面。
BTW: Nice idea about dis-allowing password logins.的BTW :尼斯知道存款保險計劃-允許密碼登錄。 I thought about it too but didn’t get around to implement it.我認為它太,但沒有得到周圍的貫徹落實。 Now I will.現在我會。
December 24th, 2007 at 6:33 am 2007年12月24日在上午06時33分
Maybe you guys should look at information like this in respect to LayeredTech:也許你們應該看看資料,這樣在尊重layeredtech :
http://spamhuntress.com/2006/10/14/massive-spam-campaign/
A lot of people have all traffic from LT IPs banned on their servers.有很多人都從交通審裁處的IPS禁止對它們的服務器。